XFF IPs Not showing in the Traffic logs for HTTPS Traffic
Hi, I am unable to see the XFF IPs for the HTTPS traffic in the traffic logs. We already implemented the Decryption but still we are unable to see in the traffic logs. Any suggestions.
Hi, I am unable to see the XFF IPs for the HTTPS traffic in the traffic logs. We already implemented the Decryption but still we are unable to see in the traffic logs. Any suggestions.
Dear Support crew,we have two PAN-3220. Our devices are HA. We received advanced evaluation package licenses for the devices, but my device operating system was 10.0.3 so the advanced licenses are only installed on PANOS 10.2.0.According to the release note, we upgraded PANOS devices to 10.2.0 and after 24 hours, our primary device had problem. ...
Hello, I am looking for mechanical drawings for the PALO ALTO 800 (820) Series FW, including dimensions, locations and distance between the screws, screw sizes etc. The images in the installation guide do not contain this information. Cheers
Hi Folks, We have PA-220 running on PAN-OS 10.0.6. Upon checking the Threat logs via GUI no threat logs are visible . So we had checked on the CLI of the firewall for any threat logs but no luck. The firewall have all the required licenses. 13 percent disk space quota is allocated for the Threat logs. The disk space utilization is also healthy. ...
Timeline of my struggles: Somewhere between 10.1.0 and 10.1.4 the clientless VPN stopped showing icons for each app not super big deal because the apps still worked but after trying a couple upgrades... 10.1.5: brings the icons back! but now the apps themselves do not work at alltrying by IP to rule out DNS issuestrying with https in case its so...
Hi,I come from Cisco background and getting familiar with Palo Alto firewalls. My query is about checking any debug running on the box and how to turn it off. In case of Cisco, show debug will show any active debug(s) and undebug all would turn it off. Please advise the equivalent in PAN-OS. In PAN-OS few debug commands that I am aware of are he...
Hello to everyone! This is my first topic))Gents, need your help to enable MS Teams for user w/o internet access.Need for users w/o authentication could start video conference in teams. I added teams.microsoft.com to enabled address, also created MS Teams group in application groups, but Teams still working only after authentication on PA. P.S. ...
Hi, Long time lurker here.I need some directions with a project I am preparing.The project adapts the way we communicate with the internet. This means preparing PBF rules, NAT rules, quite some objects(100+) and groups (10+) and also adapting the way the security rules interact with the zones. All this is quite some configuration change and I wa...
Hello all,Please be advised, there is a current issue with PAN-OS 9.1.6 which seems to break anything SMB related, e.g. mapped network drives. Sessions have an end reason of "incomplete" and go into state "aged out" in the session table. After doing a packet capture, i found firewall dropping packets with info Negotiate Protocol request - SMB R...
Hi All, I am quite new to palo alto. can anyone explain me what happened if we configured object as a FQDN, IP and URL..I have created one security policy where I have implemented destination as a FQDN (nslookup results into 1 IP address) but user is reporting that it's not working..For that, FQDN default TTL is 5 mins, refresh time is 6 hours.....
Hello all, Please be advised, there is a current issue with PAN-OS 8.1 which seems to break anything SMB related, e.g. mapped network drives. Sessions have an end reason of "resources-unavailable" and go into state "Discard" in the session table. Upon speaking with a TAC engineer, this is a known issue and they are working towards a fix. Edit: T...
Hi All, I would like to enable QoS on an IPSec tunnel. The tunnel is carrying mostly voice and signalling traffic.If the voice traffic has a marking, eg EF, will this marking be copied to the outer IP header (the IPSec tunnel header)? Or, will I have to create a separate QoS policy, which prioritises IPSec traffic as it egresses the physical int...
I have a HA Firewall Active/Passive. Due to certificate is already expired I have exactly follow below guide to create my Self Sign ECDSA Certificate and apply it to my Passive firewall. The issue is when the passive firewall is in HA mode that time I`m unable to access to the management interface. When I make it as standalone mode that time the...
Export in base configuration output screen Device-Groups does not show arrows to expand organizational groups and sub groups. When trying to import from Panorama 10.0.Currently running Ubuntu 16.04.6 and the Expedition shows 1.2.15 but had error messages when performed the install but it seems to work. Does any know how to fix the device group n...
Hi everyone,Currently, I'm trying to design an auto scailing with VMSeries on AWS.The official template from PA is required with Panorama.Anyone have a suggestion with ASG & Warm pools for VMSeries without Panorama?
| Subject | Likes |
|---|---|
| 7 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 7 | |
| 4 | |
| 2 | |
| 2 | |
| 2 |

