URL problems
hello.although the rule is set to allow any but in request to some web-sites we can see such a problem.there is incomplete in application coloumn.i understand that it cannot pass the three-way handshake.but why only with any sites?
hello.although the rule is set to allow any but in request to some web-sites we can see such a problem.there is incomplete in application coloumn.i understand that it cannot pass the three-way handshake.but why only with any sites?
Whis is it that I get deny and not-applicable and why is it that destination interface is missing from as shown below screen
Hi, I am very new to Palo Alto and trying to active licence on new PA-850. the devices are already registered on support portal using serial key and authcode. when i click Retrieve license keys from license server, z dialogbox opens and tells me retrieving licenses from Palo Alto Networks license server. Please wait... and then suddenly dialo...
Hi guys! I have two PA-5060 in HA and in this moment my secondary is active. In secondary I've seen the following messages:EBL(dyn-block-list-ip-sadc) EBLRefresh job failed. No valid IPs found in listEBL(dyn-block-list-ip-sadc) Unable to fetch external list. Using old copy for refresh.EBL(dyn-block-list-ip-sadc) EBLRefresh job failed. No valid ...
Hello! Could you tell me why taxii output doesn't do data deduplication? Is it normal behaviour or bag? This problem is very important for us because we have huge amount of IOCs (about 450K). TAXII output just multiply this list. Additionally after the output toked 1000000 IOCs it just stop to accept new data until deletion of some old IOCs. The...
I have errors from retieve feed file form any source. It shows "HTTPSConnectionPool (host='source',port=443): Max retries exceeded with url: xxxx.txt (Caused by ConnectTimeoutError (<requests.packages.urllib3.connection.Verified object at 0x7fdd988ad310>, 'Connection to souce timed out. (connect timeout=20)')) But I can use wget fil...
Hello, I wonder if someone can help - I currently have a firewall deployed in a vWire configuration, however the requirements for the site are changing and we now need to utilise the Multi-vSys feature.I've had a look but can't see any information that specifically states whether or not when this license is applied and Multi-vSys is enabled, whe...
Hi, I am reconfiguring my PA-100 VM, as i am changing the network design, but after i changed the interfaces IP, Router configuraattion, NAT policy, and security policy. I cannot get to internet and in monitroing end reason is "aged-out" From CLI i can ping and traceroute using the management and external interface as source, but i cannot use my...
Hi folks, I went and bought another used PA 200 from Ebay to go along with my existing one to test my first IPSec VPN connection.Neither have a support or threat license at all and not registered.PA 200 #1 has PANOS 7.0.5-H2 and PA 200 #2 has PANOS 7.1.9. I am using PA administrator's guides and other material to create an IPSec Tunnel, but stil...
Hello folks, Not sure if my question is worded just right, but here goes. 🙂 We have a partner company that has a Juniper NAT type of device plugged into our PA 3020 that does a NAT to a server in there environment, which we communicate with fine using the 10.1.5.x network.I am being asked to do something similar on our side. Today they are abl...
Hi All, Guys don't judge me, but l have a very little knowledge about the BGP process (iBGP and eBGP) and looking for assistance.Watched a nice video on youtube on how to advertise eBGP learned routes by iBGP peer to other iBGP peers using route reflector technic: https://www.youtube.com/watch?v=yaMUq6WTUTc This part is clear. We have a PA conne...
Hey Guys, I'm looking for a place I can practice using a PA firewall without actually purchasing one. Are there any rentals like INE's rack rentals for other technologies?
Hello,To test the link monitoring of the high-availability, i want to shut one interface on the active member.I set up the interface at down but i do not find how to do the commit on the active member only.Is there a solution to push the commit on one member of the cluster only?Thanks for your help.
I know how to create a standard U-Turn NAT from outside to inside and that works fine as long as the INTERNAL object is an IP Netmask address. On the NAT Policy Rule the Original Packet is a static IP on my external facing range. The Translated Packet needs to point to a device that will have a dynamic IP. This is a mobile cart that can trave...
Is there any specific why someone would configured a certificate profille only on a GP Gateway and not on a GP Portal (or vice versa)? In tutorials or videos, I've always seen it configured on both, but on some networks I've seen people only configure on one of them
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 8 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

