Log forwarding "Zone Protection" ?
I can't find an up to date way to enable log forwarding for "Zone Protection" profiles. I found a guide for 6.1 but its not relevent for 8.0 I want alerts when we get port scanned. Cheers Rob
I can't find an up to date way to enable log forwarding for "Zone Protection" profiles. I found a guide for 6.1 but its not relevent for 8.0 I want alerts when we get port scanned. Cheers Rob
I keep fighting this SSL Decypt issue with my PAs, its almost getting to the point where its not worth running the SSL decrypt function because it causes so many issues. I am currently having issues with people downloading a zip file from git hub. github.com/Microsoft/vsts-agent/releases/download/v2.117.2/vsts-agent-win7-x64-2.117.2.zip The err...
Stupid question. Just need confirmation.PA (42020) devices are default deny correct?If a packet is not specifically allowed or denied by a rule; when it gets to the bottom of the rules the default action is to deny, correct?thanks--CH
Hello All, I would like to capture packet by tcpdump on other interface than management interface.How can do it ? (please explain more detailled as possible). Thanks for your help.GB.
Looking for feedback on what you all have experienced with GP VPN for a user count of over 2k users. Specifically what type of INet circuits that were needed. What was the amount of bandwithd which was seen on the circuits? Finally, is there any sort of way to limit the amount of bandwidth each host can consume?
Is there any experience with 'symantec-endpoint-manager' over tcp/8014 being mis-identified as web-browsing? We have a 5260 firewall in a datacenter environment, with hosts that need to access a Symantec-Endpoint-Server for AV updates. Clients access the server on port tcp/8014. Tha pport is associated with app-id 'symantec-endpoint-manager' p...
On the PAN 5020 I can see in logging that user successfully authenticates with MFA and radius but within a second it says the user has logged off. I know that in fact the user did not log off. I hope to grab some logs at the client next week. But I figured I'd ask the hive mind if anyone has ever seen this symptom and what they found. Thanks.
I have a scenario where I'm creating a VPN tunnel between two PAs. The infrastructure between the two PA is MPLS, each PA has two BGP links (Primary 50Mbps) and (Secondary 10Mbps). I'm terminating the VPN on the loopback of the PAs, however, i noticed that the VPN tunnel is initiated from the primary link (50Mbps) of the first PA and entering th...
I am aware of the below limitation when using an Unlicensed VM-Series Firewall: https://live.paloaltonetworks.com/t5/VM-Series-Articles/No-Logging-in-Unlicensed-VM-Series-Firewall/ta-p/66123 Are site to site VPNs fully supported when using an Unlicensed VM-Series Firewall? If it is, are there any restricions like IPsec tunnel numbers, throughput...
Hi, all. Recently, one of our company's valuable customer request the solution about QoS policy. The customer's QoS policy was Application 'ms-update' Services 'application-default'This policy applied well in Windows 7 environment. However, the problem is Windows 10 envrionment.When the computers tried to update to Window Updates, this QoS rule ...
Hi guys,We have been used 30 Days trial ULR Filtering License so far.After 30 days, it means expired, We couldn't use it naturally.and I tought it may can use old db version-url filtering- even though It won't get any update information as like normal License. But it didn't happen like below traffic log It couldn't block any pages belong to in...
Hi Guys, I need some help dealing with CyberAck over VPN. The problem is that I created and established a VPN with a remote peer for CyberAck traffic. Service is Any but application is default. Traffic is allowed via the firewall but I get an error (tcp-rst-from-server) on both sides or server and client. Cyberack uses TCP ports 4118, 4119, 4120...
When users are connected to GP they are unable to search online templates from both word and visio.it works OK when connected to LAN and we have a test policy that allows all outgoing traffic for myself and I still cannot search the online templates via GP. I think this has something to do with MS NCSI, as the VPN client has no default gateway. ...
I am looking for documentation on using MPLS with my PA 3050. I have found community article 59127 but was hoping for more information. We are about to aquire an MPLS circuit from our ISP for a remote office. The remote office will have seperate VLANS. The ISP will provide the MPLS routers. On the remote office end the router LAN interface will ...
Hello all.is there any possibility in Palo Alto to kill connection in real time if i see for example some user downloads too much or uploads too much?
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 8 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

