joining paloalto firewall with active directory
Dears ,please we need your help to join paloalto firewall with active directory and use all user's IDs instead of user's IPs in the access list in paloaltoRegards
Dears ,please we need your help to join paloalto firewall with active directory and use all user's IDs instead of user's IPs in the access list in paloaltoRegards
Should the untrust to untrust be denied. As the defalt interzone traffic allows everything. untrust to untrust rules for us are ether used for IPSEC or global protect. It seems to me blocking this traffic effects detecting SCANS.
HI guys, I've read most of the reference material by Palo alto only applying security profiles on inside->out security polices but not outside->inside polices. I would think that is a given since outside->inside policies are to protect your front facing web services. Do you guys apply security profiles for outside->inside policies. Khai
Hi there, Wildfire is not submiting files. I have the simplest configuration possible, and I'm using the test file (https://wildfire.paloaltonetworks.com/publicapi/test/pe). However, nothing is getting to the portal, or logs for that matter.I'm running VM-100 on a ESXi server, 8G RAM, 4 vCores, PAN OS 8.2.The only thing I have noticed is on the ...
Hello 1-i have the router adsl with the public ip adresse : ex 41.137.11.123 (WAN interface) ==> this is a Public/fixe IP adresse.2-i have a paloAlto firwall, is connected by its wan interface (192.168.1.2) to the local interface of the router adsl (192.168.1.1). 3-i follow this course to configure the GlobalProtect (https://live.paloaltonetw...
Is Palo Alto's API able to accept GET requests from the PowerShell "invoke-restmethod" cmdlet which have the api key set as a variable? I ask this because I would like to run these requests without embedding my API key in the HTTPS GET request. This does not seem secure to me. Rather, I would like to store the API key elsewhere and have Power...
I can't find an up to date way to enable log forwarding for "Zone Protection" profiles. I found a guide for 6.1 but its not relevent for 8.0 I want alerts when we get port scanned. Cheers Rob
I keep fighting this SSL Decypt issue with my PAs, its almost getting to the point where its not worth running the SSL decrypt function because it causes so many issues. I am currently having issues with people downloading a zip file from git hub. github.com/Microsoft/vsts-agent/releases/download/v2.117.2/vsts-agent-win7-x64-2.117.2.zip The err...
Stupid question. Just need confirmation.PA (42020) devices are default deny correct?If a packet is not specifically allowed or denied by a rule; when it gets to the bottom of the rules the default action is to deny, correct?thanks--CH
Hello All, I would like to capture packet by tcpdump on other interface than management interface.How can do it ? (please explain more detailled as possible). Thanks for your help.GB.
Looking for feedback on what you all have experienced with GP VPN for a user count of over 2k users. Specifically what type of INet circuits that were needed. What was the amount of bandwithd which was seen on the circuits? Finally, is there any sort of way to limit the amount of bandwidth each host can consume?
Is there any experience with 'symantec-endpoint-manager' over tcp/8014 being mis-identified as web-browsing? We have a 5260 firewall in a datacenter environment, with hosts that need to access a Symantec-Endpoint-Server for AV updates. Clients access the server on port tcp/8014. Tha pport is associated with app-id 'symantec-endpoint-manager' p...
On the PAN 5020 I can see in logging that user successfully authenticates with MFA and radius but within a second it says the user has logged off. I know that in fact the user did not log off. I hope to grab some logs at the client next week. But I figured I'd ask the hive mind if anyone has ever seen this symptom and what they found. Thanks.
I have a scenario where I'm creating a VPN tunnel between two PAs. The infrastructure between the two PA is MPLS, each PA has two BGP links (Primary 50Mbps) and (Secondary 10Mbps). I'm terminating the VPN on the loopback of the PAs, however, i noticed that the VPN tunnel is initiated from the primary link (50Mbps) of the first PA and entering th...
I am aware of the below limitation when using an Unlicensed VM-Series Firewall: https://live.paloaltonetworks.com/t5/VM-Series-Articles/No-Logging-in-Unlicensed-VM-Series-Firewall/ta-p/66123 Are site to site VPNs fully supported when using an Unlicensed VM-Series Firewall? If it is, are there any restricions like IPsec tunnel numbers, throughput...

