Management access for permitted IPs
hii am trying to add 10/8 as premitted IP subnet in mgmt interface but it seems to not work? anyone else has experienced this?
hii am trying to add 10/8 as premitted IP subnet in mgmt interface but it seems to not work? anyone else has experienced this?
Hello, Looking for suggestions and recommendation, just got an offer from the ISP to upgrade the Internet speed to 1Gig down and 10Mbps up for a very good price. Except I have a PA220, the spec is good for 500Mbps with AppID and 150Mbps with threat. That just won't fly. I am aware the 220 can do better than 500Mbps. I don't think I can go...
I was having issues with DHCP being blocked, so I can a packet capture from the PA to see if I could tell was was blocking the DHCP traffic and if it could possbile be the PA. It shows the mac address of the interface on the PA as the source and then its lists a mac address that I cannot identify as the destination. So if anyone has any ideas of...
Hi,I'm trying to setup GlobalProtect with Prelogon, but I'm having trouble authenticating the user at the portal. I'm trying to test just the user authentication with the Windows Server 2016 ActiveDirectory DC at 192.168.###.9. Using the Pan-OS 8.0.13 CLI admin@fw-1> test authentication authentication-profile "Corp-LDAP" username "DOMAIN\us...
Hello allWe have one public IP address and two groups of users who must connect to Head Office but get different policiesWe decide to use loopback ip address and NAT it to the public one but with different port (for example loopback ip 1.1.1.1 and public ip is 85.10.10.1 and we NATed 85.10.10.1:446 to 1.1.1.1:443)but when client try to connect t...
I want to collect log files from a GlobalProtect agent 4.1.2 but our gateway policy is set to disable the admin view.By doing this, the user can't colelct any log files anymore. Is there another way to collect logs ?
Hello allWe have configured GP REMOTE ACCESS VPN with OTP authentication.Ones we try to connect to Portal it failed to pass at the first time only second time.In Radius server we see that it tries to authenticate first the Ldap account then VPN accountwe configured the followings and it is ok.And i would like to know is it best practice from se...
on passive PA we are seeing ( description contains 'No synching file to peer because local state is not Active (Passive).' ) is this normal?
Hi All, I have a PA3020 with 7.0.5-h2 PAN-os version.I have tried different times to sync manually the running config on passive member without success. I can clearly see from the Active Member's "ha_agent.log" these errors:=========================(active)> tail mp-log ha_agent.log00000001TLV[2]: type 11 (SYSD_PEER_DOWN); len 4; value:000000...
I've used MineMeld in the past and I've been very happy with all of it's functions. Recently, I've started a new job and I've recommended MineMeld as a solution to get O365 IP's into the firewall for writing policy. Microsoft announced on April 2nd that it will be retiring the HTML/XML/RSS feed. I've included the announcement and link below. ...
I need to rename a whole bunch of firewall rules (Security Policies).Ive done a search here and looked in the manual; I think I know the answer.I can change Firewall / NAT rule names as needed? There will be nothing else I have to change right? This will not break anything? I do not think firewall names and NAT rule names are referenced anyplace...
Hello, We've recently enabled safe search on our PA-3020 and noticed that whenever you do your first google search while on google.com a quick block page pops up and almost immediately goes away. Is this to be expected behavior when safe search is enabled? Thanks
This link (https://www.ietf.org/mail-archive/web/tls/current/msg27066.html) says that PAN-OS 8.1.4, PAN-OS 8.0.14, and PAN-OS 7.1.21 will fix a TLS issue. I don't see any mention of this in the 8.1.4 addressed issues page though. Do we know this is fixed for sure?
Hello, Scheduled Device Config export is only exporting local running config from the managed devices(same as export config snapshot done from device) and not panorama pushed policies,objects and network templates. While this may appear as an expected behavior per below docs* https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface...
Now that we have newer features like static route path-monitoring, is there a new recommended configuration for Dual ISP with VPN failover? I'm thinking SiteA (Dual ISP) to SiteB (Dual ISP) with IPsec VPN both using a single VR. I assume it will be one static default route with path-monitoring to fail over to the other ISP default route. Then ...
| Subject | Likes |
|---|---|
| 7 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 1 Like |
| User | Likes Count |
|---|---|
| 7 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |

