Resolved! Using Same layer 3 network with different vlan tag
Need to confirm if we have layer 3 subinterface say network 11.11.1.2/24 vlan 100network 11.11.1.3/24 vlan 200 It is possible to do this on the PA?
Need to confirm if we have layer 3 subinterface say network 11.11.1.2/24 vlan 100network 11.11.1.3/24 vlan 200 It is possible to do this on the PA?
Hi, We have a certificate generated by RapidSSL as CA. but we can NOT set this certificate as a forward trust certificate to use in Decyption SSL, the option shows disable. Roots is in the list "default trsuted certificate authorities". Why the option is disbled???
Has anyone been able to get ProofPoint TAP logs into MineMeld? I think the issue I'm having is with my JSON configuration. Here's what I have so far but it's not pulling any indicators. I've tested my query on http://jmespath.org/ with sucessful results. The field I'm trying to extract is the URL in the threat field - badsite.zz in the examp...
Just curious. The recommended QUIC rules set the action to 'deny', but the first rule is for service udp 80/443 any application. Is there a reason this is a 'deny' and not a 'drop'? ReferenceHOW TO BLOCK QUIC PROTOCOLhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClarCAC What a difference a Deny makeshttps://live.paloa...
Need to block facebook chat and allow Facebook for some user group. i was reading this Allow application facebook before denying application facebook-chat Does it mean block facebook chat first then allow application facebook?
What if we create creates a custom application containing Layer 7 signatures.And after few days the PA send the Latest APP and Threat updates and we download those in the PAWhat will happen if the update contains an application that matches the same traffic signatures as the custom application? or which thing is hit first custom app or applica...
Hi, I followed the document on how to create VPN for IOS devices with certificates, and I got it working.I was wondering how I can deny a device VPN access for a device which is lost or stolen. Deleting the certificate Client ID certificate on the PaloAlto Box does not help. The device can still connect.The user can change his password but I wou...
Is it possible to bulk upload to the LocalDB Nodes? The input UI appears to only accept a single indicator per line, and doesn't do any validation of the information being input.
The GlobalProtect Portal/Gateway had been working perfectly until tonight I have restarted the Palo Alto appliance.After - I was not able to connect. The portal page - ERR_CONNECTION_TIMED_OUT. I tryied to load older configs, I have even reinstalled the software version (8.0.13). No luck. I the Session Browser I do not see anything that looks li...
Greetings, I am trying to create the NAT IP only rule as outlined here.https://www.ericooi.com/palo-alto-firewall-home-network/ I have a single External WAN interface Etherenet 1/1. I am wondering how the referenced NAT SOURCE Translation interface (Object/Physical/Other???) is created to configure the Source Translation?I am only able to add '...
Hi all and specialist engineer, I would like to know sometimes I'm doubt about monitor wildfire submission and threat which wildfire is shown in a monitor (ref: wildfire portal ) but why threat does not show even though same both a file name and type malware.
Hi,I am trying to terminate on PaloAlto VM-100 (8.0.13) an IPsec tunnel.It seems that the other side is not able to connect at all. We have checke all IKE settings and they seem OK.I am using a Loopback interface with an external IP address (exactly as I am using for the GlobalProtect VPN which is working fine).Do I have to create any NAT rules ...
I am trying to fulfill a request by my security team to enable app id on our palo alto rule base & I cannot find the app id for https. There is also a machine inside our envirionment that needs to be accessed over tcp 444 using https:// so I assume enabling app id won't break communication to this machine as long as I specify port 444 in th...
Hello Team, I am going to deployed the VM-100 serie firewall in AH mode on vmware Hyper-Converged VxRail ( with esxi).The VM-100 series will bee used to protect the servers deployed on the VxRail.What are the requirements needed for the deployement of the WM-100 on the vmware Hyper-Converged VxRail ?cans somone please sugested a senario of ...
Bonjour à tous, Est-il possible déployer le palo alto VM-series en virtual wire sur Esxi ? Merci d'avance pour votre reponse. CDT, Zanga
| Subject | Likes |
|---|---|
| 7 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 1 Like |
| User | Likes Count |
|---|---|
| 7 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |

