Resolved! Group Based Administrator Account
Hi, Is there any option in Palo Alto, To create a single administrative account for a user group fetched from RADIUS.
Hi, Is there any option in Palo Alto, To create a single administrative account for a user group fetched from RADIUS.
Hi, We are having a strange issue in our FW. User in VPN-SSL reported the stop working. The issue doesnt have any pattern. Random users, random time-range. The issue is solved when the customer force to reconnect the VPN or force pass the HIP check in GPclient. This is what we see in FW monitor logs. The FW stops identifying user and jump the ru...
If patching a HA pair to the next Major version i.e. 9.0.6 -> 9.1.0 is it safe to patch one of the pair all the way to 9.1.0 (minor versions and major versions) And then fail over and do the other firewall to bring that up to latest minor and finally on to the major version. Or should both firewalls be running the same latest minor version ...
Hello, after upgrading to macOS Monterey globalprotect stopped working... i tried to unistal reinstall 20x, firewall of/on, private relay of/on, i did allowed it in security, limit IP address tracking of/on, tried with "spctl kext-consent add PXPZ95SK77" in recovery mode, but im still getting this error:P 800-T29719 02/18/2022 00:35:20:833 Info ...
I'm looking for some feedback on the UDID HIP check for iOS devices. Currently there is no way to pull serial numbers from the Apple iOS platform unless you connect a compatible MDM solution to the PA. There is however a way to pull the UDID or ( unique device ID) that apple has tagged on each device it builds. I've added that under HIP objec...
Hello teamCould someone tell me if it is possible to see the occupancy of the VPNs in the Paloalto pools?If so... How can I see it?ThanksGreetings.
Hello All, We are looking into use PAs as routers on some of the sites. This will entitle us to accept BGP routes from Prisma and OSPF from internal routers. That's the reason I would love to find out if there's a limit (I am sure there is) for ammount of prefixes per each model of PA appliances? I think I've found a post here from 2013 regardin...
I am getting a SAML error after renewing a few certs that expired. eventid eq saml-certificate-errorCan you use the same IDP xml file across multiple Device SAML profiles? IDP is Microsoft azure.and ( description contains 'Failure while validating the signature of SAML message received from the IdP "", because the certificate in the SAML Messag...
Hi Team, On GP 5.2.5 on GUI logs i see ( status eq failure ) and ( eventid eq gateway-register ) and ( error eq 'Existing user session found' ) is this bad?what is the reason for this error? Regards
I'll start off by waving the "I'm not as strong in networking & network security as I probably should be" flag so I apologize in advance for my lack of expertise in these areas and products.In short, I need assistance getting PXE to work on devices connected to a PA-820. In this particular case the PA-820 is the DHCP server which is differen...
When using the following link the header of the page states "Download and Install the GlobalProtect App for Windows" but the text is about "How to install the GlobalProtect App for Linux". The way I arrived at this page was the following:I searched for "download global protect agent" using the search engine Startpage.com One of the results (in...
Hi, We are getting warning message (Warning: No valid DNS Security License) when we commit every time. currently we are using PAN OS 9.0.5. Is it possible to disable this warning message. Regards,Logesh S.
I am trying to set up a TLSv1.3 / TLSv1.2 webserver behind a palo firewall with ssl inbound decryption.However i seem to get a lot of ssl errors and the website does not work if specific ciphers are not listed first...For one I would like to understand why that is and even ciphers listed here have issues: https://docs.paloaltonetworks.com/compat...
I have two PAN 3220s operating as Virtual Wires behind a pair of ASA 5525s. Normally in upgrading a pair of PANs you upgrade the standby, then suspend the primary (secondary takes over), upgrade the primary. Repeat as necessary to get to your target version. But since these are behind another HA pair, I'm concerned I could end up with a situatio...
Running PANOS- 9.1.12h3. What is the ssl decryption session limit.
| Subject | Likes |
|---|---|
| 1 Like | |
| 1 Like | |
| 1 Like | |
| 1 Like | |
| 1 Like |

