Hardware processing
Hi, Modifying the security profiles that come by default to drop. Hardware processing will rise at any given time?Thank you
Hi, Modifying the security profiles that come by default to drop. Hardware processing will rise at any given time?Thank you
I am having issues with SSL decryption for office365 . In specific this is related to Azure API and SOAP protocol . Traffic to azure cloud via soap to the following URL "roaming.officeapps.live.com/rs/RoamingSoapService.svc" is keep getting "decrypt-error" . Trying to bypass and adding the site to the exclude list , and/or adding it to a url pr...
I recently upgraded my PA 5050 to 7.1.9. Before that users could connect to the VPN could connect via their native VPN client on their android phones and today I got a call saying one user no longer could and it was failing on the encryption. Any ideas?
Hello, We are seeing the following error occurring when trying to commit changes. Validation Error: rulebase -> application-override -> rules -> SMB -> application 'ms-ds-smb' is not a valid reference rulebase -> application-override -> rules -> SMB -> application is invalid vsys1 Error: application-override rule 'SMB': F...
Regarding the User-ID Agent (Active Directory) feature of the firewall, I’m confused as to the difference and need for either the User Mapping and/or User-ID Agent. Is the User Mapping feature replacing the User-ID agent?The units we have were setup prior to my employment as we 6 office locations and two data centers each data center with a 3050...
I've been complaining about GlobalProtect's lackluster UI for years now. Here's my post from 2016 complaining about the issue: https://live.paloaltonetworks.com/t5/General-Topics/New-Global-Protect-3-0-is-not-good-enough/td-p/75922 Here's my post from 2015 complaining about the exact same problem: https://live.paloaltonetworks.com/t5/General-To...
We have Global Protect set up to use user-logon and use user certificastes issued by our PKI to authenticate users. When a user logs in while connected to an external network, it connects just fine. But when a user logs into windows while connected to our internal network, the panel launches showing a status of not connected. This is very con...
So I know that within in ACC dashboard there is a Risk Score Displayed. There is also Rule list that that shows risky app assosciated rule name . My question is does Panorama give you overall risk score for the rule itself? For example what if I have a mix of Risky apps for Risk 3, 4 ,5. Will it give me a avg risk score for the actual r...
Hi I found thishttps://live.paloaltonetworks.com/t5/Management-Articles/How-to-check-the-media-type-on-the-interface-of-a-Palo-Alto/ta-p/71362 which gave me thisshow system state filter sys.s1.p*.phy But this I don't think shows me aux1 or aux2. Any one know how to show the SFP module info for aux1 and aux2
Hi, I have configured PA on Azure but it is unable to ping to PA.It always shows that "aged-out" as error message.Once I ping to proxy-server on Azure, the log is shown on PA but it is aged out and could not get the response.I did set up Static route and everything. I have set up as below.PC->Azure(PA)-Azure(Proxy server)-Intenet Can anybody ...
Hi folks, Are there any Cisco ASA specialists out there?We have a problem with a site to site vpn connection between paloalto and an ASA 5540. Actually the problem seems to be on the ASA side. The proxy id's on the PA are configured like this:Remote (ASA): 0.0.0.0/0Local: 1 private /24 subnet As described in the title, we use IKEv2. Now everythi...
I have a Site to Site VPN to a customer and they are using 192.168.5.0/24. I have a new customer using the same subnet. I have configured this on a Cisco ASA using PAT. I am fairly new to Palo Alto firewalls and do not know how to configure this. I am using a PA-3020 running 8.0.2.
hello everyone , is anyone knows that how to view the number of new sessions per second on paloalto ? my pan-os version is 7.1.8 .
I work at a company where we use various version of MAS OS X and connect to client VPNs that use various verison of Global Protect. The problem is that we find many conflicts between versions of GP and the host OS and there cannot be two version of GP installed at the same time.Users providing support to clients often have connectivity issues be...
Hello all, I have a Guest/BYOD Wireless Zone that can get out to the internet just fine. The internet & internal network can get to my webservers just fine. The problem im having is that my Wireless zone can not get an internallyu hosted website from the public IP of my webserver. I do not want any kind of connection or link of the wireless...
| Subject | Likes |
|---|---|
| 7 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 1 Like |
| User | Likes Count |
|---|---|
| 7 | |
| 3 | |
| 2 | |
| 2 | |
| 2 |

