Resolved! Stripping prepended URL info
Does MM have the ability to remove HTTP:// and/or HTTPS:// from a list of URL's before creating the output file for EDL?
Does MM have the ability to remove HTTP:// and/or HTTPS:// from a list of URL's before creating the output file for EDL?
I have PAN running version 8.1.17 and it is configured with two DNS servers on the management interface, you know the usual, nothing special. I have security and NAT rule on the PAN firewall the uses FQDN. Is there a way to detect when the PAN fails to query the DNS server? Is there anything in the system log that will tell me the PAN can NOT...
Hi Community,We wish to add a batch of users to the local database, I'm just wondering if anyone has had experience with scripting this or doing this in batch. With the command "set shared local-user-database user testuser" it requires separate user input to add the password so this is out of the question. I thought the command "set shared local...
Hi everyone, We have our PA Firewalls in different countries all around the globe.Lets call them Country1, Country2. Country3 and so on.All locations are connected to each other via S2S VPN.We have Panorama in location Country1. And it manages firewalls in all countries over the S2S VPN.At all sites, we do have local admin accounts.Now, my conce...
Hi All, I use PA-220's in HA pairs often, and I've always used a straight-through cable to connect port 7 and 8 from FW1 to port 7 and 8 on FW2. I've never had ANY issues with this configuration. I just learned that PAN says to use a crossover cable when connecting the firewalls directly to one another like I have been doing all this time with ...
has anyone noticed that globalprotect portal allows a user to download the software without authentication? I'm running 5.0.4. Here's the exact link:https://{IP/FQDN}/global-protect/getsoftwarepage.esp .
I am trying to access http://www.brokercheck.com from behind the PAN firewall via dynamic NAT without any success. I have other customers behind different PAN firewalls, regardless of PAN OS version, with the same issue access website http://www.brokercheck.com. The FW rule is wide open "any any accept log" It works for customers NOT behind PAN...
Hi Guys,Just want to seek your inputs about what can be the best integration approach for this scenario.Currently, the VLAN gateway is in my core switch and I will be introducing PA FW into my network. I want to have control and visibility for my intervlan switching, will the virtual-wire approach be the best for this scenario? I am a bit not co...
I recently migrated a few HA pairs into Panorama in my environment. Historically, our security policies were configured to only send traffic logs from deny rules to our syslog. Any allows were only logged on the local firewall (due to costs of Splunk ingesting logs). It was simple to also send those to Panorama. However, I also want to now send ...
We then pass the data through http 2.0 in plaintext, the data length of http2 messages exceeding 65526 will be partially discarded, resulting in incomplete data and affecting normal operations.Currently, the solution is to turn off the HTTP 2.0 checks, not to do checks on HTTP 2.0, and the business is back to normal.May I ask if anyone has encou...
Hello all, I'm new in Paloalto firewalls, i'm doing a migration from Fortigate to PA220. i configured all interfaces, router... but I'm struggling with Policiesattached the basic policy i created to allow my LAN users to access internet:After testing the PA:users can only ping to internet eg: 8.8.8.8users can access website using IP address not ...
Hello community, I´d like to check with you regarding the following:Since upgrading the user-id agent from 8.0 to 8.1 the user-id logs in the firewalls are showing "Managed Service Accounts" (computer accounts with "$" appended at the end) in the way "domain\computer_account$" as well as the user account who logs into the computer.Does anyone kn...
Our GlobalProtect VPN was using a self-signed certificate which got expired caused end users not being able to connect to the VPN.This raises the question that what are the ways to get alerted for these sort of incidents. Is there any in-build mechanism on the firewall or the Panorama that we could use to get notified of the Certificate Expiry i...
Can we integrate clearpass as a radius server for Global Protect 2FA ?
I'm part of a cloud team that does not manage the FW but am not getting clear answers from them.My operations counterparts have the following issue: Support person logs into IP address x.x.x.x into production domain. As part of their function, they must RDP into servers on prod/dev/pat/sit domains. Each domain with a separate ID once the rdp cli...
| User | Likes Count |
|---|---|
| 5 | |
| 2 | |
| 2 | |
| 1 | |
| 1 |

