Mitigating CVE-2019-0624
HI @reaper , @gwesson I'm seeing the subjected CVE is missing in palo alto vulnerability profile. How can I mitigate this vulnerability. https://nvd.nist.gov/vuln/detail/CVE-2019-0624RegardsVenky
HI @reaper , @gwesson I'm seeing the subjected CVE is missing in palo alto vulnerability profile. How can I mitigate this vulnerability. https://nvd.nist.gov/vuln/detail/CVE-2019-0624RegardsVenky
Hi Community, Hope somebody can address my below query.I am able to see the Release date of App&threat version 8146-5421 as 2019-04-25 UTC in both threat vault and support portal( is it actually UTC time??, i am seeing 1-day gap here !),But my firewall have the details pf release date as 2019-04-26 07:24:00 GST (2019-04-26 in UTC aswell). I ...
Hi Team How to block the XLSM, AHK extensions in firewall? Please help us RegardsMohammed Asik
I've been trying to figure out if you can add custom reports to the PDF summary report or how I can group a list of reports into one PDF report. My CIO likes the summary report but would like it to be monthly or quarterly and I'm trying to figure out how to reproduce that. Thanks in advance.
i have a small new palo alto , i have read i should use mgmt port for HA1 with the second palo alto , but if i do so how can i make up for the mgmt port important functionalities like updates and dns if i use it for HA? im confused
this is my first time deploying palo alto , is it important to have the managment port connected? does it play important role in the device function or is it just solely for managment?like can i manage the device from the inside interface only?
We have PA in active passive mode, We have ipsec connections going to end devices.When i check the passive PA GUI I see All Phase 1 connections as redAll Phase 2 connections as green IS this normal behaviour?
i have a core switch and a router which connects to other router to reach the internet , i was wondering if i put the palo alto as a VWIRE between the core switch and the router would i be able to control which ip addresses can go to the internet and which cant? like create security policy rules for ip addresses on a palo alto set as a Vwire?
I know there have been several messages about this issue, but so far, the only solution Palo Alto has given, is to update to a new version. We have followed PA suggestions and months after the update, the issue starts again and their solution will be to update to a new version. Firewall model: PA-5060Software version: 8.1.10 fw1(active)> show...
Hello, We are planning to use Faster Link (400MB) as our primary link in our org.Once we get this link running, we can get it setup with GlobalProtect and start setting up the remote sites to connect to that link as a secondary tunnel until we are ready to flick the switch and make it a primary. Below are some questions we got. 1. Is it possible...
Currently, in our schools, we use Squid+DansGuardian for basic web content filtering (URLs, phrases, domains, client users, and client IPs). We use Squid for handling the HTTP requests, not for any local disk/mem caching. It appears that most of this can be handled by a PA firewall with some LDAP hooks into the school Linux server (URLs, applic...
Hey all, I have a PA-220 that has the Alarm LED lit. The cause was that someone tried to insert a power supply from a PA-200 into the PA-220. Thinking that what happened is that a brief short was created which triggered the alarm. All other LEDs are good. Anyone know a way to turn off the Alarm LED or clear it from the CLI or GUI? Thought m...
Hi, We have a setup in which a switch is used for interconnecting several virtual systems to a perimeter router. The switch is going end of life and needs to be replaced. Is it possible to replace this switch with a "Virtual router" in Palo Alto?Below is the setup: 1. All virtual systems have their own virtual routers. 2. Default routes from th...
Hi, I've configured my VPN tunnel to use IPSEC. However, immediately upon logging in the session switches to SSL. I'm wondering if anyone has experienced this.
Hi, I currently manage a group of Palo Alto FW Devices (5220, 800, 3200 and 200 series) via a Panorama M-100 Series Appliance. I would like to know if Panorama pushes automatically PAN OS SW Update (at the PAN OS - level only - not AV, AppID or Wildfire signatures) to the managed devices (after having them downloaded from the internet, hence ass...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 8 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

