Resolved! Application ms-update on WSUS 6.2 and later
Why application ms-upate usage only port 80/443 when WSUS 6.2 an later usage port 8530/8531 (Step 3: Configure WSUS) ?Robert Ogonowski
Why application ms-upate usage only port 80/443 when WSUS 6.2 an later usage port 8530/8531 (Step 3: Configure WSUS) ?Robert Ogonowski
Hi,we are using a PA environment in combination with Bluecoat Proxy SG for caching and user authentication. Bluecoat describes on his knowledgbase KB3323 the differences for session timeouts on proxie servers and firewalls.From our proxies I have many retransmissions to the Internet and so I want to change my timout settings on the PA in a bluec...
Dear Expert , I need to get all System messages of PA in case of the below Events CPU Errors, warnings.Memory, RAM utilization warning, problem.Hardware failure, problem. .(Physical Events)Links , interfaces down.Processor warning.Disk warning.Fan warning.Power supplies warning.Restart, reboot events.Shutdown event.Your support is highly apprici...
Hi all, We have upgraded globalprotect version 3.1.4 to 4.1.2. Its connected successfully . But after some time it saying portal not available. username take as portal name. anyone experience with globalprotect 4.1.2???
Im setting up a s2s vpn between a Palo and a Cisco ASR. The GUI is showing it all as up - green lights and ike tunnels. But the logs are showing the below: IKEv2 child SA negotiation is failed message lacks KE payload I am not sending traffic down the vpn yet so i am unable to ascertain if this is important message or not (would rather know it w...
Hey guys, I've been tasked to have Globalprotect only allow company owned devices over the VPN. I know I can create custom HIP checks for Windows/Mac (reg/plist value). How would I do the same for Linux clients? I have two end users that work remote, and are on a Linux machine. Still having issues with getting the GlobalProtect client for linux ...
My topology is as follows.Client (10.1.1.11) <--> (10.1.1.10) PA-VM (172.16.1.10) <--> (172.16.1.11) Server ethernet1/1 ethernet1/2 PA-VM-ESX-8.0.0.ova image was downloaded from PA support site and installed on VMware Workstation.I was able to ssh and accessing web GUI via management interface. No...
Hi guys, We have migrated our production web infrastructure to run through Palo Alto (previously running through Checkpoint) and although we have no issues with production traffic we are seeing some intermittent failures on our health checks between Child and Parent bluecoat proxy devices. The health check is purely doing a TCP connection on por...
I’m new to Palo Alto VM series deployment and it’s the new project .. we’re trying to deploy Palo Alto HA in VMware environment . Deployed ovf template and configured management interface . Connected to GUI and all looks ok . But I’m not able to configure any other data interface because there is no other interface available in Palo Alto . But i...
HiI must build up an IPSEC tunel between PA and Watchguard XTM. The other Side gives me ike phase where DH Group is 15. On PA I only can choose Group 1—768 bits, Group 2—1024 bits (default), Group 5—1536 bits, Group 14—2048 bits, Group 19—256-bit elliptic curve group, and Group 20—384-bit elliptic curve group Is there a way to build up a "custom...
I have built a VPN server in company domain and I have tried to connect it in the domain computer. Now I need it can be connected to external computer. I have search many information in Internet to know how to do this setting in firewall. But it still not work. Please help me to solve this problem.below is the NAT rules and security rules I set ...
Hi community! I have encountered a "problem" with our Global Protect authentication while we were doing some maintenance works.We have an Authentication Profile with 3 RADIUS servers for authenticating the users, and the number of retries is set to 5.So, according to Palo Alto documentation, after 5 authentication attempts against server 1, it s...
Hi I have 2 NAT pools, actually 4, cause for HA each pool is doubled - does that make sense. 1 pool is on a.b.c.13 and the second is on a.b.c.113. All good. what I would like to do is say going out internet interface from src group "out via non prod" nat to a.b.c.113going out internet interface from src group "inside ip address" nat to a.b.c.13 ...
Hi I am looking to setup 2 IP address I want to use for DNS proxy - I was planning on having each ip as a HA VIP - in fail over mode - 1 priotised to one node and the other to the other node Then I tried to setup the DNS proxy - can't attach it to ip but to interface. so I bound it to the same interface I have the HA VIPS on. some times it wo...
Hi, Im trying to set up Group mapping and foudn an interesting issue that I wabnted to put out here see if theres any ideas that can help us out. This is the situation: Hardwareethernet1/12 is trunk with subinterfacesethernet1/12.2 vlan 2 tagged subinterface with IP = PAethernet1/12.3 clan 3 tagged subinterface with IP = YAD server is on vlan 3 ...
| Subject | Likes |
|---|---|
| 7 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 1 Like |
| User | Likes Count |
|---|---|
| 7 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |

