Resolved! How NAT Oversubscription works?
Hi experts, I am trying to understand how NAT oversubscriptions works in Plao Alto. What will be its exact use case and how firewall behaves in default settings?
Hi experts, I am trying to understand how NAT oversubscriptions works in Plao Alto. What will be its exact use case and how firewall behaves in default settings?
Hi,I am setting up a PA-VM50 that is in an isolated environment solely for testing any changes before we deploy to our production physical Palo's managed by Panorama template and template stack in a device group.I would like to save myself a heck load of time by being able to import most of the object configuration and pre-rulebases. I don't min...
There is no workaround available for this vulnerability https://security.paloaltonetworks.com/CVE-2020-1981A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation.This issue allows a local attacker who bypassed the restricted shell to execute commands as a low privileged user and gain root access on the PAN-OS ...
Hello community,Is it possible to Block File transfer over Remote Desktop
TCP 3-Way handshake – TCP is a connection-oriented protocol, a connection needs to be established before two devices can communicate. TCP uses a process called three-way handshake to negotiate the sequence and acknowledgment fields and start the session. Here is a graphical representation of the process. The three way handshake process consists ...
Hi Everyone, I have two IP addresses used for inbound/outbound emails on our email gateway.I have created the attached rules NAT and Security and I wanted to get opinions if its correct because I tested it and it seems something wrong that prevent emails from in/outbounding and even the web mail access did not work...your advice please.thanks
Hello Team, I have a question regarding drops during the packet capture. What is the packet drop means - Firewall dropping any packet or firewall detect drops packet.? Once i performed the packet capture at the same time i have run the command global counter but i didn't get any drop in counter. So could you please let me know what is the meanin...
Hello Everyone I have simple but very important questions about an eventual Zone Renaming in a Template commited and pushed from Panorama to a Managed devices: 1. Changing Zone names inevitably will have an impact on an active sessions ? https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm1cCAC 2. In PAN-OS 9.0 could I ...
My environment has Palo Alto Firewalls that has Aggregate Interface configuration and use. There are infrequent issues with them and I have some questions:What are the tools for trouble shooting Aggregate Interfaces within the GUI (web interface)What are the CLI commands for trouble shooting Aggregate interfacesThanks in advance
Hi, We have issues with a service using GP. To solve it we add the IP Palo GP tunnel in the PanGP adapter gateway in local machine. Why this is happening? is there any way to configure this pangp gateway from palo alto when user connects in GP?
I know the question about how to set Reconnaissance Protection thresholds has been asked dozens of times. The answer is always "it depends on your environment and situation". I understand that there can't be a one-size fits all best practice. It seems as though a trial-and-error approach is how you should dial in the thresholds and intervals.B...
Hello - Will enabling any of the logs like traffic, url etc in the web UI in admin role profile give more than read-only access to the users with the profile? Asking because I don't see read-only option, just enable and disable. Thanks - Jisha
While migrating from checkpoint to Palo Alto after defining zones and interface.Can I simply use any in source and destination zone and create policies with specific objects in source/destination address.Will it work, for replicating same policies while migrating from checkpoint to Palo Alto.
Instead of seeing alarms when I login to the web GUI, how can I get alarms forwarded? I'd like to send to SysLogs and also receive via email.
Is there a way to see the BGP prefix before they've been processed by the IMPORT or EXPORT rules ? Thanks,DL.
| Subject | Likes |
|---|---|
| 7 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 1 Like |
| User | Likes Count |
|---|---|
| 7 | |
| 3 | |
| 2 | |
| 2 | |
| 2 |

