Resolved! Proxy ID need and its requirement
Hello all, I am new to Palo Alto and in learning phase. Why palo alto works based on proxy IDs? is there any limitation on this.Please help.
Hello all, I am new to Palo Alto and in learning phase. Why palo alto works based on proxy IDs? is there any limitation on this.Please help.
Hi All, PA-3060, PAN-OS 7.1.17 Please see below: LACP:**********************************************************************************AE group: ae1Members: Bndl Rx state Mux state Sel stateethernet1/17 yes Current Tx_Rx Selectedethernet1/18 no Current Attached SelectedStatus: EnabledMode: ActiveRate: FastMax-port: 2Fast-failover: DisabledPre-...
Hi, We are facing issue with DNS Application, it uses more DP CPU Utilization 60 to 70%.We have done DNS Application override but no luck. Please find the DNS Session details below. Mem-Pool-Type MaxSz(KB) Threshold MinSz(KB) CurSz(B) Cur.Alloc Total-Alloc Fail-Thresh Fail-Nomem Local-Reuse(cache)dns 2048 80023 1024 830152 10012 279410 0 0 23472...
What do you guys do to send clear text or SSL decrypted traffic over to a nDLP for further action? In my case, the nDLP only support ICAP in order for it to accept traffic from its peering devices. Since PAN doesn't support ICAP at all and I am in search of an alternate solution. Thx!
We have a site to site VPN setup that was allowing one IP. On the ipsec tunnel sec proxy-id allow local (10.1.2.1/32) which was working just fine.We had to recently allow two more IP's 10.1.2.20 and 10.1.2.75. I Changed the ipsec tunnel sec proxy-id local to 10.1.2.0/32 to allow a range. When we made this change the VPN is enabled, but we are ...
Hi So, silly me I manage my cert in panorama, so when my int CA for my management ports came up for renewal, i renewed, and pushed out to all the devices ... except for my panorama 😞now I have cli access only.I have found the location configurepanorama certificate but when it comes time to add my multiline public key ... it will not take multil...
Is there a signature yet for CVE-2020-0688? https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0688
I'm using PA-3220 firewall.Ethernet 1/1,1/2,1/3,1/4 is connected to main switch, Cisco AP, Internal router and server 10Gb switch. I setup a GlobalProtect internal gateway for using User-ID and used vlan 1 (192.168.1.2) as the gateway and Portal's IP. When I used GlobalProtect to connect the Portal (192.168.1.2), it shows “Connection Failed – Pl...
Fellow Engineers - Wondering if there is a way to integrate User-ID with Google Apps, such that a school that has deployed Chromebooks can use the students' existing Google login IDs to identify the users on the Chromebooks. Does anyone know if this is possible, and if so, how to enable it? Thanks!
Hi All, I have successfully tested Authentication policy using LDAP, MFA (Okta API), SAML and RADIUS (Okta). I am working on the redundancy scenarios wherein if Okta fails, the fallback would be LDAP. I am using RADIUS (Okta) and LDAP in the Authentication Sequence. I am however unable to get the LDAP (Active Directory) fallback working. I am si...
Has anyone tried to get a userid authentication from users with Chromebooks? We are evaluating Chromebooks to be used in a laptop cart setting in our school. I don't want to fall back to a portal login if there is any way I can get a current user off the chromebook via the chromebook/google apps login session they will be using.If it helps, I ...
Can we configure shared gateway on a VLAN or subinterface? And HOW that vlan / subinterface can be used for Internet connectivity from different VSYSs? Please share the supporting urls for the same as well.
Hello all, I try to set up alert mail to prevent when my PA220 detects an threat (inboud attack for example). I configured scheduled PDF reports (daily and weekly) but I want also be informed instantly when a threat is detecting ? It is possible ? Thank you in advance for your help.
We are having some issues regarding the port redirection when combined with third party program. This program brings up a TCP listening port that TS Agent redirect to the designated port in the default range (20000-39999) but the program doesn't notice this redirection and keeps trying to stablish the connection on the non-redirected port (i.e:...
Hi community, I have followed this instruction https://live.paloaltonetworks.com/t5/MineMeld-Articles/Manually-Install-MineMeld-on-Ubuntu-16-04/ta-p/253336 to install MineMeld on the Ubuntu 16.04 server. All steps are good except the last step Checking if MineMeld running. I did the command and got the message$ sudo -u minemeld /opt/minemeld/en...
| Subject | Likes |
|---|---|
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |

