Resolved! Pre-Logon Global Protect
Hi Can anyone explain the pre-logon feature that is now part of GP. Specifically how I could use it to launch AD login scripts one a user have authenticated via GP.ThanksRod
Hi Can anyone explain the pre-logon feature that is now part of GP. Specifically how I could use it to launch AD login scripts one a user have authenticated via GP.ThanksRod
We are planning to upgrade PA-3020 devices to PAN-OS 9, please advise either PA-3020 devices can be upgraded to OS 9PAN-OS 9.x is to use new features introduced in new OS like GRE tunneling, would you please confirm either our device PA-3020 support this upgrade? Model PA-3020
Hi, My PA-220's needed some SSH changes. After these were committed locally, I ran the "set ssh service-restart mgmt" command, as the manual says, in run mode.The firewall pings for about 30 seconds, then reboots. I'm using 8.1.13. Why does it reboot? How can I get around it? I have had a ticket in for a week, and the lady working the ticket doe...
Is anyone managing the application 'Square'? I am trying to get a better understanding how to identify the application being used for a transaction vs a website visit. A website visit to https://squareup.com/ triggers the application the same as a transaction occurring from what I can see. Definition: Square is a card reader tool and application...
Hello, i have a question about policy if i configure application - any & service - application default in security policy how does it work? is it the same as application any & service any? Thanks.
Hello all, I cannot install aws.AMAZON miner when I add it with the default config all minemelds is not responding and the minemeld's service is looping curl -k 'https://ip-ranges.amazonaws.com/ip-ranges.json' works the default config. the miner. Process looping.when I tried to check log : /opt/minemeld/log/minemeld-engine.log.1:2020-07-09T17:12...
we have set retention period for 1 day , but still config logs are showing of last 5 days in Panorama. As per tac this is the bug as they are currently analyzing the file.Also tried to delete all config logs of Panorama through cli but no luck. Below command not worked on M200 running on 9.0.9-h1 to clear config logclear log [ acc | alarm | conf...
Hi All, An object (IP address: 192.168.1.2 as an example) configured in the PA firewall and assigned it to 50+ security policies as a source/destination address. Now, I want another object (IP address: 192.168.1.5) assign into the same 50+ security policies as IP 192.168.1.2. What's the fastest way to do it? I can manually do it by going in each...
I work for a K-12 school district that uses a program that reads books to students. The file extension is .kes (KES is a file extension that belongs to Text Files of Kurzweil Educational Systems) and is blocked in our file blocking profile as an Encrypted ZIP file. Is there any way to allow the .kes file without allowing all Encrypted ZIP file...
Hi All, I am looking for a method to replicate the configuration of one of our virtual firewalls to a physical firewall through Panorama device-groups and templates. Let me explain the setup:We have a core firewall with multiple vsys enabled, and one of these vsys is our external (internet) vsys. Now due to capacity issues, we need to replace th...
In particular we discovered that methods of creating configuration backups are not consistent across the various management interfaces. It appears as if the most restore-able version of the backup has to be done from the GUI. The 'export'/'scp'/'tftp' command may be equivalent, however they do not seem to allow access to the auto-saved configur...
We have a Paloalto connected in vwire mode Cisco ASR1 is connected on PA eth1/21 (Primary) and Cisco ASA (Primary)is connected on PA eth1/22. Same as Cisco ASR2(secondary) is connected on ethernet1/23 and Cisco ASA(secondary) is connected via Ethernet 1/24. Interface are automatically going down and coming up Can any one suggest me why is going...
I have a IPSEC site to site VPN with a Check Point firewall. In the Palo Alto I have networks / proxy ID's that overlap each other? Can this cause issues? For example I have: Local Remote192.168.50.0/24 10.241.8.0/24192.168.50.0/24 10.241.0.0/16 B...
I have been using SSL Inbound Decryption for over a year with options1) Block sessions with unsupported versions2) Block sessions with unsupported cipher suites After applying Windows 10 updates to a reverse proxy server, it appears that connection to website is encrypted and authenticated using TLS 1.3, X25519, and AES_256_GCM (based on Google ...
Hello, I have one server belongs from the DMZ zone.Example:-server ip- 2.2.2.2source ip for VPN user - 1.1.1.1VPN zoneDMZ zoneThere is 2 scenerio:-policy(1) - I have created a policy like:-sourcezone- VPNzonesource ip - 1.1.1.1destination zone - DMZ zonedestination IP - ANY.Application - ANYservices - ANYAction - Allowno security profile. Policy...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 3 |

