HIP check - check if a non running process present
I configured a HIP check for a non-running process, but the GP doesn't detect it.Have someone got it working?
I configured a HIP check for a non-running process, but the GP doesn't detect it.Have someone got it working?
We've been using SSL decryption inbound for a while. In order to decrypt traffic based on DHE and ECDHE ciphers, we moved to PAN-OS 8.0. On 7.1.10, traffic with those ciphers were not decrypted but passed through. Now, on 8.0.6, we see drops. The decryption profile sets TLSv1.0 only as protocol, but we allow other protocol versions and ciphers (...
Hi Expert , I found issue about UIA which some user logon into network sometime IP mapping user long time or sometime not mapping I must use clear user mapping and every time and ip map user on AD , I would like to know why user mapping longtime or not mapping show unknow however , I config cache User Identification Timeout (min) 720 mi...
Hi all,I'm installing Traps on new Hosts, but once installed they do not appear on the ESM console, does this take a while?
Hi Guys, I got a simple question for you: Is it possible to literally disable/shutdown mgmt interface, via CLI or webUI, in a VM enviroment when is not needed? I notice a DNS issue after we have deleted the IP address assigned to the MGMT interface via cli with command:"delete deviceconfig system ip-address" Obviously we have made PA reachable f...
The first step seems a bit contradictory, just looking for some clarification. I have 2x5220s that I am setting up in HA Active-Passive mode. To cable the dedicated interfaces it looks like I just use regular ethernet cables, but the second sentence "Use a crossover cable if the peers are directly connected to each other." seems to contradict th...
Hi
HelloI have strange intermittant issue with PBF and Tunnel monitoring. If I disable the IPsec VPN at both side and bring it up PBF and Tunnel monitoring is working at configured. ( Shows as up ) I have configured a monitor IP destination of an address across the tunnel. Randomly the PBF and Tunnel monitoring fails. Even thou the IPsec VPN is up....
Dear All, When we create subinterface, the main interface is assigned to one vsys(none option unavailable). So under a physical interface, when we create multiple subinterfaces and assign to different vsys, will this cause any issue?? and whether physical interface needs to part of any VR. I have attached screenshot for reference(i...
Hello brothers, Plz i really need your help, we have a big project with a big Service Provider, it's the MSSP, i know the concept but technically i don't know anything.As i understood, the MSSP is a security as a service, the Service Provider host the Firewalls Appliances in his own local, and sell the security service to its clients, but the bi...
Dears I want to know the IP of this user "None",as per to a below image, through CLI ...Can I do? Please feedback with the command or the way to know who it is ? thanks
Here is another interesting commit status dependency warning "Rule 14 application dependency warning: Application ms-update requires ssl be allowed but ssl is denied in rule 15. " Why is an application in the rule above getting on a rule below it?
I'm working with our AD admin, and we are trying to replace our DCAdmin account with a service account on our firewall. With AD2016, the MSA/gMSA accounts require that you link the account to a computer object. I've seen in a couple documents that it eludes to the fact that MSA's can be used, but it doesn't give any information how. What we are ...
Hi, As described in following links we've configured multiple untagged sub interfaces all assigned to different vsys (different virtual routers and different zones) but with different IPs from the same network and the same VLAN: https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-L3-Untagged-Subinterfaces-to-Communicate-...
Can someone tell me how to know/what would be the Source IP address for an SSL Tunnel Proxied from the PAN NGFW while running in Virtual Wire Mode ? My topology is very simple: User (Virtual Wire) ----> PAN ----> Internet Does the Firewall initiate the Proxied SSL Tunnel using the management interface IP address with the Untrust Zone ?
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 8 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

