Resolved! SFP Compatibility PA3050
Hi We have a PA3050, and we have 4 SFP like this: SFP HP X121 1G SPF LC LX So we would like to use 2 SFP to do a aggreagete link in PA. Is this SFP compatible with PA3050? thanks a lot
Hi We have a PA3050, and we have 4 SFP like this: SFP HP X121 1G SPF LC LX So we would like to use 2 SFP to do a aggreagete link in PA. Is this SFP compatible with PA3050? thanks a lot
Hello we have PA 5220and we need to connect SFP+ modules.We have Finisar SFP plus module but it does not workCan you recommendme any third party SFP+ module which is sure to work
We have an in house mail server which have different URLs to access its web mail and administration center. We want to block administration center access from Internet. I tried using URL Filtering but Palo Alto is not reading full URL and only showing host name in URL Filtering logs, I have also imported the the email server ssl certificate on P...
WE have configured OSPF between a Palo Alto firewall and the CORE to which it is physically connected, within this CORE there are several VRFs that interconnect with the firewall (VRF1, VRF2, VRF3). Is there a way to filter the default route in the Palo Alto firewall so that it is only sent to the interface that interconnects with the VRF2 in th...
We are using MFP for port 22.we have CP configured and also we have rule in PA to allow traffic for CP url on specific port.But we see no hit counts on this rule If i remove the rule then CP redirection does not work? Can someone please explain this behavior?
Is there any way to restrict amazon-cloud-drive-upload for certain websites? For example, say the website is www.mywebsite.com (public IP 1.1.1.1) and has an applet that allows users to upload files. When the user attempts to upload the files, the firewall detects this as application "amazon-cloud-drive-upload". You can't create a firewall r...
This is not a new setup. It was working fine before.No change was made recently.Firewall logs show traffic hitting the right policy, however from the same zone (NET to NET) instead of SZ104-ITSupport to LAN.How to fix this issue?
Hello everybody!PAN OS build 9.0.3-h3. According to the PAN documentation the "External Dynamic Lists" (Object-> External Dynamic Lists) )are supposed to use "External Dynamic Lists Service Route" (Device-> Setup -> Services -> 'Service Route Configuration'). This doen't seem to be the case since any changes in that area have no effe...
HiI have a firewall configured with different zones (users, servers-prod, servers-dev). At network configuration level, 4 network interfaces are linked to 1 aggregate group and under this aggreate group, I have on subinterface linked with each secuirty zone (ae1.1 for users, ae1.2 for servers-prod, ae1.3 for servers-dev). The 4 interfaces of th...
Hi,We are using Global protect VPN. Whenever we connect the VPN with office network the system gets slow and we run any command it takes a lot of time to run.Whenever we connect the VPN with an open network the commands and the websites are working fast. We checked the tracert with office network and home network and the in-office network it r...
Has anyone already got wifi calling via PA to run? I see in the session log the connections udp 500 and 4500 but wifi calling does not work on my iPhone 8. I have already excluded my AP, that's not the reason. At home router with itss integrated AP it ran - no problem. In which logs can I find something about this? I released ike and ipsec-esp-u...
Hi ,If anyone there who have a solution for this IPv6 IPsec Site -to-Site VPN Phase-I issue, I checked all the Phase-I and II parameters and took help from PAN TAC engineer as well. they don't have an answer for this. I am getting an this error. Your suggestion is highly appreciated! 2019-09-23 23:31:43.000 +0530 [PNTF]: { 116: }: ====> PHASE...
I have several customers (and my homelab) that leverage user certificates issued from Active Directory Certificate Authorities as a second authentication factor. Since upgrading to the new 5.0 client for iOS, the client errors out on connection to the portal, indicating that the required certificate cannot be found. If I attempt to connect to ...
I just want to make sure I'm thinking through the use of SIP inspection. If I have the sip application configured on a security rule, then the ALG will be in affect.If I have defined port-based services in a security rule with no sip application defined, then the ALG will not be in affect.SIP inspection will only happen if the application is def...
Hi Folks, I want to configure email alert for interface flapt i.e ( subtype eq port ). On email server profile under custom log format if I add $subtype eq port , would it be sufficient to trigger alert ?
| User | Likes Count |
|---|---|
| 6 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |

