Recommended PAN OS 8.1.3 or 8.1.4 ??
Hi All, What will be the recommended PAN OS for Perimeter firewall ?? 8.1.3 or 8.14 . I got the update from support team as 8.1.3 is not a stable but initially it was suggested by SC. Thanks in Advance
Hi All, What will be the recommended PAN OS for Perimeter firewall ?? 8.1.3 or 8.14 . I got the update from support team as 8.1.3 is not a stable but initially it was suggested by SC. Thanks in Advance
Historically, for a LONG time, we have created an object for every IP address and every port (for port based rules). Over the years, this has lead to our config being HUGE. Last tech support file from Panorama is 85MB. With thousands and thousands of objects, my opinion is that's contributing to the performance issues we see; the fact that al...
Having issue to install the MM behind the proxy, the IP address of MM is whitelisted for any proto/url in the proxy configure.While the installation is started thru the command sudo apt-get install minemeld I do see the requests from MM is comming to the proxy and the process of the install seems like goes well enought until at some points it f...
we have configured url filtering where certain categories are blocked and user get the response page.but under networkinterface management profile the response page is unchecked need to know how without checking the response page users are getting response page that certain site is blocked?
After click "Check Now" in "Dynamic Updates". Show the error popup as below linkhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClkuCAC The above KB not apply to my case. As I not allow my management interface to reach internet.So I go to customize "Service Route Configuration", and set the Source Address of Service - "...
Hi ! We configured Windows User Agent for the IP-to-User Mapping to apply the AD group based policy. User Agent is fine and IP-to-User lookup forwadred to firewall . But the problem in the user format. Some user's mapped in the format of netbios\username ( AD\user1) and some of the user's mapped in the format of dnsdomainname\username ( AD.ex...
Hello, In PANOS 8.0.8 release, now can disable or enable the L4 checksum checking. How do I check if my 5200 firewall L4 checksum is enabled or disabled? How do I check if traffic is dropped due the L4 checksum? Thanks, E
Hello, I have generated the User Activity report, just wondering whats the count column in the report? Is that the number of time the user has visited the site? Also some category has 2 counts and browser time 0:00:00 what does that mean? Total time is showing: 7hours and 3 min. Does it mean the user spent that much time in all the categories? H...
Hi teamHow can I implement in the Global Protect confuguration the use of client certificate and LDAP authentication as two factor authentication only for some user (or a user group) ? We had only rolled out private certificates from our PKI for some user that has access to sensitive services and these user should use their certificate as additi...
Is there a way to list all configured values for a given template? I have searched the tech docs and Community but can't find a good answer for this. Background: I inherited a Template Stack in Panorama, and one of the templates has an oddball naming convention and doesn't SEEM to contain any values at all (browsing manually through the screens ...
Hello All, I am looking for any helpful suggestions,recommendations,critics etc for my new firewall design implementation project.currently, we have a pair of 5020s facing the internet and having DMZs,Internet and Internal networks on them. My management would like me to implement a "True DMZ" with new 5220s for greater ssl decryption capabiliti...
Good Morning I have two questions regarding the HA Fault conditions When I configure Link Monitoring and Path Monitoring in the Active Firewall Should I also configure these conditions in the same way in the passive Firewall? The "Heartbeats Backup" option must be enabled even if we do not have a backup link configured? Thank you! Regards!
I'm using minemeld to pull the O365 urls into my PAN. I get a list that has entries like*.domain.comsub.domain1.com I need to import those entries and rewrite them so they look like*.domain.com/domain.com/*.sub.domain1.com/sub.domain1.com/ Any pointers would be appreciated.
I have a policy rule to allow dropbox. I am performing SSL Decryption. The users are using the dropbox client (not web). I came across this article that mentions this will not work when decrpytion is on https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGaCAK Anyone have recommendations on how to exclude the dropbox cl...
For about the last week https://urlfiltering.paloaltonetworks.com/ has been broken in way that makes it impossible to submit reclassification requests. I have several sites that I'd like to reclassify, but I have been unable to do so.When will this be resolved? One of the issues is that a JavaScript is being loaded over plain http, so at least t...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 8 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

