Required role to do cli backups
We have a process to do backups using the cli. I'm going to create a new role restricted to cli for this purpose. What admin role is required to perform backups?
We have a process to do backups using the cli. I'm going to create a new role restricted to cli for this purpose. What admin role is required to perform backups?
Good morning, We are trying to leverage as much functionality from our PA FW right now. At the moment we are using 3rd party filtering and 3rd party captive portal. The challenge is always matching the URL filtering logs with the user mac address. Is there a way to see the MAC address of a client from the URL filtering logs?
Hi, Just to confirm. it would be compatible this:UserIdagent in version 9.0.xand FWs in version 8.0.13 WE need to upgrade FWs to version 9.0.x, and we are thinking to upgrade first UIA, but we are not sure about compatibility in UIA two major higher.
Hi, I explain my scenario: We need a cluster A/P in 8.0.x. We had issues upgrading when the LACP didnt come up in the passive node jumping to 8.1.10.So in the last try we realised that jumping to base 8.1.0 the LACP interfaces were up. So we will do this upgrade path:8.0.13->8.1.0->9.0.0-> 9.0.9-h1. Customer has UIA 8.1.6 versionPanora...
Hello,If I have a policy for example that allows application "web-browsing" and service is "port 500" - does that mean that the rule will allow if the application is either "web browsing" OR "service 500" or the rule will be allowed if the application is "web browsing" AND "service 500"?Thanks.
Hello all, currently we use a Panorama VM running PanOS 9.0.5 in Legacy mode (did not even know that was possible) to manage a couple of HA pairs of firewalls. Unfortunately we are unable to edit the resources of that VM in our Hypervisor, likely due to how it was originally provisioned, so we cannot go the route of adding the needed resources f...
Hello,I would like to know if static route path monitoring can monitoring outside of the interface bound to the static route? For example, I want to monitor across a VPN tunnel and if the test fails, withdraw the static route so traffic fails over to the backup VPN tunnel. I don't have a IP addresses (within the tunnel) on the destination side o...
Hey there everyone. I wanted to let everyone know that the Cyber Elite experts are among our top contributors within LIVECommunity, and our first interview is with @MP18. Read the blog here: https://live.paloaltonetworks.com/t5/blogs/get-to-know-cyber-elite-mp18/ba-p/347622 Get to know more about him as he shares a bit of his background, ...
Hi all,I'm quite new using Panorama.I need to create a new network interface on a device managed by Panorama.I tried to modify the template but when I push it to device I got an error telling that there isn't that interface.Of course I miss something.Could you help me understanding what? Thanks
Hi,I would like to do url white listing. before i do white listing , i would like to monitor all url of users and office application.after that i would like to allow specific url only. In paloalto monitoring is only show destination ip address and never show the url. I would like to know can i mornitor the user access url and application access ...
When upgrading from VM100 to VM300, is there an upgrade SKU with discounted price or use the SKU# "PAN-VM-300-PERPBND2" with regular price? Thanks, Michael
Hello guys and Happy New Year!!First time when I use an palo alto device. So I configure this device PA-220, and I put it on my network.Everything works great but I have some problems; For example now all my MFP devices wont scan to email anymore. I use PAN OS 8.03. Some advices ?Thank you,
We've closed an office and took the two PA-500s off the network, and are now attempting to remove them from Panorama (following this procedure: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cmd6CAC ). Everything is good up to 3 a. Panorama Templates: Remove the device from "Template-Stack"...I have multiple devices i...
i'm have issues with IPSEC Tunnel which is configured by another engineer. currently facing issues with Tunnel connectivity and i need to cross verify the parameters. So can someone guide how to heck pre shared key in plain text format @IPSec IPSec S2S VPN between Palo Alto and 3rd party Security FW Vendor -> ISAKMP Negotiation Question regar...
Hi So I am doing some network segregation. I have vr with say 40 interfaces on it.I want to add 3 more.can i create a new vr (vr_b)place the 3 interface on the new vr (vr_b) and then create a vlan to connect vr original (vr_a) to new vr (vr_b) When do you create a new vr ?And what is the down side.
| Subject | Likes |
|---|---|
| 1 Like | |
| 1 Like | |
| 1 Like | |
| 1 Like | |
| 1 Like |

