ISP Failover with dual Dynamic Public IPs?
Hello,
I have two ISPs with Dynamic Public IPs. Is there a way to setup ISP failover?
Thanks,
Bill
Hello,
I have two ISPs with Dynamic Public IPs. Is there a way to setup ISP failover?
Thanks,
Bill
Based on the PA-5400 MPC Component Descriptions, the MGT-A and MGT-B management ports are bundled by default as a LAG:
"Two SFP/SFP+ management ports providing 1/10GE connectivity that are used to access the management interface. MGT-A and MGT-B ar
...
Hi Community!
Recently I stumbled upon this weird behavior where a security rule shows 0 hit-count, but when looked under the traffic monitor lots of traffic is being allowed by that rule.
This is the rule in question (0 hit count marker):
This is
...
we have a v-wire setup where we are controlling traffic to a secondary firewall w our 820. as its sitting between ISP and the site secondary firewall (sonicwall) we created a rule that negates all but some countries we do business with and that negat
...
We currently block access to Online storage using URL Filtering and make exemptions to online-storage sites like Sharefile using custom URL Category with list of URLs that we want to exempt. However, this setup lets everyone in the company have acce
...
If our fw ha group is managed under Panorama, is it necessary to sync config?, is it the best practices ?
Is there any documentation available on how to achieve this for general user network access? I assume the network has to be set up with a captive portal, but traffic to identity provider for SAML exchange need to be allowed even before the user gets
...
I've set up one of our PAs (a 5260 running 10.1.6-h3) to use as a certificate authority and OCSP responder for use with GlobalProtect remote access. I'm able to issue and verify certificates with no problem, but revoking a client certificate has no e
...
I have users at a development partner company who need to access a dev SQL instance. So they need TCP 1433 to one server. I would like to restrict access to their corporate public NAT IP and require that they use AD credentials. But it would be prefe
...
We are currently seeing the Management Plane of our Palo Alto Firewalls communicating to the following IP-Addresses:
This communication occurs on different Platforms. We see more activity since PAN-OS 10, curr
...
Hi Experts ,
We have twice nat rules (nearly 608 NAT rules) configured on ASA FW and we are planning to refresh them with Palo Alto 5020 soon.Below is one the NAT rule of ASA FW.
nat (Internet,Inside) source static any any destination static h-19
...
Hi everyone
Can bypass the url filtering by changing the URL in HTTP get request ?
For example
Firewall rule deny connect to url deny.com and allow url allow.com
User try to connect to deny.com with IP adress a.b.c.d, user add item the host file or usin
I have a PA-460 that stopped doing pcaps for unknown traffic about two weeks ago. I played around with the application dump setting and I think I may have broken something:
Application setting:
Application cache : yes
Supernode : yes
Heuristics : yes
Hello Guys.
Good day.
I've found about User-ID logs.
these logs are occurring from now.
How can I solve this problem ?
Should I Check AD DC Server ?
(Luckily, There are no CPU Load, Network Latency)
Hi,
recently I am facing an aged-out case for a typical web site, reachable without any issue from 4G for example.
the traffic is not decrypted and after reading many articles I am running out of ideas.
Checking the session info I saw a mismatch b
...Subject | Likes |
---|---|
3 Likes | |
1 Like | |
1 Like | |
1 Like | |
1 Like |
User | Likes Count |
---|---|
5 | |
3 | |
3 | |
3 | |
2 |