HA Setup
I have firewall in HA(A-P) mode.If device priority is same on both , will there any delay in switching A-P role during failover activity ?
I have firewall in HA(A-P) mode.If device priority is same on both , will there any delay in switching A-P role during failover activity ?
Dear All, As I have always been practicing to do the configuration and changes on the primary device and then it is its responsibility to push the configuration on the secondary device but as I have also been seeing people to do the configuration on the secondary devices be it juniper, F5, Palo and they really don't consider this active passive ...
Hello Paloalto Team Last thursday you published the securityadvisory for a critical RCE vulnerability and today you notified the customers again with an "Action recommended" article here: https://live.paloaltonetworks.com/t5/Customer-Advisories/Action-Recommended-Recent-Security-Advisory-PAN-SA-2019-0020-Ref/ta-p/278505 In this article you write...
We have vendor traffic coming to PA and session end reason is threat.Under threat i can see the threat id numberThey are lot of them For easy way I have disabled the security profile vulner protection for that rule. Need to confirm by doing this PA should not end the session with threat right?
Hi Team, When I'm trying to connect global protect from agent it gives an error "Could not connect to gateway contact your IT administrator". When I dig into debug logs, i found below intersting logs. (T3120) 08/06/19 12:56:14:274 Debug(4388): SetGatewayRoute: GetBestRoute() returns Dest:0.0.0.0 Mask:0.0.0.0 if_index=12 metric1=50(T3120) 0...
For threat logs in PA i see below options ( subtype neq vulnerability ) and ( subtype neq spyware ) and ( subtype neq packet ) and ( subtype neq scan ) need to know if this makes sense ?? where vulnerability is part of vul protection scecurity profile which is layer 7 ?? spyware is anti spyware profile which is also layer 7 ??? scan and packe...
Hi, Recently we had to upgrade our customer PA-3050 from a 8.0.10 to 8.1.8 version.After we did it everything works fine, but when they did a commit of the configuration a lot of Aplication Dependency commit Warnings appears:We check all the policies and in every one all the applications are included. Anyone knows why this happened and how to so...
Hello All,I was in the process of upgrading our firmware of our PA500 to 8.1 and when the device rebooted, it did not want to come back online. Checked the startup and noticed I was getting this error message. I did read online that it might be an issue with the hard drive? Is there a way I can resolve this? I cannot even get into maintenanc...
Hello,I'am planning to install a monitoring tool, and i need critical system logs generated by the PAN-device. Is there any docs that mention it?Regards.
We have 2 VPC each having Palo alto VM-100 hosted in AWS ,both VPC are having overlapping subnet and we are try to setup ipsec site to site vpn ,kindly let me know the fesable configuration solution with configuration example if possible.Thanks .
When connecting WildFire Private Cloud to firewall (Device > Setup > Wildfire), It appears that we can only add one (1) appliance IP address. However with a cluster there's more than one appliance.1) Should this be the management IP address of the Primary cluster member?2) How does the Firewall know to send traffic to the other appliance(s...
Hi Community, Does disabling HA using the master switch ( Device -> High availability -> general -> setup ->enable HA checkbox) will cause the interfaces to go down and up ?. I understand that the interface mac has to be changed from virtual to physical one, does it cause a flap.I have faced an issue that disabling caused aggregate i...
I was attmepoting to configure Minemeld to pull AWS ip addresses, but nothing happened when I hit commit. I noticed the Supervisor had stopped, and came across this earlier article. I issued the commands: sudo service minemeld stop sudo service minemeld start sudo -u minemeld /opt/minemeld/engine/current/bin/supervisorctl -c /opt/minemeld/local/...
When I click on the icon to open a web page in a report, it takes me to a "whois" page. I would like it to rather take me to the website.Is there a way to customize this behavior? I would appreciate any help, thanks!
Hi Team We have configured the one Destination NAT policy. My requirement is Ping the NAT IP (Public IP) from the external network. I have configured one security policy with application as 'ping' and service as 'any'. For the above configuration, I can able to ping the Public IP from the external network. But I want to allow the specific servic...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 2 |

