Resolved! dual ISPs ECMP and virtual routes
if i have 2 isps, same bandwidth, used for load balancing with ECMP do i need 1 or 2 virtual routers?
if i have 2 isps, same bandwidth, used for load balancing with ECMP do i need 1 or 2 virtual routers?
Hi guys ,I have a lots of doubts about how to configure .1q vlan TAG / TRUNK on PALO ALTO FIREWALL.It`s possible to work with layer 3 interface ?I don`t found any documents here.Does anyone have something to help me.Nbest RegardsTHiago LIma.
Hi Team, I want to Disable weak cipher suites for SSL/TLS and SSH my question is, are the below commands correct ? Do I need to run below commands on Active and Passive firewalls separately ? I am using data port as management ( I do have dedicated management port with IP but not using it) so below commands are still valid. Also, I am on PAN OS...
Hi there, I'm looking for the correct way to build our UserID redistribution topology based on our enterprise needs. We have 1 Panorama appliance, 4 PA3020 hosting a GP Gateway component and 50 PA3020 for remote offices. Our only source for UserID is the GP Gateways. I've set up Panorama to retrieve UserID information from our 4 GP Gateway and o...
Can I just export the configuration from the 3020 running 9.1.8 and import into the 440 firewall running 10.1.8? Do I need to downgrade the 440 to 9.1?
Just registered (created an account) on this community and was greeted with "Your company requires multifactor authentication", emphasis on "your company": By "you company", does it mean Palo Alto, or some other company? Thanks!
I have a block rule for some of the more egregious regions of the internet. Unfortunately, the regions use the source address within the rule on the Palo so I see no way to negate an IP address in a region being blocked. Is there a way I'm not aware of to do this? It would be nice if you could group a rule with another and skip the next rule ...
Hello PAN community,I have setup user-ID with Active Directory and the hostnames and user names for domain joined systems are being logged in the firewall's monitor.Some systems have their hostnames resolved, but others are just showing IP addresses. Does anyone know why?Second, I'm also trying to see if user-ID can pick up source names and host...
Hi Team, We have observed a situation where all the connected interfaces were flapped on the Firewall with the below logs, there is no much conclusive evidence in the tech-support logs, not sure if i am missing the log file which has the reason for this cause. LACP interface ethernet1/2 moved into AE-group ae3. LACP interface ethernet1/...
Hello everyone I have a question, I was recently exporting a few reports to PDF and I realize that the order regarding to the column Day Received is not the same when you export it to PDF as we see in the Custom Report builder.I'm using version 7.1.3
I would like to reconfigure our PA-3260 FW to use its 40G interfaces instead of the 1G interfaces being used in production now. I plan to create one new aggregate ethernet interface made up of subinterfaces that correspond to each of the individual 1G AEs now in production. In the process, I will need to remove the IP addresses in each of those ...
We have configured the Check Point firewall version (R81.10), but it is not supported for native log ingestion. However, we have checked the official Palo Alto documentation for this link: https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Ingest-Logs.... -It states that log ingestion and data require a Co...
Hi Team, >In general, the PA Firewalls are manged by Panorama will log directly to Panorama or do we need any configuration to be made to push the logs to Panorama? >What is the best way to configure logging for the firewalls managed via Panorama? For the firewalls in cluster as well the firewalls which are standalone? >Based on what i ...
I have device registred and lisenced also I can ping from the device updates.paloaltonetworks.com however I cannot run any: request support checkrequest license fetchrequest license inforequest content upgrade check Server error : Failed to check support info due to generic communication error. Please check network connectivity and try again.
Hi there, Playing around at home with DHCPv6 Client with Prefix Delegation. Been following this guide: https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/networking-features/dhcpv6-client-with-prefix-delegation The configuration for the outside interface is working ok, and I get a prefix from my ISP. What fails is when I try to ...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 3 |

