https://www.airfrance.com not open
Dears Although we set "Travel"category on no decryption rule befor decryption ,the web sitehttps://www.airfrance.com not open i wait to install but the brows go to
Dears Although we set "Travel"category on no decryption rule befor decryption ,the web sitehttps://www.airfrance.com not open i wait to install but the brows go to
Hello, We have recently upgraded our FW to PanOS 8.x (currently running 8.0.8) and we want to use the newly added feature that enable to add exceptions in External Dynamic List. However it doesn't seem to work since the configured IP we put in exceptions (in a IP list) are still blocked by our policy. Did you try this and does it work for you ?
I'm struggling with GlobalProtect and always on.I have it configuerd for Multi-gateways and that part works great. My issue is when I switch WiFi networks to internal, the globalprotect still tries to connect. I have added internal host detection and put down an IP and Hostname of a server. If I disbale the globalprotect from systray. I'm able...
Hello ! We encounter a problem on a power supply on one of our Palo Alto. Since power supply replacement, we've the message "Running config not synchronized - Sync to peer" but i've one question : Is the active firewall configuration will be pushed on passive active firewall ? Other question, since we've connected "new" firewall, in our Panora...
We've syslog configured on devices with tcp protocol on port 515. Our passive device syslog connection is breaking every 300 seconds. Can you help in understand why passive palo alto not sending keep-alive?
Greetings all, I've been asked to set up a secure desktop for one of our departments. The desktop will need access to a few on premises resources such as DHCP, DNS, and AD but, otherwise, it has to be restricted to allow connectivity only to a specific website. I can do this simply with a VLAN setup but this leaves open the possibility of a mis...
I want to configure my internal network to go dual isp with ecmp, isp Failover , VPN Failover and gp.If anyone have any idea?
Hello everybody!I have a problem with user identification and accordingly with security Policy.In different computer, the same user is seen "user" or "domain\user".The rules for work must have both type of user format. This is a big limitation.Where I have made the mistake?Help me please.Thanks.Daniele
Today I got many critical alerts from Palo Alto Firewall. Threat Type: vulnerabilityThreat Name: Microsoft Active Directory DCSync Attempt DetectionID: 54406Category: info-leakContent Version: AppThreat-8010-4662Severity: critical Does anyone has the same issue? Can somebody share the details of this attack?
Hello, good morning. I have a virtual firewall vm-300 I'm considering setting up the firewall in HA. But the company where I have the dedicated servers does not offer me floating ip`s.But they do offer failover ip's.It is possible to mount a HA, with failover 's ip's? There is some other alternative that you can recommend to me to avoid having ...
I've successfully configure SAML with a Shibboleth IDP for administrator access, however, the login process still requires two clicks : One to select SSO, and another to continue without a username. I'd like to provide a better user experience for admins/customers and ideally eliminate all clicks. Is there a specific URL or configuration that w...
I have created a rule which requires access to Adobe-creative clolud. This application is dependent on SSL and web browsing. Setting this rule to allow aslo grants access to websites like Amazon.com or general internet access.Is there a way to make it work just for the particular app? or I am missing something in creating the policy?Thanks.
Hi all, We have a standard IPSec tunnel one of our smaller sites with a strange issue related to the Proxy-IDs defined on the PA side of the tunnel. Our ASA side (10.7.0.0/16) is set to inherit all policy settings from the PA side, and our PA defines the "policies" with the Proxy-ID. Normal behavior with a policy based firewall (ASA) and a route...
Hello friends, I have a question about saving my firewall changes and then applying them at a later date. What I want to do, is enter all my changes into a production firewall, but then not commit them. I want to save just my changes, ie a small configlet. And then at a later date, "load" my changes and commit them (during out of production hou...
Hi All, i want to ask you about HSTS Session,i just installed Captive Portal with Transparent mode because Palo Alto run in Virtual Wire mode, but Captive Portal can't intercept https session.based on article : Captive Portal Not Working with HTTPS Sessions i trying to decrypt the session. and the problem is when the session intercept web with ...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 8 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

