Resolved! Fortigate Migration
HI Guys,I would like to know how to migrate fortigate to Palo Alto/...I heard is a tool available to do it.thanks
HI Guys,I would like to know how to migrate fortigate to Palo Alto/...I heard is a tool available to do it.thanks
Hi, We have an issue with "Nist NVD" integration.When I click the command "!Nvd-search-keyword" we are getting the following message:"{" message ":" Both modStartDate and modEndDate are required when either is present. "}" The integration was published by: "Murat Ozfidan" and supported by "Community".Does anyone have an issue and can help? Thank...
Hi, i am migrating fortinet 100D to Palo alto 850 appliance. Current below is the configuration we have in fortinet, wanted to know the same can be achieved in Palo atlo 1. wan link is ADSL-(dynamic IP- PPOE)2. Branch locations also has WAN- ppoe link, currently from HO to branch established IPSEC vpn on FQDN both ends.3. fortiguard DDNS configu...
Hi Everyone, I would like to get the pa firewall packets rate via snmp monitor, however I can not find any snmp-mib description about it. I lookup paloalto networks Enterprise SNMP MIB Files for PANOS 10.0 & 10.1, but no any finding. Is it possible to get pa firewall packets rate via snmp mib ? or not ? Thanks. Regards,Joy Liu
Hello I am looking to find the best way to migrate a blue coat policy to PAN OS 8.1. I am assuming it will need to be exported to xml then imported to the cli? I am sure some tweaking will need to be done. If anyone knows of a tool please let me know. THank you everyone.
Hi All, We are using TACAS+ Server profile(integrated with Cisco ISE) for authentication of our admin users. Both the username and password authentication from Firewall admin users are done through TACAS Server auth profile. On firewall we are having two locally created two super user admins. When an admin with super user access is authenticated...
heyso i have main site and dr site and they are connected in L2i have in the main site 2 physical pa3220 that there are in cluster (active, passive) and they connected to Panorama and they work perfect now i need to add the Palo Vm 100 machine that is in the dr site but i want that in the end every change that i will do in the main sitelike add ...
Dear Team,We are using Azure Ad server to integrate with PA.We have configure Azure Saml for authentication of Gp .We need to configure user-based and group based policy foor Gp users through Azure Ad.We need to integrated user-id agentless or uid agent and group mapping.IS it poosible to integrate with Azure AD.Note - We dont have on premise AD...
As I know when SAML login for Global Protect, it will pop-up a login browser unlike other login method. take Azure AD syn with on-prem AD as a example, notebook Window domain login use a on-prem AD (Since Azure AD not support it), but Global Protect use a Azure AD for SAML.Two AD (on-prem vs Azure) will not the exactly same domain even it is syn...
Anyone use Mitel mobility app and working on your Pa-3260?
Hi PANOS 8.1.13 At result of show command, in some policy, it is not displayed "log-end" and "log-start" stanza like below test2 policy.But log-setting is enable. I'm sorry I could not paste hole configuration.Does it mean that it is impossilbe to logging to Traffic_log file? snip:set vsys vsys2 rulebase security rules test1 log-start noset vsys...
Hello Community, A bit of context :- we have a server that queries external websites- we allowed the "ssl" app from this server to the outside world- we discovered that some of the trafic originated by this server was dropped because of the firewall detecting it as a specific application, not "ssl" I understand that this behaviour is intended an...
I am trying to integrate PA firewall with newly installed Active Directory server (windows server 2019) but it is not connecting. I get the error Failed to connect to 10.x.x.x(10.x.x.x):389 and the server monitoring status says host unreachable. The group mapping, group include list does not populate as the firewall has not made connection yet...
Hi - I create a service (tcp-443) and then create a security rule that uses this service as the service member. This works. Then, if I call the same API call with the same xpath and provide a different service, say tcp-449, the resulting security rule has *both* tcp-443 and tcp-449 in the Service column: First call is <service>["tcp-443"]&...
Hi there, I have 2 sites on 2 different locations. On the first one i have a core router Cisco 9407 and on the other site i have a Firewall PA-5020. Since the ownership of the line between the sites is not ours do you have any suggestions how to connect the NGFW and the Core router securely?For example I will use MACSEC for the connection betwee...

