Reassign PA-VM EVal license to new vm firewall after rebuilding the VM
How can reassign the VM Evaluation authorisation to new PA-VM after rebuilding the VM firewall?Kind regards Zoumana
How can reassign the VM Evaluation authorisation to new PA-VM after rebuilding the VM firewall?Kind regards Zoumana
I'm looking at doing some re-design for our DC networks and wanted to investigate some further segmentation. Since we aren't really large enough for NSX or ACI I wanted to look at PVLAN. I've got some Nexus9K switches with Layer 3 licensing in HA and had originally thought to use them as the gateway for the DC networks. Now though I'm wonderin...
Hi together, at the beginning of this week I ran into the following challenge. I’ve to setup an IKE v2 Tunnel between a Cisco ASA and a PA-850 running on 8.0.12.During the configuration the Cisco Partner send me the local and remote tunnel pre-shared key.After a few seconds of confusion, we started a funny discussion and 30 minutes of try and er...
Hi there,I have some problems with a user-id installation on PAN-OS 8.1.4, scenario:1) Windows AD Domain Forest, with around 6/7 domains2) I'm only interested in authenticating users from one of the domains in the forest3) I've correctly connected the firewall to the local domain controllers and pulled out ip to user mapping4) I've also correctl...
So we have several PA-200 in production and need to upgrade to 8.0. I was talking to a Palo Alto technician and he was telling me that the PA-200 are too old and not enough resources to handle the newer firmware and to upgrade. Do the PA-220 have enough power. I am assuming so since they are the newer version. Also, can they handle the workload...
Hi I have minemeld mining O365 address for my PA's. Moved to the new API as well. I have a hybrid Exchange setup.I have moved some mailboxes up to the cloudWhat I have found recently is mail stops flowing I have a rule that basically say MS Public IPv4 to my beachhead port 25 smtp O365 attempts to talk to me and gets blocked.I check the src ad...
Hi so my setup 5220vlan 20 ... my named dns server 10.43.20.100 and 10.43.20.102 ... dns1 and dns2on the pa on interface with vlan 20 10.43.20.1 I have configured dns proxy. works well for dns via udp but tcp doesn't workso tcpdump -pni eth0 host 10.43.20.1 and port 53 -c 20 & dig @10.43.20.1 _ldap._tcp.abcde.com SRV[1] 25943;; Truncated, re...
We have M100 in active and Passive mode. On Active Panorma under managed devices I see commit succeded for all firewalls when i log into passive panorama it shows commit failed for few firewalls - template and shared policy? How can i fix the commit failed on passive M100?
I had configured the Template say Corp Under email profile I have selected the Location as vsys shared is not checked in. When i go to log settings then system then under email I do not see email profile which i created If i change the email profile location to shared then under log settings, system i can see the email profile name. Need t...
Question is it possible to create and use a dns proxy when in vwire mode. I would think that a vlan with an ip would need to be created in Interfaces- Vlan to facilitate this. Thought I would query to see if anyone had tried this. One issue that comes to mind is vwire layer 2, vlan with ip layer three probably will not work but I'm curiuos. Than...
Hi, I have a question like that. I am using PA-220. I want to block the use of facebook chat, but do not block the use of Facebook base. Is there a chance to do this without ssl decoding?
I can see the traffic using smtp on port 587 but everything end tcp-fin. Tried turning off decryption to me.com. Traffic hit the rule that allows any traffic out for this particular user and they are also exempt already from decyrption. What should be the next troubleshooting step? Thanks
Panorama M100 is in active and passive mode.Active PAnorama has latest app version.Each Panorama has separate connection to Internet for dynamic updates and they do not get syn. when on passive PA i click on download for app and threat version it gives error Configuration changes not allowed on the passive Panorama?
I have a group of computers that I want to apply a different security policy with a different Security Profile to. I have created 2 Security policies.The first policy = Internet Out allow any - Trusted Zone to Untrusted Zone with the default 'basic file blocking' Security profile.The second policy = Internet Out allow any - Trusted Zone with S...
I have read all the documentation, and have a test environment for MineMeld, but I still cant work out what share levels are being used for.I was of the beleif that it was green=good (i.e. whitelist these) and red=bad (i.e. block these) however this doesnt seem to be the case in most the current prototypes.@lmori Said the following, but I am not...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 8 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

