When should I use "enforce symmetric return" in the PBF rules?
What is the purpose of this setting? Doesn't all traffic go out the same route as it came in, anyway?
What is the purpose of this setting? Doesn't all traffic go out the same route as it came in, anyway?
Client is testing 100Gb throughputs on a pair of PA-5450s. We added the PA supplied QSFP28-CWDM4 (Finisar) transceiver into the Cisco switch and the Cisco logs revealed the transceiver is incompatible. But, in order to do 100Gb on the PA it is required that the transceiver be QSFP28 - so the PA side doesn't have the option of using anything bu...
PA-5450 I need to enable the AI Access feature, then the PAN OS requirement must be PANOS version 11.2.2-h1. Currently PAN OS uses 10.2.9-h1, then I checked in portal Preferred it is still 11.1.6-h3. Please confirm to Palo Alto best practice, which OS version should I upgrade to enable AI Access?
Hi Everyone, I am unable to see on my Palo Alto Firewall PAN-OS 11.1.4-h13 on Monitor Data Filtering or Unifed when I was downloading an iso which file extension in the iso file is blocked. Nothing shows up as blocked and the browser stops the downloading at 224mb. Extensions that are blocked: 7z, bat, cab, chm, class, cpl, encrypted-r...
Hi Everyone,i am currently running 7.1.14 and am looking to upgrade to 8.08 with third part trancivers HPE X242 10G SFP+ to SFP+ 3m Direct Attach Copper Cable J9283B I read in the Upgrade/Downgrade Considerations Support for Third-Party SFP Transceivers https://www.paloaltonetworks.com/documentation/81/pan-os/newfeaturesguide/upgrade-to-pan-os...
We're configuring authentication and we have a requirement that Local authentication should not work if when radius is available. Team - is that supported of Palo Alto Firewalls? Let me know if that is possible or any documents would help us. Thank you
Hello Experts, Is UDP broadcast relay (not DHCP) supported by PANOS 11.1? There is a requirement to relay these UDP traffic: ip forward-protocol ndip forward-protocol udp 10001
I'm working on doing some clean up, and I want to take advantage of dynamic address groups. I have 943 address objects tagged and one dynamic group. When I monitor the logs, I see some traffic bypassing my rule and going to rules below. I checked the address objects and they are tagged.As a test I put all 943 address objects into a static group....
Now I can not download software version 11.1.5 or 11.1.5-h1 now. what's happen?
Hello everyone,I upgraded a Pan log collector to Software version 9.1.11 . Recently I receive the event "No valid device certificate found" . So I need to generate OTP certificate and install it . This can be done easily through GUI. However, with LogCollecor , Web UI is disabled and CLI is the only way to access the device .Can anyone guide on ...
Hello, I have two sites: Site 1 and Site 1, both running Palo Alto NGFW. Currently, traffic is routed between the sites via an IPSec VPN tunnel. However, we’ve recently set up MPLS between the sites and are planning to gradually migrate traffic from IPSec to MPLS. The challenge we're facing is related to asymmetric routing, where requests co...
I would like to ask again for PANOS version 11.1.5-h1, what is the current status? Is it still monitoring?
Hi, How can we know the frequency release version of PAN OS? Or just wait for new info on software release guidance eg version 10.1.14-h8 Version Represents Frequency 10 Major Version 1 Minor Version 14 Maintenance H8 hotfix (urgent fix on introduce issued) Thanks in advance!
They mentioned that based on this behavior in which they think that this is a : 1.-Threat identification.2.- VPN disconnection when using the sbs robot, which performs queries to a certain page located in the internal network of an entity (Judicial Power). 3. -Sbs query: add ip range in the policies so that a user group can access from vpn con...
I will have a single PA device in the cabinet, so no HA on my end. I understand the risks and this is not part of the question. Datacenter/Colocation is providing me dual ports into the cabinet and they are handling VRRP through their IP blend. They will provide me a /29 with the first 3 IP's being the VIP, R1 and R2 addresses. I am being to...
| Subject | Likes |
|---|---|
| 8 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 1 Like |
| User | Likes Count |
|---|---|
| 8 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |

