PAN-OS and Global Protect software
I plan to update to PAN-OS 6.1.6 and GP 2.3.1.Currently at 6.1.0, and 2.1.1. Any suggestions or issues? Thanks in advance//moe
I plan to update to PAN-OS 6.1.6 and GP 2.3.1.Currently at 6.1.0, and 2.1.1. Any suggestions or issues? Thanks in advance//moe
How to get the apps content update release notes of 8447-6897 ? Please help me
Current setup : Multiple virtual instances running on a pair of 5250 and 5220 active-standby deployment each site.Meaning 1 pair of 5250 + 1 pair of 5250 > 1 pair of 5450Target setup : All virtual instances would be migrated/consolidated to a pair of 5450 modular hardware active-standby deployment each site. Note : Migration methodology shoul...
We had a site to sit VPN between on premise PAN going to AWS.The tunnel was established and does not show any downtime but the issue we encounter is that when the Tunnel Monitor IP(169.254.2.x/30) and (169.254.3.x/30) is not pingable/unreachable PAN will remove the route going to AWS in result we are not able to connect to the AWS LAN segment. A...
Hi Team, i have problem with ssl vpn palo alto detail in picture acctually ssl vpn session is 0 detail belowwhat can i do?? Thanks
Hi, I'm currently doing DHCP server migration from Windows server's DHCP server function to Palo Alto PA-3200 series, with PAN-OS 9.1 series. I copied over all the configurations from Windows server to Palo Alto including the IP address reservation. After migration, what happened was that, for an IP scope that corresponds to a VLAN with 802.1X d...
Hi, Palo-alto PA-VM-KVM-9.1.0.qcow2 is installed into GNS3 version 2.1.21 based on the below link. I try every configuration is same as the link. Two vCPU, 4G RAM and 8 interface. but after it start, it shows below message and then stop at the end of the below message. Anyone can give some suggestion? Thank you https://www.gns3network.com/how-t...
Hi all, I have a IKEv2 IPSEC from PA to PA Firewall with tunnel monitoring enabled on one end. The tunnel suddenly went and the peer with no tunnel monitor is sending every 4 seconds a ikev2-send-p2-delete. What could be the reasons behind this behaviour? Regards
Good day, I need to uninstall Global Protect from bout 100 user devices. We deploy and remove application using Microsoft Endpoint Manager (Intune). I have created a script using this uninstall command:This command reported that it ran successfully on the devices and uninstalled Global Protect as intended, however when I logged into the devices,...
Hi, We are having a weird issue in Palo. We have a FTP server and we can not access because Palo detects this vulnerability: Name: SSH User Authentication Brute Force AttemptUnique Threat ID: 40015The Palo action is "alert" for this vulnerability but its being blocked "block-ip". I attach the screenshots: why Palo is detecting a normal access a...
I would like to have a miner to connect to the Pingdom API to pull a list of their US node addresses. The Pingdom API uses basic auth and requires an "app key". Their documentation references two HTTP headers, authentication and app-key: > GET /checks HTTP/1.1 > Host: api.pingdom.com > Authentication: Zm9vQGV4YW1wbGUuY29tOnBhc3N3b3J...
Starting with PAN-OS 9.0 there is the ability to assign specific agent configurations based on software and app settings on GlobalProtect portal configuration.It's possible to collect registry data from Windows endpoints under the new tab "Portal Data Collection". Now my question. Is it possible to see somewhere in the logs what data was collect...
My company are going to migrate upgrade one firewall from 6.0 to 10.1.And I found below KB points out the supported payload options above and below PANOS 7.0.Several IKE/IPSec profiles are using aes128 for ESP encryption, is it aes128 equal to aes-128-cbc?https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClYtCAK PAN-OS 5....
Dear all, I tried to register a device as spare via "Assets -> Spare" in the CSP, but instead of appering as Spare it is now listed under "Assets -> Devices" with an expired licence. I tried to open a support case via "Get Help", but because the device-licence is expired, i can't select the asset and im never able to finish the support for...
VM-300, 10.0.8-h4 on KVM.At one point issue with commit showed up:Error: Error reading signature DFA datafailed to handle CONFIG_UPDATE_STARTAlso updates for Wildfire & Apps/Threats were not being installed. HA sync started to fail.It was concluded that CTD resource usage is high - show system setting ctd state, Content Allocator Usage was 1...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 3 |

