Rule tagging best practice and guidelines
Hi , Can someone share best pratices and guidelines on how to use tags on PA ?
Hi , Can someone share best pratices and guidelines on how to use tags on PA ?
Is it best practice to override template variable settings at the template-stack or at the device level? It looks like template stack would be sufficient unless you have multiple firewalls and only a select number with different settings.
Hello, In our lab, we made a set up about peering BGP between Palo and a third part device.According to this kb from Palo : "The Palo Alto Networks firewall does not advertise an aggregated route to its peer when it receives a prefix falling within the aggregated route range from the same peer" but in our case it's workingDoes it mean the KB is ...
We have found in the logs, Malicious DNS queries are being blocked but few of them are in Alert State. however the Domain is marked as a malicious in DNS signature at Threat Vault.Can you please elaborate why paloalto having dual action on same malicious domain.
Hi, I am trying to replace my ISP-provided Zyxel home router with a PA-200. I'm also subscribing to IPTV from the same ISP, with a Thomson DBI-8500E-TLN2 IPTV PVR.The zyxel - while branded, appears to run standard zyxel firmware - the config doesn't contain anything related to IPTV, but it has an "IGMP Proxy enabled" setting. Is there a way ...
I did not see any good information on how to fix this issue. I accidently entered the wrong subnet under Device > Interfaces > Interface > Allowed IP Addresses and was locked out of my primary firewall. I could still login to the backup as this was not a shared setting. I opened a support case and they did not offer a good solution to f...
Hi Team We are getting below critical alarm in firewall. Please let me know how to resolve this issue RegardsMohammed
When it comes to vm series firewalls, Layer 3 subinterfaces, trunks and port groups, are there any downsides/catches/cautions to setting the ESXI port group to use vlan 4095 (trunk), and then simply utilize layer 3 subinterfaces on the vmseries firewalls with 1 NIC? Article noted below, using just like a normal trunk if I understand correctly? ...
Hi, I'm looking to purchase a PA-220 lab unit (lab license) for home. Basically, using it for labbing with my personal internet/internal traffic. Are there limitations with that device/license, such as bandwidth limits
Hiho, I´d like to know how to see how much ipv4 adresses of the pool are in use or free so I need to know when to enlarge the pool.That dhcp redirect doesn´t work I unfortunately recognized while searching the forum regarding dhcp and gp.We are using always the prefered version of the 9er release. I wasn´t able to find relevant information withi...
Hello, I hope everyone is staying healthy. I work at a company that provides ISP services to public schools, each school district is divided in to separate security zones on our Palo and I am trying to see if a read-only user can be created that is able to only look at security and NAT rules for their assigned zone. I've been fiddling around in...
Hallo,I have defined a IPSec VPN connection with following params:ike: 3des/sha1/dh5 Lifetime: 8 hoursipsec: ESP/3des/sha1/dh5 Lifetime: 30 minutes (life size not set, shows 0MB)ike gateway: main mode, DP enabledThe connection is established but in system log I see very often (every 5 sec.) tunnel is again and again down and up. We have packet l...
Hello Team, I have tried to configure SNMP V3 to send trap messges to opmanager in palo alto. - At the tiime we struct with engineID,here we are unable to find engineID for Palo Alto in Opmanager. - And also SNMP Walk itself its not working.- Its seems something i was missing in the configuration.- Can anyone help me here on what are things need...
Maybe it's because I'm new here. BUT, every doc link I click on via a post in the Live Community gives me an 'Access Denied. You do not have sufficient privileges for this resource or its parent to perform this action. Click your browser's Back button to continue.'What am I missing? Please help.Below are several of the links I've tried and all g...
Hi community,I am facing a weird behavior that is driving me nuts.I have 2 sites linked by a Leased Line (zone L3-GW-InterDC) and an IPSec tunnel (zone L3-VPN) as a backup. 2 static routes are therefore configured, with different weight and path monitoring. I don't use PBF in this setupEverything works fine, except for this traffic between 2 hos...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 3 |

