Catchall DNS and Redirect to host
My old firewall was able to catch all dns requests from a zone and redirect them to a defined server. I cannot find a way to do that on the Palo Alto. Can it be done?
My old firewall was able to catch all dns requests from a zone and redirect them to a defined server. I cannot find a way to do that on the Palo Alto. Can it be done?
We are attempting to use a computer based ldap group in the source-user field of a traffic policy on our palo alto 5020.At the moment that policy is being ignored, and subsequent policies based just on the same source ip group are being acted on.(if the source-user is set to any (removing group domain\wkstn_group) then the policy works)We have b...
Hi, I need to limit the bandwith in untrust interface. We replicate DB info to the Oracle cloud and we want to limit this traffic. We have 100Mbps bandwith, and we want to limit the Oracle cloud traffic 50Mbps max. So this is what i configured: Profile QoS: all the classes with 50Mbps max egress. QoS config eth1/1 is our untrust interface (100M...
hello guys, Our FW is connecting to ISP lines, and we configured default route with different metric.The metric of primary link is lower than the secondary link. For such case, Can I have an automaticlly failover when the primary IPS line is down?Do Ihave to create pbf and path montor? Thanks
With PAN - if I have a client who wants to his a public IP address when their traffic passes through the inside/private interface - what would the NAT look like? E.g. say outside/untrusted IP address is 67.1.1.1 and NATs 1:1 to 10.10.4.5 which is reached via the inside/private interface for any port. Now a user at 10.10.40.47 wants to hit 67.1.1...
Is it possible to tail live traffic in the CLI while running a grep (or match) for specific things? I would find this extremely useful.. Thanks.
Our Minemeld will longer let me log in via the user interface. The operating system logon works fine. When trying to log into the web interface I get "ERROR CHECKING CREDENTIALS - Bad Gateway" We are a Windows shop and don't really have any Linux skills to breing to bear on this. What do I need to do to resolve this? It is a production i...
Users complain Global Protect vpn client performance problem. There is shown ping time more than 1000ms after I disconnect then reconnect there is shown less than 150ms. Below photo after and before connection via GP
Hi, I've just created a new node and I'm seeing events such us: DROP_UPDATE on aggregator type. Does anybody have an idea of what could be the issue?
Hello, I need article(s) that shows step-by-step instructions on to use Azure MFA (which is a RADIUS software) for Palo Alto admin authentication in their web interface or CLI for Palo Alto management.As of today, Palo Alto Management is without multi factor authentication (MFA) which is not ideal but it works fine and it is using LDAP for authe...
Hi All Emails from inhouse exchange server is not getting delivered to target email ID or either getting delayed . I have configured the secuirty policy with no security profile attached and the traffic is showing as allowed was suspecting that it might be getting blocked or dropped due to some security profile .once i remove zone protection pr...
Hello 🙂I am doing a migration from a Sonicwall device to a Palo device and I am not finding any migration tools that can help me. Does anyone know of a tool that will migrate from Sonicwall to PAN? I am at a loss of how to go about this without building it all up from scratch.
Hi guys, EnviromentPA3020panOS 7.1.11 -- UserID agent 7.0.4 I got issue with UserID that is currently receiving identites from UserID Agent.UserID has already mapped IP address with a specific LDAP user for example "domains.it\test".Sometimes happens that UserID starting to map the same IP address with this user: "nt authority\accesso anonimo (a...
Hello, everybody. I am configuring a VM-300 Virtual Firewall on a KVM installed in CentOS. The dedicated server where the virtual firewall is installed has two network cards.One of which connects to the Internet and the other with which it connects to a switch to which other servers are connected. My intention is for all incoming and outgoing tr...
In my network we tag certain IP addresses for various reasons on our Palo Alto's. Sometimes we will get a large batch of these that need to be done and manually creating an address object and then tagging it via the GUi can be time consuming (to say the least). I'm wondering if there is a way to add these object groups and tag them via the CLI. ...
| Subject | Likes |
|---|---|
| 7 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 1 Like |
| User | Likes Count |
|---|---|
| 7 | |
| 3 | |
| 2 | |
| 2 | |
| 2 |

