Resolved! vulnerability block action
Hi,when creating a profile choosing block action is seen as "reset-both" on the logs.is that normal behaviour or not ? Thanks.
Hi,when creating a profile choosing block action is seen as "reset-both" on the logs.is that normal behaviour or not ? Thanks.
When forwarding logs, they are being sent to udp 514. The udp time out is 30 seconds, and the syslog server actually receives packets every 5 seconds. However, I wonder why the firewall keeps the session longer than 30 seconds. When the time is long, it is several minutes or hours, and sometimes the date passes.
Hi- I am trying to implement exactly this article for ipsec - https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGkCAK However the tunnel is not coming up, I am not sure if its gns issue or my configuration? Wireshark packet drop also attached Please note you are posting a public message where community membe...
Good evening, Tomorrow I'm cutting over a new pair of 3410's. I have 3 LAG connections (AE.1, AE.11, and AE.10). AE.11 is the physical connections to my ISP switch. There are two L3 sub interfaces (VLAN 800 & 801). VLAN 800 = ISP1 and VLAN 801 = ISP2. Both ISP routes are static and have the same metric / AD. I'm using ECMP and it works well ...
Hi, All The action of security policy is set to allow, but session-end-reason is shown as "policy-deny" in traffic monitor.The PAN-OS version is 8.1.12 and SSL decryption is enabled.Could someone please explain this to me?If you need more information, please let me know.
just to give a baseline - hardware are pa-5220, running 10.1.6-h6, HA (active/passive), device managed by Panorama. Long story short - one of the firewalls got stuck on a reboot cycle where the firewall would reboot every 85 minutes. The data plane would not come up during this time and support processed a RMA. For the fun part: our initial...
Dear Team, Our question is "How can the firewall choose the route without configuring the ECMP" Appreciate your support as mentioned in this documentation https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/ecmp "Without this feature, if there are multiple equal-cost routes to the same destination, the virtual router choo...
I need help. I bought a used PA-820 off eBay. Works great! When I try to set up account on support.paloaltonetworks.com, I enter the serial number and SO. However, each time, the registration fails. I get an error message telling me to try again later. I tried on different computers and browsers on different days. Always the same result. The r...
Hi,Received a call from a client said their external scanner shows their servers behind the firewall allows tcp port 80 connections and able to passive finger those servers, but there is no firewall rule permit tcp port 80 to those servers. Digging it deeper, found one of the rule allows traceroute application with application default which all...
Since we configured dns sinkholing for some stuff like parked, malware domains, we are seeing related threat logs but no associated traffic logs pointing us to the source behind the queries. Recently we tested it on Mac machines and we do see traffic logs to sinkhole IP, but it doesn't seem to be working on the windows hosts. Has anyone exper...
SNMP Nagios OID interface Interface Throughput per Interface Hello good afternoon, first of all thanks for your collaboration. I have a question, can someone tell me, the exact data of the OID or to build the troughput detail, to monitor the "throughput" of each of the interfaces and if you can also get the Global detail of the total through...
Hi All ,Do we have any role for PANOS upgrade in collection : paloaltonetworks.panos Thanks
I get this error message “Public Cloud Server certificate validation failed. Dest Addr: wildfire.paloaltonetworks.com, Reason: self signed certificate in certificate chain”. Kindly help me resolve the issue.
I can't find a How-to document or community comment on this exact issue. Some that are close. And maybe I didn't search with the right terms. I have one customer that connects to a resource on our network. We set up an IPsec VPN between them and us. Their inside subnet is 192.168.1.0/24. I set up a static route on our 'default' router tha...
Me puedes ayudar. Que periodo se toma en cuenta cuando hago una renovación de licencia con diferencia en la fecha original que tenia que renovar. Por ejemplo mis licencias vencieron el 22 de febrero, pero las renové el 22 de noviembre, respetan las fechas de noviembre a noviembre o cuentan del 22 de febrero al 23 de febrero?

