Resolved! Guide to updating an HA Pair
While learning more about Palo Alto firewalls, I put together a guide on how to update a pair of firewalls in HA.Hope it's useful, and I hope you like it! https://youtu.be/tPkMxJXIW7s
While learning more about Palo Alto firewalls, I put together a guide on how to update a pair of firewalls in HA.Hope it's useful, and I hope you like it! https://youtu.be/tPkMxJXIW7s
We see"Show system search-engine-quota" displays 480491MB of space, accounting for 66% of the document, and the detailed information(total size) displayed under search engine also does not reach 480491MB. Can you explain it? Thank youThe following is a screenshot of show system search engine quota.
the PAN-OS has upgraded from 8. 1. 9h4 to 8. 1. 14h2.The issue has been reported that users are able to connect the VPN via Global protect with their AD logins, but unable to access few web-based applications.The logs are not received by the firewall in the traffic monitor, At the same time packet capture was done and counters from the firewall ...
Created Dynamic Domain list, added single domain x.y.com > added list to antispyware profile > profile is used in policies but still the list shows empty. Also tries y.com still it is empty. Source URL is accessible an there are other IP lists in same location that are working. request system external-list refresh type domain name SINK-Do...
Hi Team, Does Paloalto NGFW supports GRE tunnel with Zscaler? Thanking You!! Regards,Om Prasad
Guys, facing a small issue hope can resolve togetherI have created a new network on PA as Layer-3(503) and am trying to communicate with my other existing layer-3 network (501):Steps configured are as follows :1) created Layer-3 ae4.503 with IP X.53.1 and existing is ae4.501 with IP X.50.12) Policy from both either network 3) Policy based forwar...
Hi, We dont have configured split tunneling for GP. We have 0.0.0.0/0. We would like to do split tunneling only for zoom-base.We tried to configure in GP gateway excluding the zoom ips but its still the zoom traffic reaching the PA, because IPs can change.Whats is the best way to split just for zoom or any app.
Hello Community Is there a way to restrict Global Protect client from being able to run multiple VPN's at the same time? We have 2 PA firewalls in different locations for different services, and do not want GP clients accessing both networks at the same time. Regards Andrew
Hi All, I have a customer that looses it's access to the Web GUI of the PAN Firewall except console connection. Aggregate Interface is configured. Can I assign an interface management profile via CLI on the aggregate interfaces? E.g. ae1.100? When i type set network interface aggregate-ethernet and hit the "?" I can't see tha aggregate interface...
We have configured the SSL inbound decryption.When we do the PCAPS on the PA we do not see POST message on the re and tx pcaps. Need to know is this default behaviour?On traffic logs we see decryption flag as checked.Also from CLI i verify that PA is decrypting the traffic.
Hi Team, we have firewall running version 9.0.6,9.0.4 and 9.0.7, well in this case what could be the suggested version of panorama?i have heard , panorama should run with same or later version firewall OS, Is it talking about the major version like 7.x,8.x or 9.xor talking about minor release?
Hi Community, All the agents in my traps setup on ver 4.2.5 shown as disconnected. As the issue looks like ESM server related, i have followed the document https://docs.paloaltonetworks.com/traps/4-2/traps-endpoint-security-manager-admin/troubleshooting/troubleshoot-esm-console-issues/why-do-all-endpoints-appear-as-disconnected-in-the-esm-consol...
Hello, I'm planning to upgrade storage capacity M-500.It's using 12 slots with 1TB disks, I'm going to insert 2TB disks to empty slots and replace 1TB to 2TB. As I know, after add new disks, panorama will redistribute existing logs.While that process, can I replace 1TB disk to 2TB? Thanks
Hi,Here I am trying to create a site to site vpn in Paloalto firewall, now in local network I have 8 individual /32 ips and for remote 10 individual /32 ips. This is for policy based vpn. Now if I add proxy ids for local and remote ips. I am getting around 80 proxy ids. Requirement is to only use ips not subnets. Now few connections are not work...
| Subject | Likes |
|---|---|
| 1 Like | |
| 1 Like | |
| 1 Like | |
| 1 Like | |
| 1 Like |

