Licensing DNS Security
I am trying to register our DNS Security. I have the purchased Auth Code, but I cannot where to add it in the customer support portal. I tried to add it under PRODUCTS --> Assets. My part number is PAN-PA-5220-DNS-5YR.
I am trying to register our DNS Security. I have the purchased Auth Code, but I cannot where to add it in the customer support portal. I tried to add it under PRODUCTS --> Assets. My part number is PAN-PA-5220-DNS-5YR.
Seems not long after PAN OS upgrade to 10.1.3 we started seeing errors in our system event viewer logs for DCOM 10036 coming from our account that we use for LDAP on our PAN OS. They all reference the IP of our PAN OS as the originator. The logs are full of this error sometimes 3 or 4 times on the hour. Normally, I dont pay a lot of attention...
Hello Live Community, good evening, thanks a lot for your time and colaboration. I have a question regarding the value of "HA timer - Additional Master Hold Up Time" by default is 500 ms. In the documentation it indicates that this is an additional value to the "Monitor Fail Hold Up Time (ms)" that is to say, how many examples are an Interface...
Hi All, The Forward Trust certificate on a PA-820 firewall pair was expiring, so we issued a new SubCA certificate from the Windows ADCS root CA server and updated it on the firewall. The certificate was imported with a 2048bit key and there is a password on the key. Since switching over to the new certificate for forward trust (SSL Decryption),...
Hi There, I have configured a security policy to block a URL category using the Service/URL Category method and my action is deny. This works and the category is denied, however the block response page is not displayed. Instead i get "This site can’t be reached" and "ERR_CONNECTION_RESET". When i block the same category using the URL Filtering S...
I have a site to site ipsec vpn between two Palo firewalls. A always initiates the tunnel to B. Is there a way i can make A always keep the tunnel up even when interesting traffic is not present?
We have a PA-3220 which is running in 10.2.4 Pan OS, we observed something really weird in the traffic logs this morning which shows 'ms-rdp' connections allowing through the default interzone deny rule which we re-verified again to see it is still set to 'deny' and no one really touched the rule. This is really freaking us out? Any insight on w...
Our customer encounter intermittent connectivity issue with IPSec IKEv1 during phase 2 rekey of IPSec Child-SA. We open case with the IPSec peer device vendor, they mention that PAN is not sending message to R2011 (IPSec peer) for deleting the SA when the SA negotiation fails. Summary of issue: On IPsec PA-850 peer device log, it shows IKE ph...
I'am using PAN-PA-3220 We want to setup this model with: 1. HA (active-active) 2. Interface configuration using Layer 2 configuration Is it possible to done it?. as when I try to create Layer 2 configuration. It always pop out error "Layer 2 unable to configure due to HA in active-active mode. Can help to suggest or any ways to do it? *ps: c...
I have just setup SSO in our new eng panorama. When I tested it initially it gave me the error message "Error Displaying SAML error response page". I reached out to our team and it was noticed that the new saml app had fewer claims and attributes than the already existing saml app for our prod panorama. So we modified the settings of the new sam...
We have this setup for one site ------Dis sw--------------Edge switch stack of 3 ----------40 users we need to move few users behind the PA . what can be best design for this as we only need to have 5 to 10 users behind the PA 850.? Should we connect small switch to the existing stack of switch ?
Hi i have a problem certificate delete. But sow error Failed to delete Certificate - CaptivePortal. ° CaptivePortal cannot be deleted because of references from: i look to to ssl/tls service profile list not show profiles. plase help mee
Hi All, I am running PanOS 10.1.0 vm image. Devices are connected as mentioned below. Firewall E1/2 ---> L3 switch ---> Vlan 10, Vlan 20 I would really appreciate if some can tell me how to configure two DHCP scopes for Vlan 10 and Vlan 20 in PA firewall because once I configured one scope under E1/2 , for second scope E1/2 is not appearin...
Hello,After reading about and looking through documentation regarding vsys, and routing between vsys on the same firewall via use of external zones, as well as the vsys<>VR association, I have a few questions I would like to clarify if possible:1. If I have two vsys that share one virtual router, by default, will they be able to send traff...
Hello, I'm playing with the API to get hosts' vulnerabilities and images' vulnerabilities in Prisma Cloud (CWPP) (documentation: https://pan.dev/prisma-cloud/api/cwpp/get-images/) Following the documentation (which is great by the way) I noticed there is a note for some endpoints « Note: The API rate limit for this endpoint is 30 requests per mi...
| Subject | Likes |
|---|---|
| 7 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 1 Like |
| User | Likes Count |
|---|---|
| 7 | |
| 3 | |
| 2 | |
| 2 | |
| 2 |

