x-forwarded-for IP not appear in traffic log
Hello everyone, I have enable x-forwarded-for in PA. When I look at the pcap from PA, I see the ip address but from monitor log traffic, collum x-forwarded-for ip is empty Please your help. Thank you
Hello everyone, I have enable x-forwarded-for in PA. When I look at the pcap from PA, I see the ip address but from monitor log traffic, collum x-forwarded-for ip is empty Please your help. Thank you
I have a PA410. After upgrading the software recently, I found that the original monitoring log has reduced a lot of functions, and even the ACC function has been lost.I checked the website information and found that this function was cancelled after 10.1.2. These are the ones I use the most and I can't even find any replacements or anything abo...
Hi All, We have a client who all of a sudden started to receive the following telemetry error - 'CDL Receiver Key Empty' on PA-440. No changes have been made. Currently running PAN OS 10.1.2. They are not using CDL and are just sending Telemetry data to PA with a certificate. This looks like it may be a an issue on the PA backend. Can anyone cl...
I have a fairly simple network setup in my LAB Management Interface 192.168.1.1 /24 LAN Interface 192.168.100.1/24 DESKTOP IP 192.168.100.100 I have allowed all the Internal Subnet on the Management interface which is 192.168.100.0 /24 in permitted list I cannot ping the Management Interface 192.168.1.1 FROM 192.168.100.100 NO SECURITY POLICIES ...
We have just configured 2 IPSEC tunnels with a remote palo. Both sides have 2 IPSEC tunnels with tunnel monitor and DPD configured. For some odd reason, the when the primary tunnel is active and has active routes going to it, the secondary tunnel still shows active. Traffic is still flowing the way it should, I never see the traffic change to...
Hi Guys, NTP was working well. But when authentication was enabled below msg is seen on the Firewall (NTP Stopped working) NTP server is a local one using IP address (not FQDN) PAN-OS Version 10.1.5-h1 All the other devices are syncing except for the Firewall. Has anyone else seen this issue? Any help would be greatly appreciated. Regards,...
11.1.4-h1 PAN OS is recommended version for PA-450 box ? what is the release date of it ?
Hello,I have a web server in DMZ with private ip address 192.168.10.100/24 and I would like all the traffic from outside should come to this server. My public ip is 1.1.1.2/255.255.255.248 which will bind to 192.168.10.100To perfom this I can create a destination rule FROM TO Source Destination Destination Translation Address (Static)Untrust--&g...
We have an existing GP setup and it's working, but the IP Pool is set to a range of IPs 192.168.10.10-192.168.10.100 instead of a subnet 192.168.10.0/24. I want to either expand the range or change it to a subnet. I tested this by expanding the range to 192.168.10.5-192.168.10.150, but clients that got an address in the newly expanded range ...
Hello -I've set up SAML and by all accounts it looks like everything is working fine. In the Monitor > System logs I see four different events: saml-client-redirect, saml-idp-activity, saml-signature-validated and finally auth-success. The issue is this:I click on "Use Single Sign-On" > (same result with/without optional Username) Continu...
Hi Team, Can someone please confirm if the incoming expiration of the certificate used by NGFW, and user-ID, going to impact Cloud Native solutions as PrismaCloud and Twistlock defenders? I'm not sure if anything needs to be performed before the date on some PrismaCloud defender which are currently monitoring the AWS Accounts. Version: d...
Hi All, i need to undersatnd if tacacs+ is cisco properiety , so how come juniper and paloalto use it ? second question here , tacacs+ used mainly for cisco command authorization , so what is the need for that inside paloalto ?
Please advise the maximum PAN-OS version for a PA-820. We would like to ensure optimal security without sacrificing performance. Recommended PAN-OS version to run is 11.1.4-h1
Greetings, I am running NGFW x 35 (10.2.10-h3) and User-ID Agent 10.2.2-111, which I believe needs to be upgraded to avoid the Nov-18 issue. My question is, does the User-ID Agent need to remain in the same stream as NGFW (ie. 10.2.x) or can it go to the 11.0 stream? A side question (because I inherited this environment) ...If I have the 'st...
Can you please provide some advise on this: Our client has an issue with the new Apple MACOS Sequoia The new Apple MacOS Sequoia seems to have changed some behaviour in how they check the local firewall. Currently Global Protect HIP does not detect if the local firewall is enabled. I have attached the information above. Apple Firewall:...
| Subject | Likes |
|---|---|
| 1 Like | |
| 1 Like | |
| 1 Like | |
| 1 Like | |
| 1 Like |

