submit error message when remove DG
Hi Device group is created in panorama. but when I want to remove all of Device goup and submit, I got the error message. Since it is invalid command, why it cannot be removed? Please see the below. Thanks
Hi Device group is created in panorama. but when I want to remove all of Device goup and submit, I got the error message. Since it is invalid command, why it cannot be removed? Please see the below. Thanks
I want to be able to block PotatoVPN Traffic. I am successful in most of my other VPN threat hunting safaris but this one is fairly new and my current rules don't capture this little guy. Has someone out there created a policy that successfully blocks potatovpn. Can I create a policy rule simply off of the identified threatID of potatovpn wh...
Hello, I need to capture what passes through a VPN site-to-site tunnel. I'd like to see the tunnel and not the ESP.With tcpdump you can use the command "tcpdump -i enc0" which decrypts the ESP.On Palo Alto, what is the equivalent command? Because with view-pcap follow yes filter-pcap <filename> I can only see the ESP.Thanks
I am unable to select Asset when I am opening a case on the Support portal even though the account is Super User. Kindly advise.
Good Day, I currently extract custom reports for the strata firewall running PANos 9.1.x and 10.1.x using Python but I am having a problem running the same python script on PANos 10.2.x Has anybody else encountered this problem?
When we were trying to recover our account for PA Customer support, but we found out that another entity is using our commercial name to activate PA products with a different account ID. How we can request to deactivate or change this?.
Hello all, this sounds very similar to a previous post I found on here but I could not see a resolution. Very basic. I am trying to block or allow a domain user from the internet, from LAN zone to WAN zone. This will not work if I have domain\user in the Source User Field. I can see a user when I run: admin@GeoffFirewall> show user ip-user-m...
Hello we have our enterprise CA and our PA firewalls have signed certs from it. Now for our captive portal, we also have a certi signed from our enterprise CA. Everything works and there is no browser error for certificate.But in the FW commit, we get a warning "Warning: cannot find complete certificate chain for certificate ..." I found the fo...
Hi All, We have implemented the SAML two-factor authentication for Global Protect users. We have tested via browser for SAML authentication, and the page successfully redirected to the Microsoft sign-in authentication page. After signing in, the Two-Factor Verification process was initiated, and access to the global protect portal was granted ...
Hey all. I'm starting my PCSNA journey and I've been going through CBT Nuggets and have setup the CBT Nugget lab. My 1/6 interface 23.1.2.15/24 cannot ping my vyos router ip at 23.1.2.1/24 and vice versa. I have allowed ping via the interface management on interface 1/6 which is associated to the outside zone. I have a policy allowing traffic ...
I have detected that my website alde.es has been marked as grayware and it must be a mistake. It is a very simple website of a non-profit university association that has no advertising. I have checked everything on the server, updated plugins and wordpress. All the malware tests are correct except this one. How can I ask for my site to be re...
Hey all!I have a problem with my second passive PA-3020. (7.1.7)We had a loss of power so the firewall was shutdown hard.When it's booting now, the autocommit fails.When I do a commit force, it says: "Threat database handler failed".Then I stumbled over this link: https://live.paloaltonetworks.com/t5/Featured-Articles/Threat-Database-Handler-Com...
Hi Team, We have a requirement. Our PA Firewall has internet connectivity and VPN set to one of the peer end Forcepoint device. VPN is up and running. Traffic from Forcepoint LAN to MPLS connected to PA is all working over the VPN. Now the requirement is ANY traffic from Forcepoint site will reach PA firewall for both its internet and MPLS acces...
Hello, I have a PA firewall without panorama, at present I have public ntp servers in sync with pool.ntp.org which are default from PA. Is this good to use public NTP server or local NTP server ? Please let me know the best practices on this.
Hi, we will deploy panorama VM on esxi server, but only bought 1 panorama license. So our users want to use high availability from the hypervisor Esxi. Im not familiar with esxi/vsphere. The question is, if we trigger high avilability from Esxi/vsphere, is the UUID and CPUID will change? Is any out there have deploy the panorama with th...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 8 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

