What are the limitations of Expedition Migration tool when migrating other vendors firewalls
Hi, Can any one name the technical limitations of using Expedition tool for migrating to PAN. Thanks and regards.
Hi, Can any one name the technical limitations of using Expedition tool for migrating to PAN. Thanks and regards.
Hello all,We have a PA-3050 configured with V-wire and are operating as STP Block on the uplink of Backbone_B. We are going to replace PA-3050 with new construction equipment, PA-3410. STP blocks are not generated in the in-house LAB before deployment, and disconnect occurs during communication. In conclusion, the issue has been resolved. 1....
Hi guys. We have a number of developers that use Windows Subsystem for Linux (WSL) on their Windows clients, and there are a lot of URLs and services that will not work when we decrypt the traffic. Managing a decryption exclude list for them would be a major pain, so I am thinking of ways to fix this. Is there any way to separate WSL sessions fr...
Hello I'm interested in the Palo Alto virtual or VM-series appliance that would be broadly equivalent to the PA-5250. I realise the product selection is best made based on requirements such as sessions security rules, dynamic ip addresses, security zones, ipsec vpn tunnels but that information is not available just yet. What I can say is tha...
We are using PANOS 9.1 and latest DNS security. Any thoughts on these errors from proxy log? 172.16.1.1 and 172.16.1.3 are Microsoft AD DNS servers.Can these be effecting performance of traffic? 2020-02-17 08:30:23.583 +1100 Error: pan_dnsproxy_recv_server_udp_cb(pan_dnsproxy_udp.c:222): [udp]: fd 48 from 172.16.1.1 to 0.0.0.0 process server fa...
Hi guys, greetings. On of my customers asked me a simple question about palo alto database. How does it work internally? Is there any SQL database internal on PAN-OS? Should it be accessed by any external factor like APIs os something like that?
Hello Friends, We have Palo Alto firewalls (various models like 3050, 5220 and 3220) which are in HA (active-passive mode). IPSEC tunnels are working fine when traffic is on active gateway. The issue is, when we failover traffic on passive gateway, internet works fine but my tunnel resources becomes unreachable. When i checked tunnel status on ...
Hi All, We currently have a pair of PA-5250 firewalls configured in active/passive. We have 4 port channel groups configured with the condition set to 'all'. The question i have is we are using eth1/1 & eth1/2 as HA interfaces if one of these goes down will the firewalls failover? Also is it possible to stop a interface from causing a ...
I have GlobalProtect running for machines when they are off the network. Is there anything that I need to setup that would allow them to be able to print to their local LANs even though the agent is connected back to the FW? I am currently testing this right now, but users most definitely will need to print when not in the office, so I am hopi...
User ID agent showing access denied after microsoft update on the DC and I nothing I have tried has fixed it
Hi Community, I have a spare firewall PA-820 that I need to upgrade from 10.1.6-h3 to 10.2.0 but it returns an error asking me to update the content version. Please see picture below: But when I try to upload the content version, it asks me for a license. I remember doing the same procedure last year without the device requesting a license....
Hello, We are trying to use Cisco Prime as an SNMP manager for polling/snmp traps for our Palo FWs but according to Cisco, they only support Cisco MIBS. I was wondering if anyone could recommend an SNMP manager tool for Palos that we can use for polling and snmp traps using Palo MIBs where I can automatically collect the data over a period of ...
We have purchased Threat Prevention subscription for our older PA-200. I asked for both Premium Support and Threat Prevention but we were sold only Threat Prevention because supposedly PA-200 is no longer sold by PAN. But I cant seem to be able to proceed with Threat Prevention license activation because I also need the firmware updated to 9.0 o...
Hello. I followed the video while watching it, and I want to send the log to the panorama server. https://www.youtube.com/watch?v=B_ttlugnARE The log is not being checked. Is there a different setting to check the firewall log on the panorama server?
Hello. Sir. registering a firewall on the panorama server. The firewall administrator IP is set to default. In this case, how do I register the firewall on the panorama server?
| User | Likes Count |
|---|---|
| 8 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |

