- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
I have an inbound SFTP, I need to secure access to from only a single domain, say *.mydomail.com/. I have tried with a URL category in the security policy. This does not seem to work. The source is in AWS, so to much of a hassle to manage a source ip list to allow. The source owner says he is AWS-US-EAST-1 zone. However the source IPs he listed ...
Hello all,I enabled DNS Sinhole on my palo and it is working fine. But now I'm interested in the DNS security license. Please help me understand some things?According to PA documentation since I have TP\\AV\\WF licenses, when a DNS query is made to a bad site the firewall will check its local DNS signatures which will hold a capacity of 100,000 ...
Hello Experts, We have enabled safe search in URL filtering & also added response page given by Palo alto from given link below. However when we implemented it, it works fine with yahoo, bing and google. however it doesn't work with yandex. Transparent Safe Search (paloaltonetworks.com) As per palo alto it should also work with yandex but it...
Hey there, Today I joined the community to enhance my Palo Alto and Security Leanings.. Thanks guys in advance. Hoping for great learnings and knowledge sharing!!
Hi Folks, We had configured to forward the system logs for severity of informational, medium, high and critical using filter builder. But we are receiving logs only for informational on our QRadar Syslog. What is the supported format for System log forwarding in PA firewall, we can select only one severity type for each entry or multiple severit...
Trying to set MTU for my GlobalProtect client.I've found some information about this in Palo Alto docs.I could not set it with netsh, I think it is because of GPO.But I could set it with the PowerShell command: SET-NetIPInterface -InterfaceIndex 3 -NlMtuBytes 1300When looking in the registry I see now MTU 1300 on the interface to which is assign...
Hi folks ! Would like your advice on a specific issue about user-id limitations : One of our customer is using one central firewall to redistribute user-id mapping to more than 100 devices, and has issues about user-id process crashing on the central fw.As far as i understood limitations on user-id redistribution, there is a limit of 100 redistr...
Hello, Good day, I have found many articles related to configuring standalone to HA. However, I don't find related articles for HA to standalone. Is there any good reference guide for changing role from HA (active-active or active-passive) to standalone (including best practise) or pre-caution and steps that we need to take note with and without...
Hi All, Can the integrated User-ID agent of an on-prem firewall monitor Azure AD for user-to-IP address mapping information? Many thanks
Hey,If at all possible, please could I ask for some input on the best way I try allow M365 office installs (from their CDN) and Windows updates to our endpoints even though we are not using SSL decryption at the moment? We currently have a policy rule to allow outbound web traffic, matching:any destservice http/https.security profile applied to ...
For the Flood Protection calculations: Alarm, Activate, and Maximum - the documentation states to use the baseline thresholds (average) for the zone. I have used the OIDs to do this, however, why would I be using the TOTAL ZONE baseline and not just TCP CPS? As how else would I calculate UDP, and IP flood protection? They would ALL be set to...
Is there a way to display a badge for taking these courses? I says I have passed but I cant find a way to carry it over to Linkedin
I have an active passive pair: PAN01- Passive , device priority 50, Preempt- disabledPAN02- Active, device priority 40, Preempt- disabled Now I wanted to switch the priority i.e. to make PAN01 active and PAN02 passive. I changed the priority on PAN02 to 60 and committed configuration, but it remained active and PAN01 remained passive. I had to s...
I just installed a firewall for a customer last night and it absolutely refuses to activate the default route for both ISPs in the virtual router. Only 1 will go active at a time. The intent is to just use route monitoring and use the primary ISP unless it goes down. The primary ISP static default route is created with a route monitor.The back...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 8 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

