Global protect client for windows 11
Are the Global protect agent is compatible with windows 11?
Are the Global protect agent is compatible with windows 11?
Config changes retention in Palo Alto For non root user with read only admin access Hello All, I have recently come across the issue of read only admin access config change 10-15 days back but same not reflecting in the commit when I checked. So, my main query is that for many days the changes will remain as it is in commit for read only adm...
We have had overlapping subnet scenarios where someone is connecting using GlobalProtect Cloud Services from a subnet that overlaps our internal subnet and, as they have a more specific route, access to internal resources is failing as the taffic is being routed via the local router instead of over the VPN due to the more specific route. Due to ...
Can I add On-Site Spare PA-440 firewalls with ZTP? Thanks
Hello, I have a question about the mechanism of TCP session timeout on PA FW. Assuming that default TCP timeout on PA device is 3600 seconds. What happen after a TCP session is idle after 3600 seconds ? Does the FW send TCP RST at each endpoints ? Or does it just delete the session from its sessions table ? And in this case if a new packet is se...
Our vulnerability scanner has detected a weak KEX algorithm (diffie-hellman-group1-sha1) on our firewall. Is there a persistent way to disable the weak KEX algorithm? I found this article (below), but it says every time the firewall reboots the weak algorithm becomes enabled again.https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=k...
Hello,since a few days we see strange things with User-ID-agent.For some specific IP-addresses there are shown wrong users. This users even are not in the internal AD, they are just external VPN users invited from Azure. But they are mapped to internal ip addresses. Even if they are not online over VPN.When looking into Monitor - User-ID in the ...
Good afternoon, first of all thank you very much for the help and support for this case: "The virtual adapter was not set up correctly due to a delay. GlobalProtect will try again soon. If the issue persists, please restart your system" -Windows versión: Windows 7 64bit SP1-Global Protect Client: 5.1.8 64bit I have already restarted the computer...
Hello, I have 3 locations that I need to create VPNs to AWS for. Each location is dual ISP using PBF. Since AWS uses 2 tunnels each VPN connection, seems there will be 4 total tunnels per location (2 per ISP). My initial thought was to use static routing but I'd like to avoid any asymmetric routing from AWS. In these locations, we are usi...
Hi All , Just checking what cmd we can use to validate receive and adversities BGP route from a peer like we have in cisco . @PavelK
Hello, I'm trying to configure a Security Policy to only allow US-region IP addresses to hit our network. I added as a first rule to allow any untrust us region to destination untrust US region. I am not sure if this is correct. maybe I'm allowing all traffic within US, that probably is not supposed to be allowed. thanks #urlfiltering #r...
Hi Folks, We have PA-3250 firewall deployed in our environment managed by Panorama. The panorama is deployed in Panorama mode and the firewall is under panorama and no connectivity issue between firewall and Panorama. The firewall is also added under log collector group setting in Panorama. Configuration vise everything is good. The fire...
In Global Protect HIP check we have allowed only specific domain machine and specific antivirus. Firewall will continue to check domain and antivirus if Global Protect license is expired ? Any impact if GP license expired ? Do we require to remove HIP profile from rules in such case ?
Dear all,What is the session timeout for unknown-tcp/udp?Since this is an application which has no values set for timeout, can I conclude it will use the default-tcp/udp timeouts?Kind regards
Palo gateways have supported ipsec site to site vpn for a long time. Do they also support acting as an OpenVPN gateway? I dont mean openvpn passthrough to a backend. I mean actually being the Openvpn endpoint.
| Subject | Likes |
|---|---|
| 7 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 1 Like |
| User | Likes Count |
|---|---|
| 7 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |

