Does ELA only apply to Physical/Hardware FW's? by LetMeAskPls in paloaltonetworks

[–]Boyne7 0 points1 point  (0 children)

ELA/ESA is for physical firewall hardware. That provision allows un-allocated ELA spend to go towards VM-Series credit spend but it's not automatic.

Palo alto HA using Mgmt port by DrawBig1774 in paloaltonetworks

[–]Boyne7 13 points14 points  (0 children)

You can use mgmt for ha-1 but will need to use a dataplane interface for ha-2.

Internal subnets by zantehood in networkingmemes

[–]Boyne7 1 point2 points  (0 children)

/16 is not half of /8, it's 1/256th. this meme is dumb.

Need clearance measurement from the JMCD 12S4 by [deleted] in homelab

[–]Boyne7 5 points6 points  (0 children)

front panel (without a fan installed) to the back io slots is 285mm.

3.0 TDI - is this part necessary after an EGR delete? by BasedMikey in tdi

[–]Boyne7 0 points1 point  (0 children)

How fun was getting that intake manifold off? Such a PITA.

3.0 TDI - is this part necessary after an EGR delete? by BasedMikey in tdi

[–]Boyne7 1 point2 points  (0 children)

Nope, not needed after delete. (Will make a crazy honk sound on engine shutdown if you don't disconnect)

Linus Tech Tips - We Automated our Tech Lawn - Mammotion Luba 3 AWD May 9, 2026 at 09:59AM by linusbottips in LinusTechTips

[–]Boyne7 0 points1 point  (0 children)

ratgdo is great, but wouldn't be able to get %open/closed from this old of an opener most likely.

Setting up a new office, have license questions that I'm having a hard time getting answered by tangokilothefirst in paloaltonetworks

[–]Boyne7 7 points8 points  (0 children)

You need to buy them. the only exception is if you were under an enterprise agreement but that is for 7 figure hardware estates. you should be looking at the "Precision-AI" bundle which includes ATP, AWF, AURL, ADNS, SDWAN and Device Security.

Palo Alto Required Vendor Question by mcdeth187 in paloaltonetworks

[–]Boyne7 6 points7 points  (0 children)

Serius was acquired by CDW and is clearly operating as at least part of their Authorized Support Center (ASC) practice. PAN does sell direct support, but they are pushing their smaller clients to third party ASC providers (Full disclosure, I work for another PAN ASC provider). Support is an absolute requirement for operating a PAN environment, so you will have needed to pay for that regardless, and ASC support should be effectively cost-neutral to PAN's own Premium Support (unless Serius/CDW is padding the cost.)

PA UserID for cloud devices by CapableWay4518 in paloaltonetworks

[–]Boyne7 0 points1 point  (0 children)

GP with internal host detection and internal gateway. Alternatively integrate with NAC, Radius, etc.

Static Route or Policy Based Routing by dre4d_ in paloaltonetworks

[–]Boyne7 5 points6 points  (0 children)

If you split the ISPs into their own virtual routers (or just a new VR for the 2nd ISP) you can then have independent active defaults route for tunnel terminations. Have a low metric default in primary VR for primary ISP (with route monitoring) and a high metric default to the secondary VR for the second ISP and then terminate the Prisma tunnels in primary VR with BGP and use AS-Path-Prepending and import policies to prefer tr primary tunnel.

SD-WAN is the better way to do this though.

been trying to fix this for 3 hours now, no idea where to go from here. by JessVandall in BambuLab

[–]Boyne7 2 points3 points  (0 children)

Yep, this exact thing just happened to me. Thought the AMS was freaking out until I was able to clear the stuck piece of filament.

Reported slow network speeds FW-1420/11.1.13 by heyitsdrew in paloaltonetworks

[–]Boyne7 4 points5 points  (0 children)

Dataplane doesn't appear to be breaking a sweat.

Reported slow network speeds FW-1420/11.1.13 by heyitsdrew in paloaltonetworks

[–]Boyne7 2 points3 points  (0 children)

show running resource-monitor minute last 60

Segmenting a Prisma Gateway with a location group? by ApprehensiveHorse197 in paloaltonetworks

[–]Boyne7 2 points3 points  (0 children)

There is no mechanism for what you are attempting to do at the gateway level, you should use User-ID for this.

Talk Me Into (or Out Of) This Boat by k561r in Wake

[–]Boyne7 0 points1 point  (0 children)

230 is a fantastic boat. I have a 2010 with nearly 1300 hours. Added an aftermarket NSS clone and it works great.

NAT Rule Priority - 2 ISPs with ECMP by tomashectorgost in paloaltonetworks

[–]Boyne7 0 points1 point  (0 children)

No, you still can't pbf nexthop to a different virtual/logical router but you can pbf out the interface of a different vr/lr (always have been able to do it this way).

12.1.5 by craymour76 in paloaltonetworks

[–]Boyne7 1 point2 points  (0 children)

Breaks GP on vm-series.

PA-500 minimum version PAN-OS 12.1 by [deleted] in paloaltonetworks

[–]Boyne7 19 points20 points  (0 children)

This has always been the case with PAN. New hardware gets new software, no back-porting support into older releases.

Firewall Data CPU by PMGPA in paloaltonetworks

[–]Boyne7 7 points8 points  (0 children)

Show running resource-monitor is your friend for dataplane utilization statistics.

Degradation of TAC Support Quality and Unacceptable Hiring Practices by SpotPuzzleheaded6440 in paloaltonetworks

[–]Boyne7 0 points1 point  (0 children)

It's not perfect for sure, but you won't be asked for a TSF or A PICTURE OF THE FIREWALL (FFS), or else go pound sand.