Resolved! PA-440 missing from Expedition device models
I am using Expedition v. 1.2.4.2. Trying to add a PA-440, but this model is not available from the list.Does that mean I cannot use Expedition for my migration?
I am using Expedition v. 1.2.4.2. Trying to add a PA-440, but this model is not available from the list.Does that mean I cannot use Expedition for my migration?
In November we upgrade to 10.1.3 and this error could not get resolved with TAC so we reverted back. We just upgraded to 10.1.4 and we are getting the same errors as before: deviceconfig -> setting -> session -> dhcp-bcast-session-on unexpected heredeviceconfig -> setting -> session is invalid From what we have read dhcp-bcast-ses...
When i set our URL filter to block category 'web advertisements' it works as expected. However, it also blocks many of the results of Google and Bing searches. I understand that is because the results in question are web advertisements, strictly speaking. Ideally i'd like to block inline advertisements whilst allowing results from Google/Bing se...
Hi, We enabled "Host internal detection" because user in company complanining about GP was taking the cursor. After configurin "Internal host detection" the GP stop taking the cursor but there are some users which its necessary to "Refresh connection" in GP to be efective. Any idea? why some users can need to "refresh connection" in GP?
We understand DoS protection works when we set action Protect. We need to know the benefits to setting action Allow and Deny. Because we think that option is the same as normal security policy. Thank you.
Dear All, We have deployed a PA3220 firewall. Please let me know a command that I can use to check how much utilized from allocated quota for traffic log and I know I can use >show system logdb-quota to check retention date. I am looking a for a command similar to this that gives how much have been used from allocated quota. I would really ap...
I need to create 800 IP address and Address group into Panorama. May I know what is the CLI command able to help me to do it ? I have tried below command but return as invalid. set device-group D-DMZ address H-xx.xx.xx.xx ip-netmask xx.xx.xx.xxUnknown command: set #CLI Panorama
I have installed TS Agent v10.0.0 software (x64 bit) on a Windows server in a Citrix environment. I have also configured on the Firewall the IP address of the TS Agent Server, I have allowed the firewall policies to grant access from Firewall to TS Agent server, and I can see the traffic is allowed. However, the TS Agent server is not connected...
I have an issue I was hoping to get some feedback on. I manage 27 different Palos and also Panorama. I have one FW that stops responding to the 2FA setup with TACACS+. All the devices are the same configs and all running 10.1.2 code. A simple reboot solves this (Band-Aid). I am curious if anyone else has seen this behavior?
We're upgrading a VPN tunnel to IKEv2 between a Cisco FTD 2140 and a PA-850 running 9.1. What I've noticed is that the PA doesn't have an option for PRF on phase 1. Does the PA automatically make this the same as the integrity algorithm? Is there some other way to configure this? Thank you.
Configured the Panorama SAML authentication for Admin UI SSO integration with Okta.I followed the Okta/Palo Alto single sign on setup instruction. Here SP(Palo Alto) will initiate the SSO and Okta will acts as an IDP.https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-Admin-UI.html?baseAdminUrl=https://gpmedicare...
I found some docs on whitelisting for adobe cloud which could be handy: Includes a whitelist: https://helpx.adobe.com/content/dam/help/attachments/Creative_Cloud_for_enterprise_Service_Endpoints.pdf Background http://wwwimages.adobe.com/content/dam/Adobe/en/devnet/creativesuite/pdfs/ControllingSvcAccess.pdf It could be handy to have this...
Below is an example diagram of my scenario. We have a subnet that is part of our production network, and then we have the same overlapping subnet for testing and disaster recovery which exists in a separate virtual router. I've oversimplified the drawing, so hopefully this makes sense. For testing purposes, the overlapping subnet in virtual r...
Hello all, the following problem: A Sub-AD-Domain in a forest with different domains at samAccountName and userPrincipalName. samAccountName: domain01\user01userPrincipalName: [email protected] Dial-in with Global Protect via SAML with [email protected] PA recognizes user as [email protected]. All rules based on User-ID don't work, because...
Hi Community, I got a customer who has a VM Panorama with 1 TiB of local storage.Now we have a SIEM solution installed, where the long-duration logs are stored, so the Panorama disk storage is oversized now. I know there's a guide to add disk space to Panorama VM, but no solution to decrease space. Does anyone know, if there is a solution to def...
| Subject | Likes |
|---|---|
| 7 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 1 Like |
| User | Likes Count |
|---|---|
| 7 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |

