DMZ with multiple VLANs, multiple Zones?
If you have a DMZ behind the Palo and it contains multiple VLANs or sub-interfaces, would you create multiple Zones(one for each VLAN)? Or create a single "DMZ" zone and apply that to all of the VLANs?
If you have a DMZ behind the Palo and it contains multiple VLANs or sub-interfaces, would you create multiple Zones(one for each VLAN)? Or create a single "DMZ" zone and apply that to all of the VLANs?
Hello Team,We have seen in the PA 5200 series that the following log appears: "Disk quotas can not be computed due to disk" It appears just after the boot in the system logs. Have you ever seen this log? What it means? Is dangerous for the firewall?PANOS 8.0.10
HI All I am wanting to upgrade the PAN 500 currently on 7.0.2 to 8.0 Is there a good read what major release version I have to follow to do the step upgrade? What major release i have to follow if anyone can guide me. Regards
Hello,I'm running Minemeld 0.9.46 on RHEL 7.4 installed via Ansible. Everything appears to be working correctly except I'm not seeing any logs in the Logs tab or the logs page of each individual node. I am getting updated statistics for each for each node (Add/Updates/Withdraws). And the dashboard is populated with dynamic data. When I navigat...
So I'm looking for the best way to block a user in a specific AD group but get them a response page while I do it. These users are going to be students who violated network policy and are being blocked to everything except some of the educational/homework sites we run. Initially I thought of just doing two security policies... a permit with FQD...
While configuring the PAN firewall as a DHCP server, is it possible to assign lease to a client starting from the highest to the lowest range? Meaning if the DHCP range for the subnet 10.10.10.0/24, is from (10.10.10.100-10.10.10.254), can the lease be given in the order of 10.10.10.254 1st, 10.10.10.253 2nd, 10.10.20.252 3rd and so on until 10....
Hi, Does anyone know what exactly session number indicates under ACC? For example, we have a specific appwhich has constantly around 250K sessions on the firewall. However when I click ACC and set time as "last 15 minutes"for this specific APP, I see 20-21k sessions for the last 15 minutes which doesn't make sense. I wonder how I can see the s...
Hi All,To enable SSL Decryption and to make use of URL categories to allow or block traffic based on the URL categoy , does URL filreting license is required or SSL Decryption can be used fully without URL filtering.RegardsSam
hey there, since tls 1.3 is now a ietf standard, is there any use running ssl-decryption in the close future?as far i understand 1.3 documents, it "looks like" 1.2 for the firewall, so there's no way to just block 1.3 and force both parties to downgrade to 1.2, or i'm wrong? any news/tech docs from pan about the 1.3 "issue"? so longo/
Hello - In PaloAlto 5220 appliance configured in Active/Passive mode, both the Firewalls do have the same MAC address on interfaces. For example ETH 1/1 of active and standby Firewall have the same MAC address after cluster/HA was created. These the switchport connecting the StandbyFirewall doesnt learn the MAC address of the Paloalto interface....
I am trying to figure out a way to automatically get users to my GPCS portal so they can download agent. I have tried setting up the captive portal but that doesnt seem to do more than authenticate my users so i have user-ID info. Would there be a way to do this with URL Filtering or some other mechanism? Use-Case: User is attempting to visit...
Hello everyoneI have a PA200 which has only 4 network ports. But now I have 2 direct internet connections and 2 4g connections and 1 is uplink to my network. Would it be possible to connect a port of the pa200 not directly to the router but to a small 8port switch to which my two routers are connected? These have the IP 192.168.5.1/24 and 192.16...
We have a potential customer who would like to analyze email attachments in sandbox. They are using Lotus Notes as their mail application/server. Has anyone tried decrypting Lotus Notes traffic? Because if this doesn't work the only solution is a client based sandboxing solution.
Hi Guys I want to swap the Active/passive roles of the Firewalls in HA pair and let it run for couple of weeks.I know that can be done by 'suspending the role' from GUI and from CLI too.want to be careful about pre-emption and donot want to break the HA pair.Does suspending teh device on active means forcing the device to be passive plus taking...
As of late, Ive been seeing more and more xps file types tied to phishing attempts. PAN does catch it "Microsoft Phishing Site Detection", but as a for production. XPS files are not needed. But as simlar files types are list to be blocked "pdf's, etc", theres no option to block XPS file types? Could this have been added in a certain OS version? ...
| User | Likes Count |
|---|---|
| 6 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |

