- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-26-2014 04:59 PM
we are planning to deploy more Palo alto devices throughout our enterprise and were thinking of removing our existing Cisco ASA's. Our Cisco rep got word of this and met with us on why we should still keep the ASA's and go with their new products. He mentioned that the Palo Alto device is susceptible to the use of cache poisoning to bypass its security. I've been looking all around the web trying to see if the issue no longer affects the updated version. Unfortunately everything about the issue is over a year old. Any good news I can give my boss about the vulnerability?
12-29-2014 12:19 PM
jdfernandez444 Glad to know that we could help. Please do mark the posts helpful/correct if it helped you
12-26-2014 06:12 PM
Did you take a look at this blog post (though it is 2 years old):
As mentioned above app cache is no longer used for security policies by default after 5.0.2 and 4.1.11.
12-27-2014 06:27 AM
Hi
I'm a fan of PA but You should read this too https://live.paloaltonetworks.com/thread/11580
Regards
Slawek
12-29-2014 12:17 PM
awesome...thanks everyone for your responses. It seems that on the web, everyone posts bad things but when there are fixes, no one posts those.
12-29-2014 12:19 PM
jdfernandez444 Glad to know that we could help. Please do mark the posts helpful/correct if it helped you
12-29-2014 03:08 PM
Agreed with everything mentioned above!
Don't let them talk you out of this solely because of this reason... this 'issue' has been fixed a while back and it not a concern moving forward.
Please look into all the features that the Palo Alto firewall provides!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!