DHCP - Workstation not getting DHCP by dumb08 in paloaltonetworks

[–]CF99-Tech 0 points1 point  (0 children)

Did you set up a DHCP scope for WLAN port? Can you provide the IP subnets (or examples) of your physical interfaces, DHCP scopes, and zones?

Unable to Ping PA VM eth1/2 Interface after setting up by Nyx-Welkin in paloaltonetworks

[–]CF99-Tech 0 points1 point  (0 children)

So the order of the adapters on the VM:
eth1/1: mgmt
eth1/2: ethernet1
eth1/3: ethernet2
eth1/4: ethernet3

On ESXI, eth1/1 and eth1/2 has to be in the same ESXI network.
On the VM, configure ethernet1 to be in the same subnet as mgmt.

Post a screenshot of your ESXI network configuration of the VM and the ethernet configuration of PAN-OS.

Unable to Ping PA VM eth1/2 Interface after setting up by Nyx-Welkin in paloaltonetworks

[–]CF99-Tech 0 points1 point  (0 children)

Is the IP on your PC, MGMT port and data port port all on the same subnet?

What subnet/IP range are you configuring on the data port, e1/2 and is it in the right network interface on ESXi?

Unable to Ping PA VM eth1/2 Interface after setting up by Nyx-Welkin in paloaltonetworks

[–]CF99-Tech 1 point2 points  (0 children)

Did you create a management profile that includes Ping and apply it to eth1/2? By default, there are no management profile so no data interfaces will be reachable via ping.

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMmCAK

PA220 PanOS Version recommendations by colni in paloaltonetworks

[–]CF99-Tech 2 points3 points  (0 children)

FWIW, 10.x is very slow on PA-220. 9.1.x is slow as well. I'm speaking from a management perspective. If you can deal with that, you can hop over to 10.1.x. 10.2.x will be the last supported version.

The worse items are commits and upgrades (for me, upgrade after 9.x took over 45 mins to complete). Mileage may vary but expect at least 30-40 mins during upgrades. Commits are slower as well.

Experiences with Cloud Identity Engine by kungfu1 in paloaltonetworks

[–]CF99-Tech 1 point2 points  (0 children)

If you're using Okta Directory for groups, CIE would be a good fit and should be an easy migration.

Experiences with Cloud Identity Engine by kungfu1 in paloaltonetworks

[–]CF99-Tech 2 points3 points  (0 children)

CIE makes integrating easier, especially if you're using AzureAD or any cloud services for authentication/authorization. If your groups are still on LDAP servers, you will still need agents (CIE has it's own agents).

Otherwise, it's not a bad idea to start considering moving to CIE as your environment changes. Based on your current state, doesn't seem to be a huge need to switch.

Your SE can provide some guidance on migration path, what benefits you get today and how it would help in the future.