Resolved! Clone a Device Group?
Hi Guys, I have Panorama with a few device groups; how do I clone one of them from GUI so I can do testing without impacting a production device group? Thanks
Hi Guys, I have Panorama with a few device groups; how do I clone one of them from GUI so I can do testing without impacting a production device group? Thanks
I'm attempting to factory reset a PA 200 that was on the spares shelf. The unit appears to be stuck in Miantenance mode, every reboot command boots in maintenance mode. I attempted to execute the factory reset and the message I get is: "No current image found, please use advanced options" So I click on advanced options and it asks for a pa...
Hi, I configured a PA in order to redistribute UIA mappings to another FWs. All the config is OK but its not working. I can see this in the FW redistributing: (active)> show redistribution service status Redistribution info:Redistribution service: downReason: internal error i tried to restart process UIA MGMTServer.... any idea about ...
I'm wondering if it's possible to modify alerts in PAN-OS. We've enabled email notifications for critical alerts and I'd like to change one type in particular. Our firewalls begin sending alerts related to license expiration 30 days in advance. Is it possible to change it to 60 days? Example Alert:SYSTEM ALERT : critical : License for feature wi...
Hi All, I have two 4G router and two ipsec vpn tunnel. Routers are exactly same.VPN configs are exactly same (except Ips) one tunnel up and running but other one failed at Phase1 It gives me "IKE phase-1 negotiation is failed. Peer\'s ID payload 192.168.225.100 (type ipaddr) does not match a configured IKE gateway." error. I global search on Pal...
I know you can import configuration snapshot from one model to another but what happens to the certificates? Does the certificates gets imported and still work just fine or do I need to generate a new CRS and import new certificates. Side note, the new box will have a different name then the old box. Going from a PA-850 to PA-1410.
Hi, We have 2 cluster firewalls with the same config for UIA and Group mapping. If i look for an IP. show user ip-user-mapping all | match IP I cant see a different behavior. One cluster shows user as use@domain and groups where this user belongs -> GOOD BEHAVIOUR Another cluster shows thee user as domain/user and this user donest belong ...
We previously had an SCIM integration with an old Azure AD tenant. Recently, we migrated to a new Azure AD SCIM connection, using the same user data (i.e., usernames and attributes remain unchanged).However, we have observed that logs are still showing references to the old SCIM source.I suspect this may be an issue related to User-ID mappings i...
I have configured DHCP on 4 interfaces, each DHCP on a different subnet. I connected each Palo alto port to a unique switch with the understanding that all devices connected to particular PA port will get ip addresses only from the corresponding DHCP but unfortunately the ip addresses are leased randomly. Scenario: port 1: DHCP pool (192.168....
I'm having an issue with a HA failover with 2 PA440s. When I finished setting up the HA for both firewalls the first time, I was not able to sync them, it threw me a strange error and after some research, I found documentation where it stated that I had to clone both firewalls from firewall 1 to 2. I did that saving the device state from the act...
I never received the link to download the Cortex XSOAR #community edition? any one knows how to get it
I can't find anything which goes into enough detail on Active-Active design around NAT and more importantly ARP. The easiest way to explain the current deployment is as follows: Site 1 / Firewall A Site 2 / Firewall B Each firewall is connected to unique networks and routers internally and externally. The expectation is to provide redundancy...
I'm having tremendous success automating security policy updates with the panos Python library, but I'm currently stuck on obtaining the hit counts of rules programmatically. I'm able to access all attributes of the SecurityRule objects, but the opstate hit_count attributes all come back as None. Relevant code; if type(rule) is SecurityRule...
I have a HA configuration in Azure. I’m trying to deactivate the HA configuration. If we shut down the Passive side in the Azure portal and delete the VMs, what will be the impact on the Active side?
Hi, I would like to configure SAML for my GP authentication and I would also like to be able to assign IPs by user groups and configure rules for these remote users by user groups. Does anyone know if this is possible? how can match users received from SAML with LDAP mapping?
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 8 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

