Resolved! Upgrade path to PAN-OS 8.1 from 8.0.4
Which is the latest maintenance release from 8.0.4 to 8.1? I can see on my firewall that 8.0.19-h1 and 8.0.20 are available. Thank you,
Which is the latest maintenance release from 8.0.4 to 8.1? I can see on my firewall that 8.0.19-h1 and 8.0.20 are available. Thank you,
Have had an open case with support since August 2019 with HIP checks setup for Global Protect. There are options to allow HIP checks for a large number of different AV vendors and their products. The issue we have come across is that we have defined specific AV vendors that can be used and all others are denied. The vendors we have allowed we...
Hello,I am trying to establish a successful VPN connection between my Palo Alto firewall and a Check Point firewall. The VPN tunnel on the Palo Alto side shows all green for phase 1 and 2, however on the Check Point side I keep getting a failure per the log "IKE failure no response from peer".In the "Monitor" > "System" log of the Palo Alto t...
Hi Gang, Excuse me for my ignorance. We had firewalls Palo literally thrown at us, and instantaneously put into production (not great!). I have a pair of Palo's in HA Active/Passive with preemptive enabled on active/primary. These are in turn, patched to an INET switch (internet handed off via a single ethernet patch cable to this switch). We ...
Hi, I was wondering when I went through the bootstrap documentation, it mentions that it should display logs of the bootstrap even if successful but in either case, nothing appears on the console, not even a single word about bootstrap... where should this be displayed or how can i check these logs?
Hello, I am trying to create rule that allowed specific users from the active directory. Strange enough on the rule, i am unable to get active directory users. Please advise
I have one more query, If I change week encryption to strong encryption in tunnel traffics like Global Protect, IP sec tunnels, will it get affect the clients ??Of course We have to check the peer side before we change the encryption methods & algorithms for IPsec tunnel but what about global protect ??If we change the GlobalProtect IPSec Cr...
Hello Folks,I'm planning on getting two new Palo Alto firewalls for setting up IPSec tunnels. I think the first tunnel will be a primary tunnel and the second tunnel will be back up. I'm tempted to set up my new firewalls as active/passive HA, to make life easy. But to be sure, please could someone suggest what are the advantages of using active...
Sorry if this is a dumb question, I'm still a bit new to PA. I've recently had a case where a few workstations cannot access anything beyond the local network. A trace shows that they can reach their default GW, but not the next hop, which is the PA. As a workaround, I found that changing their IP address resolved the issue. I then found that if...
In our system log of the PAN5250 with PAN OS 8.0.15 i see the following critical message : ntlm exited 4 times must be manually recovered. Does anyone has the same issue or knows how to handle this. I can't find how to manually recover this and where this is coming from. Thx for the help in advance 🙂GreetzManu
Running software version 8.1.10 on this PA firewall.I have the TLS syslog server profile setup in Configuration type logs and that works (getting config logs).Then I setup this log forwarder profile that has both TLS syslog and UDP syslog server profiles.When using adding logging for each line of policy to log on session close with the aforemen...
I've been looking at our PA, and I've found that it's detecting viruses being delivered in SMTP traffic. The PA is alerting, but taking no further action. Looking at this guide here, I understand that Palo Alto have this set based on the best recommendation at the time.https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/policy/best-practic...
There is a new Customer Advisory "Content Delivery Network Infrastructure Update".https://live.paloaltonetworks.com/t5/Customer-Advisories/Content-Delivery-Network-Infrastructure-update/ta-p/307121 We use AppID "paloalto-updates" to allow download of updates. Does this need to be adapted? The firewall devices are configured to use update server ...
Heya Gurus!I'm running into an issue that I can't seem to figure out. I helped a client migrate a firewall over from Checkpoint to PAN. A few false starts and we got it going. Now we are working through the 'b' list of items that needed to be figured out and tested.We have the GP portal/gateway configured for LDAP/AD authentication, and the a...
I'm trying to filter out unneeded/unnecessary indicators from our O365 feed, but no matter where I apply the filters I am still receiving all of the indicators. For example, I would like to filter on only indicators available over Express Route, and in the JSON you can see that 'expressRoute' is an available field with a boolean value of eithe...
| Subject | Likes |
|---|---|
| 1 Like | |
| 1 Like | |
| 1 Like | |
| 1 Like | |
| 1 Like |

