Resolved! DNS Security service
Hi All.Can any body know if the DNS Security Services have possible to enable and subscribe on Virtual Wire deployment?Thaks
Hi All.Can any body know if the DNS Security Services have possible to enable and subscribe on Virtual Wire deployment?Thaks
Hi All, We have 04 IPSec VPN tunnels created on our PA FW with Public Cloud configured with BGP. (All these 04 Tunnels are created over single Internet link). All 04 peering IP of public cloud belongs to same region. Pl note that these tunnels are in pair i.e. 02 tunnels are configured Active-Active (BGP) and redundant to each other to achieve ...
We have: MDM: FilewaveiOS: 12+GP: 5+ When an iPad is rebooted, GP doesn't auto reconnect & must manually be opened/connected again. Any ideas how to get it to actually always auto reconnect? We really only care about the user identification being automatic.
Hello,I am setting up VPN on the Palo Alto. So far, I was using a local user database and it is working fine. I will need to move to AD authentication and tested ok. However, the issue I am getting if that I can use only one type of authentication at a time by moving the authentication profile type up on the GlobalProtect Portal>Authenticati...
Hello, I have a problem with configuration of user identification in security policy. What is the target: for some users who login to VPN via GlobalProtect I would like to limit them to some specific subnet. Users login to VPN using their Active Directory accounts (via Radius). I created LDAP profile, group mapping and security policy (with sour...
Can someone suggest on how can we disable TLS 1.0 & 1.1 for port TCP-3978 Description: The remote service accepts connections encrypted using TLS 1.0. TLS 1.0 has a number of cryptographic design flaws. Modern implementations of TLS 1.0 mitigate these problems, but newer versions of TLS like 1.2 and 1.3 are designed against these flaws and s...
Hello there, Here I have deployed a set of secure rules for Office365 follow the official Paloalto guide. Now we encounter problem with office365 when ssl-decryption is enabled. Some users cannot activate office365, please refer the error as below. So is it safe if we make a not-decrypt policy for O365's URL using Minemeld? Thank you for any a...
Hello! somewhat new to the community, I used to have a login but didn't login forever...Just something that you might want to know if you are ever forced to add pinterest to a custom URL category, you will also need *.pinimg.com in the category to make it work. Here is what I used in the custom URL category:pinterest.com*.pinterest.com*.pinimg.c...
I need to configure MFA for administrator login, we would prefer second authentication through e-mail or any mobile APP token.I am unable to find exact document to configure , could you please help us to configure MFA in our Paloalto device.
When i import my HA pair of firewalls into Panorama (9.1.3), the resulting template includes values for HA config. I would like to leave HA config up to the gateways themselves and not include it as part of the template. How would i delete that part of the template? If i set values to their defaults, that part of the config still exists in the ...
Our pki team has setup a scep/ndes server for us to use for new firewall we setup. The error i get in the gui is not saying anything. If I would like to start a debug on the firewall cli for scep. Where do i do that?
Since i can see the stable version mentioned for panorama is 9.1.4,but when i go to support portal under panorama base images to download 9.1.4 i cannot the file...i am looking to install it on vm/esxi. Let me know the stable version from 9.1.x and 9.0.y family according i will install and also chose image for my firewall also
We are currently looking at updating our global protect client and would like to get some guidance on what version we should be updating to, ideally a client that may support MacOS Big Sur when it is formally released. With the global protect client is the latest and greatest considered stable for production or is there a preferred release? We a...
Hi,We have observed that “activating” a GP client version is not captured under configuration logs. Is this because no commit is required for such an action? Is this expected behaviour? How can we check on the history of such a configuration change? Are the other actions that will also not be captured in configuration lo...
Hi Folks,We currently have a primary direct internet from the ISP to the Palo Alto PA-200 configured with LSVPN .As we plan to have a secondary Internet, we want to connect the Palo Alto PA-200 with 4G Router using LSVPN as well. The problem is the public IP address is assigned to the 4G router and we'll connect it via LAN With PA-200 as the dia...
| User | Likes Count |
|---|---|
| 5 | |
| 2 | |
| 2 | |
| 1 | |
| 1 |

