Block Tor application traffic.
Hi We are planning to block Tor application traffic in our PA device , so do we need to write security policy in both the direction and also share the steps to block the traffic in Palo Alto device. Thanks,Yusuf
Hi We are planning to block Tor application traffic in our PA device , so do we need to write security policy in both the direction and also share the steps to block the traffic in Palo Alto device. Thanks,Yusuf
After the device PA-500 is upgraded from 7.1 to 8.1.15, the radius authentication of the user name and password of the device fails, and we can only log in to the device through local authentication. After performing Radius-related configuration according to the configuration guide, the account login still prompts "invalid account or password" l...
We updated the 2 pair of Firewalls on last sunday to 8.0.15 and after that our CACTI stop to show the interfaces statistics from PA-5020.Cacti is monitoring the updated PA-3020 correctly. The issue only happen with PA-5020.Did anyone experience something related ? Regards,Marcelo Castro
Hi So I have 1 internal address that when it goes out via the PA to the internet (SNAT) i want it us a specific route - net hop. So it looks like I can't set pBF on source address (SNAT). has to be on the original address.and I can't specify outbound internet
Hello, I have read the Administrator's Guide and the Use Cases for Active/Active HA but just wanted to get some confirmation that I am understanding the requirements correctly. We have two identical Palo Alto firewalls that we want to setup HA with. We will be configuring a Layer 2 Aggregate Interface with subinterfaces and then connecting it to...
I have the GP Linux CLI client working without any issues, however I wanted to test the UI client that just came out (5.1.0) Does anyone know how to actually use this? The PAN documentation has not been updated to mention this new version or the Linux UI yet. Installing it goes fine but I do not see anything installed to my desktop and when atte...
I'm currently sending FW logs to Azure Sentinel, via syslog over SSL to an r-syslog server with the Azure agent on the syslog server forwarding logs to Sentinel. I followed the documentation, format is BSD header with custom CEF format for the logs added. Using local4 facility on PA side as well as r-syslog server. Logs are getting in, but they ...
Hi,We have user identification working nicely using user ID agents on a few of our active directory domain members.I've been looking at MS Direct Access (and formerly UAG) and it seems that a DA implementation would show all connected users as having the same source IP address and therefore user ID. (The private IP address of the DA server.)Do P...
Hi All, I hope all are doing well. I am trying to block a URL on palo alto firewall using custom URL category but firewall is not blocking the traffic and its passing through allow SSL/Web-browsing rule just below it. This is the rule i created: Rule 4 is allow rule to access websites, whereas rule 2 is used to block the URL - https://natboard.e...
Some of our users are getting password expiring msg when they are connecting via GP but when we checked their ldap accounts the password is set to never expire.PANOS version is 8.16-h2 and Global Protect Agent is 4.1.10 is there is bug.Please suggest
we get a lot of site disconnects and backup reports that are constantly in a state of being disconnected this will effect performance as the connection gets closed. please advice. thanks
In the Cisco ASA at the CLI there is a command to not display names but their IP addresses: no names.Is there a similar command in PAN-OS; I'm using v 8.1.13? My goal is to list/export NAT policies without names as the individuals who will review this will recognize IP addresses.Thanks for any help. Jeff
Hi, I have allowed a FTP session. However, the FTP session does not connect. When I search the logs, the traffic is allow however the session end reason is tcp-rst-from-client. Please advice. Thks and Rgds
Hello,someone know what means this counter increasing?appid_post_pkt_queued 4294967293 826432036 info appid resource The total trailing packets queued in AIE and this?dfa_sw 4415 849 info dfa pktproc The total number of dfa match using softwareaho_sw 4410 848 info aho ...
One of my customer is requesting me to track user IP address when he move from his desk to meeting room, and vice versa.He carries his laptop, he use same ID account on AD, but his IP address will be changed when he moves around. I know he needs to generate EVENT LOG on AD to pick up the latest info by UIA, but I have no idea how to...Does he ne...
| Subject | Likes |
|---|---|
| 1 Like | |
| 1 Like | |
| 1 Like | |
| 1 Like | |
| 1 Like |

