Moving Panorama M100 function to M500
Seems M100 does not support PAN OS 9.0We have Physical M100 running as Panorama mode.Also we have M500 running as Log collector mode. Can we move config of M100 to M500 so they can manage all the firewalls?
Seems M100 does not support PAN OS 9.0We have Physical M100 running as Panorama mode.Also we have M500 running as Log collector mode. Can we move config of M100 to M500 so they can manage all the firewalls?
Currently running Panorama 7.1. We'll be upgrading to 8.1 in October-ish. According to the documentation for 7.1 and 8.1, you can create an EDL in Device Group A, and it will be inherited by all child device groups below it. This is working. According to the documentation for 7.1 and 8.1, you can check the box "Disable override" to prevent chi...
I dunno if anybody else has run across this or not but I just felt compared to share. I have been having fairly continious performance problems with a 5050 cluster and last night I isolated at least one culprit that's been adding to that problem. We are in the process of rolling out Windows 10 and a bunch of new Microsoft apps AND our firewall...
Hello Team, Can anyone provide a solution resolve below vulnerability in PA. Port no.: 443 Summary: Weak cipher suites supported Analysis :The remote host running SSL using a weak cipher suite which can be exploited by an attacker to perform man in the middle attacks. All the updated and secured services will be transmitting data over the unencr...
I've been experimenting with MineMeld and love it - brilliant product 🙂 That said, I'm struggling to get a clear idea what the size limit is of each blocklist. https://live.paloaltonetworks.com/t5/Learning-Articles/How-are-Dynamic-Block-List-Entries-Counted-on-the-Firewall/ta-p/62068 suggests even a PA200 can handle a list with 50k entries but ...
Configuration changes in case we move from 4 internet lines to one single internet line ?in Our Current scenario, We have 4 interfaces configured with 4 different Public IP address and each interface is linked to the different router( Internet),each interface has different services (Internet Email1, Email2, VPN) We are planning to get one new in...
I have found some issues in running HA Actvice/Active as it relates to config sync. It appears when a red dot on the firewall and an Admin connects their default reaction is sync config. So I noticed that something that replicated to the active-secondary was BGP peer groups which caused my BGP peering to become broken on my secondary PA. So I de...
Hi EveryoneIn my sinaro i have one internet line 10 MB and i have 5 zones configured in PA my question . and each zone for different purpose for example (IP SEC - Intenet -Email) 1- how i can provide the internet to multiple zones with a multiple services 2- How many Public ip address reqiued for this sinaro
Is it just me? I noticed that it became almost impossible to get a support person on the phone without being on hold for hours...When opening tickets online, it would sometimes take days to schedule remote session and some engineers just don't have enough knowledge.
We need to isolate the vendor traffic and we do not want this traffic to talk to our internal DNS server for DNS queries.Is it safe to use google dns server and then apply dns sinkhole?We can use the security policies app based and then apply app default.I can use all the security profiles for the security rules. This way can we protect the DNS ...
We have User where they access the Internet and traffic flow via say Corp PAWe have DNS server which is internal and the DNS traffic to Internet flows via say DMZ PA. On PAN OS 9.0 if i get DNS license on Which PA i should get for?As my understanding it should be for DMZ PA?
Is there a way within the palo alto firewalls to look at the active IPSec VPN tunnel throughput? I have a 3050 firewall with a handful of IPSec tunnels configured (individual and LSPVN tunnels) and I'm wondering how you would know if you were coming close to the throughput limit on IPSec traffic for the model of firewall you have.
I am really struggling with this. I have been at it for hours. I have two Palo Altos in standalone mode both forwarding traffic.I have connected to each palo cisco 9500s and Cisco 9300s. These are not fully meshed. So i know that I am going to need RR. I cannot for the life of me get peering to work on the loopback interfaces of the palos. The ...
Hi All,When you enable OCSP and CRL revocation checking on the firewall, if a certificate is revoked the default behavior is to block the connection. Is there any way to change that behavior so that maybe the revoked log is written in the system log, but still allow the browser to connect through. I was hoping it would be as simple as allowing...
is the right approach to simply download and install 8.1.0 and then download and install 8.1.8? Are there any "gotchas" i should be aware of?
| User | Likes Count |
|---|---|
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 |

