Wildfire Update failure
Hello, On the Tasks, I found Wildfire update failures.How can we resolve that?
Hello, On the Tasks, I found Wildfire update failures.How can we resolve that?
Hi to all I have a problems with riles with FQDN For example i created rule: source ip - destination ip - destination port I changed ip to FQDN object - pc1.domain.com. Palo Alto can resolve name to IP. New Rule: source FGDN - destination ip - destination port. In first five minutes (more or less) rule works fine, but after that traffic not hi...
I just got off the phone with Palo support as I'm doing an upgrade from 8.0.9 to 8.1.4. They said all I need to do is download (not install) the base 8.1.0 image, then download and install 8.1.4 While on the line with them, I came across this from documentationIf you are already running a PAN-OS 8.0 release, download and install the latest PAN-...
Anyone using custom vulnerability signatures in Panorama? Simple example.Threat ID 41000Name SSH-Auth-Brute-Force Using existing signature 31914 with Time Attribute to block source IP if too many login attempts in specified time period. My issue is that I run reports in Panorama and in report Threat Name shows ID number (41000 and up) not SSH-Au...
Hi All, is there a way for Palo to distinguish between Skype and Skype for business?Application list only suggests you single Skype application... Idea is to block regular skype and only allow skype for biz, maybe there are any weird workarounds.... like allowing/blocking certain miscorsoft URLs or tcp ports. Cheers,
Anyway to accomplish following without modifying routes at the router? I have a subnet 1.1.1.0/24 1.1.1.1/24 PAN ETH1 Need to route 1.1.1.50 from ETH1 -> ETH3 as it sits behind ETH3. I need ETH1 to reply back to router when it says arp who has for 1.1.1.50
I am troubleshooting sharepoint connection to cloud on port 443pcap and global counters show no dropsi see no discards in the cli. when user access the website he sees blank page no contents if i confirm the ip id in pcaps of the PA is same from receive and transmit then we are good right?
We are experiencing a high number of user lockouts with our externally accessible STS. The traffic is HTTPS so it is making it through our blocking policies. We are requiring MFA through DUO but the challenge/response for the username/password is happening before the MFA kicks in. After 5 failed attempts the users account is locked for 20 minute...
Can a vulnerability quit showing up in the threat logs but still be there or a issues? for instance this Name: ISC DHCP Server Zero-Length Client Identifier Remote Denial Of Service VulnerabilityUnique Threat ID: 35223
I am trying to upgrade from 8.0.6 to 8.1.4. I can upload the image via the GUI and it states it saved. I use the cli to install the software package and it fails. I have downloaded 8.1.0 and 8.1.4. Do I need to upgrade to another iteration first? Side note: When looking in the GUI or CLI it doesnt show any software files.
Hi 2 all What is "best practice" to downgrade from 8.1.3 to 8.0.13 step by step? For PA VM-300
We're working on an audit of our security policies to start getting rid of some generalized rules and start making things more specific. I figured we could do some organization at the same time. I'm curious how others are organizing their security policies and what best practices might be here. Coming from an ASA background, my original securi...
Hello, can you anyone let me know how i block access based on domain name, e.g. i want a rule to allow all SMTP inbound except from domain testblock.com, how do i do this? Thanks Ryan
Under Global potect client logs i see in PAN GPA logs cached credential for the portal does it mean it i using username and pw for only the portal connection? if i do not want portal to use cached credential what config change i need to do?
Hello! Sometimes the "Source User" column is empty. What should I check in the settings? PAN version 8.0.10 Thank you!
| User | Likes Count |
|---|---|
| 5 | |
| 2 | |
| 2 | |
| 1 | |
| 1 |

