Resolved! Want to configure two different domain for LDAP Authentication.
Hi Team, Can we configure two different domain in PA firewall? will it work for global protect authentication?
Hi Team, Can we configure two different domain in PA firewall? will it work for global protect authentication?
Hello , We have currently three diffent zones defined . Zone A vlan 100. For wired users Zone B vlan 200 for wireless users Zone V tunnel/ loopback interface for Global protect users. All the above users mentioned are corp users. Now customer wants to create. single zone called "All users" and want to put vlan 100 200 and loopback/ tunnel into i...
VPN just kicked every off for a couple minutes. I had a dozen logs forwarded to me saying dns-signature cloud service connection refused. Anyone know if that might be the cause? When I was able to reconnect to VPN, the # of sessions was 3-5x normal and quickly dropped.
Hi Community,I am seeing the below behaviour in my PA-850 running on 9.1.4. Security policy is allowed for traffic.Scenario-1, without zone protection in internet zone - Everything works fin Scenario -2,Having zone protection with pretty much all options enabled for 'IP Drop' and TCP drop' and other options as well. Applied it on internet zone.E...
Hello, I'm still learning PA and I'm planning to create a pair in HA Active/Passive mode. I was planning on connecting HA1A, HA1B and HA2 to a Cisco switch. Each port on a different VLAN. I was then going to trunk this traffic to a Cisco router (ASR920). I'm then planning to link two sites using layer 2 MPLS pseudowire. As anyone experienced any...
Hi All, I would really appreciate if someone can let me know below details for PA5050 and M100. 1. End of life2. End of Support3. Replaced product Thank you in advanced,Gayan Samarakoon
Hi All, I have a PA-820 running 10.0.3. Lately my main connection was a DSL connection that limited me to 12/1 (on a perfect day). However I finally got on to the Starlink Beta, hung the dish and started getting items setup. When I pass any traffic through the PA, I am limited to <14Mbps down, <1 Mbps up. I have a very simplistic rule set,...
Hello community,I am attempting to create a VXLAN over IPSec solution between my PA-3250 and a remote Fortinet FortiGate 61E. I have managed to get things configured correctly on the FortiGate (I think) as I am seeing the traffic entering on the Palo side. I am using Tunnel Inspection on the Palo side and it appears to be set up correctly. In th...
Hi, Want to use ipv6 for bi-directional natting only for VC. Want to know the procedure on how to configure it. I have tried https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/nat64/configure-nat64-for-ipv6-initiated-communication.htmlthis link but when I commit the configuration it's got failed.
I have an issue where I click acknowledge alarm several times, but the firewall refuses to update the status of alarms to acknowledged. Is there some absurdly long undocumented lag? Anyone else have a similar problem?
How can I get PAN updates via the MGMT Interface if its on an isolated network inside my organization. NOTE: Its not on the internal zone. The route is working as i can see my packets leaving via egress when i ping from the host connected to the MGMT port. I want to avoid using Service route configuration via the external facing interface. Cheers!
The user was trying to send a mail from internal to external domain but it is blocking by sinkhole because it is showing as malicious traffic, however, we are able to receive from that malicious domain, Can we block reverse mail from an external server to internal using DNS license. In my case, it has received. Eg- User mail is [email protected] and ...
I have updated firewall contents to new version. After update also still I am not able to see newly added threat id under vulnerability protections profile under panorama. I can see those ids locally on firewall but not on panorama. Wha could be the issues? Any help would be much appreciated
I have an FTPS server behind the PA. When I enable either AntiVirus, AntiSpyware or vulnerability protection with default profiles it is impossible to connect to the FTP server over TLS. The below errors are seen. When I disable these protections I'm able to connect. Regards,Han. Command: PASVResponse: 227 Entering Passive Mode (xxx,xxx,xxx,xxx,...
Hi ,currently if anyone from public network uses the external IP of the firewall as a DNS server and try to send DNS query , my FW is responding to that queries which is high risk .how to stop FW from responding to any DNS queries knowing that the DNS proxy is not configured and our DNS security subscription is expired .
| Subject | Likes |
|---|---|
| 7 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 7 | |
| 4 | |
| 2 | |
| 2 | |
| 2 |

