CRL with no internet
Hello, I have a 440 with no internet access. I could not find documentation on the proper way to update the CRL when my firewall does have access to the internet. Thanks for any help that I might be able to get with this.
Hello, I have a 440 with no internet access. I could not find documentation on the proper way to update the CRL when my firewall does have access to the internet. Thanks for any help that I might be able to get with this.
Attached is a screenshot of a rule that is ALLOW'ing ICMP, IKE, IPSEC, PING. Can someone explain why SSL is in the APPS SEEN list? I don't see where any of these applications have an implicit allow for SSL/443 trafffic yet if I read this right it is saying it sees SSL and more importantly allows it here because it hasn't narrowed it down to wh...
Hi Team, Is there any way to get a history of when NAT oversubscription dropped packets/sessions? Or can I only get realtime data on that?
Hello all,Hope you are doing well.Our customer who is using PA3220 experienced external public IP blockage due to abnormal symptoms traffic. Upon investigation, it was found that a test Linux server installed internally attempted SSH brute force attacks against an unspecified number of external public IPs. We would like to know if the PaloAl...
Model: PA450 OS: 10.1.8 ipsec-tunnel is working well. The corresponding logs are continuously occurring. I don't know if it's because of the tunnel monitoring option.
We are looking at creating a Honeypot Website. The idea is to set it up with a much more restricted vulnerability profile so when hackers are scanning for certain vulnerabilities in the low and informational category their IP is blocked. The question I have is whether this is a global block, as in that IP would be blocked from hitting any extern...
Hi All, looking for some assistance to configure VPN failover for DR/BCP. I've attached a basic diagram below Currently, static route monitoring is set up on the outside interfaces of the firewalls at Site A, so if upstream from Site A ISP 1 fails Site A will use Site A ISP 2 to start forwarding traffic out.From Site A we have two VPN tunnels bu...
how to diable anti-tampering on mac and Linux
Hello Live Community, good afternoon, thanks for your time and comments. About automating and anticipating some possible blockages and denials using Dynamic Groups - Autotag can you support me and comment me with some use cases ? Also, if you have implemented it, has it brought you good results ? does it work as expected ? what is th...
Hello, I connect from home via Prisma to on-prem. I have a few domain controllers setup for pre-logon etc. - what if my domain controllers were all offline or the firewall was offline - can i have a domain controller in Azure I have setup a site to site VPN from Azure to my firewall and can copy data across but dont know yet how to get my Pris...
One of my customers is using PA-3020 and thinking about replace. When I comparing following diagrams, I have one question. PA-3020 has dedicated "signature matching", "security processing", and "network processing" as below Compare to above, PA-400 has ONE dedicated processor with 3 features included. PA-3200 has THREE dedicated processo...
Hi, I have 2 palo alto firewalls configured as active and passive. I want to know how I should configure the Interface IP address (for inside and Dmz) on the passive firewall? Do they have different IP address configured from the active firewall (similar to how we do it on Cisco ASA) ? Thanks
Hello, We have a customer with PA-850 running 10.0.8-h2 and they want to upgrade to latest. As this firewall is placed in totally isolated environment and the customer wont allow to connect internet on firewall. This firewall is in HA peer mode. Any guidelines to upgrade to latest OS for PA 850 as offline mode? Thanks in advanced
Hi, We have an Active/ Active firewall between 2 datacenters. We have configured a single tunnel on a floating IP that is Active in Datacenter A to a remote Partner. Firewall in DC A is currently in Active Secondary State, Firewall in DC B is currently in Active Primary state. The tunnel has both phases up on the firewall in DC A and only t...
Hi everyone, I'm new to network security and I'm wondering how I can stay informed about the latest security trends and vulnerabilities to better protect my network. Are there any particular resources you recommend, such as security newsletters, blogs, or online communities? Additionally, are there any best practices you would suggest for stayin...
| Subject | Likes |
|---|---|
| 7 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 1 Like |
| User | Likes Count |
|---|---|
| 7 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |

