IKE phase- 1 SA is expired every 10 seconds?
Just curious, has anyone every seen IKE phase-1 expiring every 10 seconds, can't seem to figure it out.Thanks
Just curious, has anyone every seen IKE phase-1 expiring every 10 seconds, can't seem to figure it out.Thanks
Could anyone kindly guide me through the process of registering for the Palo Alto Networks System Engineer PSE - SASE Associate exam via Pearson Vue? Your assistance would be greatly appreciated.
Hello everyone, I have some knowledge about PaloAlto NGFW but now I intend to focus and get some certifications. For that I bought a PA-440 which runs 11.2.5 and I intend to buy a second one which doesn't have an active license and running 10.2.3-h2. Both are from ebay, so second hand. Looks like I'm gambling if I want to buy a lab license b...
PA-440, OS 10.1.14, Standalone We just changed the ISP, the static IP in interface (WAN), updated the Virtual Router as well, NAT, PBF, Security Policy was checked, IKE Gateway. But we couldn't browse the internet. The firewall management GUI is also accessible by the WAN interface Before (from the allowed host), but not now. If i revert the s...
Hi everyone!I got error 1006. I really need help.Thank you!
We have previously purchased and licensed a VM series firewall using our parent company tenant (Company A) and email. However, when comes to license renewal, we have purchased it under our child company (Company B). We would like to transfer the assets from our parent company (Company A) to our child company (Company B) so that we can manage t...
How do yuo configure a correct FW rule to only allow downloads for a specific user from a specific URL, but the content is hosted on akamai networks ? I configred a FW rule with the URL of the server as FQDN in the destination field and allowed downloads but since the content is hosted on akamai, the FW rule is ignored.I don't want to give the u...
Hello all!I'm facing an issue which brings me to ask what the proper configuration should be for an outside interface. Given the attached diagram and captures, do I have the correct outside interface (vlan.100) configuration? diagram Outbound traffic from the local users is being NATed to 194.204.1.6 Inbound web traffic from the Internet ...
Hi all, I was hoping to get some clarification on http2 and firewall interaction. I understand that generally http2 works without issue as long as it's being decrypted. I also understand disabling inspection/decryption (Strip TLS ALPN) on http2 traffic can cause it to be downgraded to http1, thus defeating the purpose. But what if there's simp...
Working for a State Government agency, we are required to keep a record of any official electronic communication. Using public Instant Messaging services creates a problem for us in that we don't have a mechanism for keeping copies of any transactions which are part of a Public Record conversation.In light of this issue we would like to block I...
Hi, I have a test AD/PA setup.AD and LDAP connectivity is okay so far. My problem is that I am unable to authenticate any user against Global Protect.The un/pw are correct.The group are correct too, as far as I can see. This is the output i get when trying to authenticate: SITE1> test authentication authentication-profile AUTHPROFILE usernam...
Typically the ATP license would be used if we want to have the IPS features on the PA firewall. However, how do we configure the firewall if its meant to function as an IDS?
Hi, Is there a command to check if a tunnel went down on a specific time and why it happened. I have a tunnel set-up to a 3rd party where they keep monitoring some of their servers. They inform me that they receive alarms every hour that the endpoint is down and its not coming back up for about 15 min. I cant see anything obvious. I have done ...
I would like to know if it is possible to configure SAML to authenticate and in case something in the SAML part is not working, certificate authentication is used. This is for GP authentication. So SAML + certificate auth (backup option). I understand that i will need a authprofile with SAML auth. But where can i choose the backup auth by cert...
Attention: JAPAC TPM team Hello I'm Shono Kawaguchi. Please tell me how to stop the output of the following error. high userid cuid-conn 0 gRPC connection to identity.services-edge.paloaltonetworks.com:443 is broken, error: Feature is not enabled or device cert isn't available for CUID gRPC connection time: 2025-03-26 02:51:47 As long as...
| User | Likes Count |
|---|---|
| 6 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |

