Resolved! Init session - Is TCP 3 way handshake gets completed here?
Init session info Does TCP 3 way handshake gets started and completed here?
Init session info Does TCP 3 way handshake gets started and completed here?
I have IPSEc ikev1 tunnel with vendor.Phase 1 and 2 are up and green. From PA from my Lan interface when I ping remote lan subnet ping does not work.I see no return traffic from vendor to PA. IS this normal behaviour to have Phase 1 and 2 up but routing does nor work both way?
Hello, We added a new VDSL Link on port 1/4 and created the PBF rule so that if the primary goes down, it will switch over to the backup. PBF rule is working fine and internet failover works okay. However, customer accesses an internal Server across the client VPN, and when we enable the PBF rule, all access to that server is blocked via the VPN...
Dear All, We require to monitor our VPN tunnels via the WhatsUp Gold monitoring tool, for which we would require the exact OID for our Palo Alto device. Kindly help in this regards. For this we can have a session with the Whatsup team. RegardsKarthikeyan
Hi All, Hoping an answer can be provided to this multi vsys Palo Alto I am deploying. I enabled the operational status of one of the virtual firewalls I am providing making it fully internet facing with Globalprotect operating on the outside interface. This is operating without issue. When I enabled this VSYS to an operational status I had to ma...
Hello Members,Please help me with a complete documentation on how to integrate AD using LDAP in PA-850 and there there asigning URL filtering rules on various category of Users Department wise. Please do let me know on any inputs required on this.. Thanks,Dev
Hi guys I started experiencing this problem in MM 0.9.52, my MM engine was restarting continuously. I tought it was some bug related with this version so, with a little bit of stress, I updated to 0.9.60 (I'm using CentOs), but I still get the same behavior. I even changed the config to the default one (few nodes - spamhaus etc.) but I'm getting...
So i have a Pa850, it has lots of vlans off it. 1 vlan connect to the other OSPF routers. I have OSPF on there. But what about the other interface - is it better to add them as passive OSPF or redistribute connected ?
Hi all, Look, I don't want to tell the good people at Palo Alto how to do their jobs, but it would be great if they could push https://knowledgebase.paloaltonetworks.com/ back online. I've been on hold for over an hour for basic information available (or not in this instance) from https://knowledgebase.paloaltonetworks.com/. The big take away fr...
Is it possible to create notifications when an EDL is refreshed? My security team would like to know so when they recieve the actual IP lists and URL lists that the PAN is getting updated at the same time. Thank you.
Hi all, Curious if anyone can point me toward amplifying info regarding Threat Vault signatures? From what I can tell, these generic signatures usually tend to generate false positives. It's hard to investigate why the alert is getting triggered when the Threat Vault only shows a hash without any context or information regarding why it's deemed ...
Hi All, I created a new policy to access apple-appstore for couple for users for testing purpose. Zone - trust to untrut zoneaddress - anyuser - user group nameapplication - apple-appstoreservice - application- default action - allow Looks like the users are not able to send their app to appstore for testing, any action to do that ?service is d...
Hi guys, I used to run standalone MM 0.9.50 with CentOS 7, perfectly. Last week I updated MM to 0.9.52 with the help of @lmori and the proccess was completed with success. See ( https://live.paloaltonetworks.com/t5/MineMeld-Discussions/Updating-MineMeld-from-0-9-50-to-the-latest-stable-version/td-p/245365 ). However since the upload my MM doesn'...
Hello, One of our customers moved from Checkpoint to PA and he's complaining about advanced search in the security rulebase.For example, he would like to search for and IP (source) with is used in an Address object or in an Address Group Object and with destination port 22 (example).If I put, for example, 192.168.1.0 in the search bar, the syste...
When I try to follow the article about support cases I get stuck on step 2 / 3https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClNSCA0I can see one of my firewalls and his serial, but I can't click on it.How can I solve it?I also tryed the support on the phone but I can't get to speak to anyone.Kindest Regards
| Subject | Likes |
|---|---|
| 7 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 7 | |
| 4 | |
| 2 | |
| 2 | |
| 2 |

