Hi everyone, Just have some queries on Palo Alto firewalls posting some questions. Help on these is much appreciated. what does the following command do > show neighbour all Does this function like Cisco discovery protocol to identify the peer CISCO devices or for OSPF neighbour or some other purpose? 2. how to see interface physical and admin status both from cli 3. What is the exact path where OS gets installed 4. what is neighbour discovery in Palo alto devices? is it OSPF discovery or all devices which run on PAN ( This is pretty much similar to first question ) 5. We created a role called Student on the firewall explicitly, only authenticaiton is happening but authorization is not happening, that is Student role is not getting picked up from radius server or on the firewall .What changes can we do on radius server for the role mapping to be picked from radius. 6. Any specific use cases where we use Tap mode and Vwire mode for interfaces? 7. When do we need Vwire sub interfaces exactly and L2 sub interface ? 8.We are not able to bind ethernet1/2.1 with ethernet1/2.2 in the same Vwire object and we are able to bind ethernet1/2.1 and ethernet1/1 into same vwire object 9. What type of encapsulation does interfaces on palo alto devices support? 10. What is ND entries under advanced tab for interface when you are configuring Layer 3 interface? 11.I am able to commit the configuration even though i did not enable USER ID on the zone but i defined some random IPs on include list and exclude list for USER ID for that zone 12. What is CRL status in Service route configuration , i want to explicitly define service route then i find this option? WHat is destination and source address in the same source Route option field. 13. THere will be limited no of policies that we can configure on any firewall what about NAT , QOS and captive portal rules how many can we configure? 14. How to delete the snapshots of the configs that you loaded into the device? Hoping to see some response on this thanks for the support
... View more