Resolved! What IP's does the Mindmeld system need access to?
Hello Everyone, I have spun up the ubuntu VM with the MineMeld iso. This system is behing a firewall. What IPs/URL's does this system need to have access to? Thank You, Scott
Hello Everyone, I have spun up the ubuntu VM with the MineMeld iso. This system is behing a firewall. What IPs/URL's does this system need to have access to? Thank You, Scott
Hello According to https://live.paloaltonetworks.com/t5/Threat-Vulnerability-Articles/PAN-OS-exposure-to-ROBOT-attack/ta-p/192397For complete protection, signature #38407 must be applied upstream from any interfaces implementing SSL Decryption, or hosting a GlobalProtect portal or a GlobalProtect gateway. I have 760 content update applied. I try...
I am trying to design the edge firewall and core network currently and I have a core Layer not in a "stack" or "VSS" so they are independent Core switches. They are doing the routing to the private WAN, and will be doing the routing to the Edge Firewalls. ECMP requires a dynamic routing protocol which usually you wouldn't run on an edge firewall...
Is it necessary to have userid enabled on the VPN zone interfaces to see the userids?
I am pretty new to the Palo Alto's so I have a questions that will be pretty easy to answer. I am setting up a PA-820 in Virtual Wire and we have both Trusted and Untrusted networks on the same interface from the router. The External interface is the route to the internet but is also the route to all our branches through GRE Tunnels. What woul...
Hi, Good day. I'm testing about Syslog setting using SSL in PAN-OS 7.1.14 environment. Under 7.0.X, when I created a certificate, then I clicked it, I can see an option 'Certificate for Secure Syslog'In PAN-OS 7.1.X, however, when I generate a certificate or import it which is created by not encrypted,I couldn't find any option for that. Firs...
Is there a place to report issues? On GlobalProtect forIOS, you can save your default username for your VPN, and the app pre-populates the field, however it leaves the cursor in the username field. It should, however, start in the password field. It would save users that extra click/tap ever single time they log on. Small thing but would certain...
Dear Community, I´d like to check with you regarding the following globalprotect scenario: I´m connected with my laptop to the LTE mobile network to be outside and I´m connected to the external gateway, when I connect to the wifi network... Is it possible that the agent will detect this change and automatically connect to the internal gateway o...
There are serveral resource available for Dual ISP and with Failover VPN on Live community such as https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774 . But here are still lake of of some information in documents, example partner IP address for VPN tunnel, IP Monito...
Hi folks, We have several IPSec tunnels, but only one is complaining of poor performance using a specific application that the tunnel is meant for. Management asking for firewall stats to prove if it is related to IPSec tunnel/firewall performance issue or not. I am following this article and see the first twenty ports, but do not know which on...
Hi All, We have a PA-7000 (7.1) and Tufin (for syslog). The system was previously setup to forward syslog traffic to Tufin. Then all of a sudden, Tufin wasn't receiving any traffic. What I have done so far: Went through the saved configurations to see when the syslog config was changed.From the saved configs, I could not see anything that was ch...
Hello, I have two customers with the same IP subnet, both behind separate IPSEC tunnels to my London hub (image attached, apologize for poor quality). Is it possible they can connect to my hub without any NAT on their side ? I've done a hack I don't like it works. By enabling ECMP and 'symmetric return' option the traffic is flowing from both cu...
I am being told that when updates are released (sometimes 3 a week or 2 in 1 day) that you only need to install the latest update as it includes the previous updates rolled in. My security mindset says to install them all anyways to be sure. But I am curious what everyone else does? Thanks, -Andrew
Creating this post based on another thread. In a previous post's comment section, @spssspss asked "Is it possible to create a white list from an IPs address file?" and Luigi requested a new post be created for this functionality.. Can a list of IPs or URLs be hosted on MineMeld without the content actually being pulled from an external source...
Hello i have an PA-200 running with PanOS 8.0.3 that got no support. Before i could do an update of PanOS manually without Support License. Now i wanted to do an manual update to 8.0.6 but it didn't work. I only get a message that the device got no support.When i upload the new Software Version, i can't see it on the device (Gui or CLI). I can s...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 3 |

