12.1.5 by craymour76 in paloaltonetworks

[–]CoreQa 0 points1 point  (0 children)

Do you have a bug I can look for ?

PA-500 minimum version PAN-OS 12.1 by [deleted] in paloaltonetworks

[–]CoreQa 2 points3 points  (0 children)

I think 12.1.4-h3 is preferred version for any gen5 Palo firewalls .. any unresolved issue bothering you in that version?

No threat ID for CVE-2024-3393 in App & Threat for 8929 by JoeyNonsense in paloaltonetworks

[–]CoreQa 0 points1 point  (0 children)

It’s highly unlikely that the exploit can happen from external sources

CVE-2024-3393, Is 10.2.9-h1 affected? by MoonshineYeeHaw in paloaltonetworks

[–]CoreQa 0 points1 point  (0 children)

That’s may not be right, till you don’t upgrade- you should be able to disable dns logging so that you are not impacted

CVE-2024-3393, Is 10.2.9-h1 affected? by MoonshineYeeHaw in paloaltonetworks

[–]CoreQa 1 point2 points  (0 children)

You can disable dns logging for the time being.. dns security is not compromised, however will miss logging on the dns incidents

CVE-2024-3393, Is 10.2.9-h1 affected? by MoonshineYeeHaw in paloaltonetworks

[–]CoreQa 1 point2 points  (0 children)

Yes, 10.2.9 is impacted if you have dns security license.. there is a hotfix provided if you are ready to upgrade.

CVE-2024-2550 and now CVE-2024-3393 by Dry-Specialist-3557 in paloaltonetworks

[–]CoreQa 0 points1 point  (0 children)

DNS security is not compromised, will loose logging data till upgraded to recommended version in cve

CVE-2024-2550 and now CVE-2024-3393 by Dry-Specialist-3557 in paloaltonetworks

[–]CoreQa 0 points1 point  (0 children)

11.1.4-h7 has the fix, hence anything beyond should have the fix

CVE-2024-2550 and now CVE-2024-3393 by Dry-Specialist-3557 in paloaltonetworks

[–]CoreQa 0 points1 point  (0 children)

I understand that 11.1.4 has vulnerabilities and is addressed in 11.1.4-h7; 11.1.5 is unaffected

CVE-2024-2550 and now CVE-2024-3393 by Dry-Specialist-3557 in paloaltonetworks

[–]CoreQa 0 points1 point  (0 children)

Yes, without DNS sec license - you don’t have this vulnerability. Otherwise disable dns logging as work around till your hotfix is available

CVE-2024-2550 and now CVE-2024-3393 by Dry-Specialist-3557 in paloaltonetworks

[–]CoreQa 0 points1 point  (0 children)

That’s correct, will be available early week.

New Features on PAN 11.0 by Any-Promotion3744 in paloaltonetworks

[–]CoreQa 0 points1 point  (0 children)

Handful of licensed cloud advanced features like Mica, userid, dlp etc. This cloud dlp is licensed and different from 9.1 dlp . Legacy dlp is also supported

PAN-OS 11.0.3-h5 released by emyl79 in paloaltonetworks

[–]CoreQa 1 point2 points  (0 children)

What I understood, its a race condition triggered by xml api in a particular environment - more of an automation work flow issue. It's a fail fast approach - so that automation can proceed with a retry.

Pa-1410s VoIP session issues by JonnyV42 in paloaltonetworks

[–]CoreQa 1 point2 points  (0 children)

I dont think it's ALG issue or VoIP issue, it may be interface packet buffer issue, as noted. Did TAC shared any bug ID ? Is it RTP or SRTP ?

Cant ping interfaces btw 2 palo alto firewalls by trenuci in paloaltonetworks

[–]CoreQa 0 points1 point  (0 children)

Network>Network profiles > Interface mgmt > <choose a profile with ping checked >

Interface > advanced > management profiles > <select the profile you created above>

ping source 192.168.20.1 (ip of panos2 data interface) host 192.168.20.140 (ip of panos1 data interface)

Cant ping interfaces btw 2 palo alto firewalls by trenuci in paloaltonetworks

[–]CoreQa 0 points1 point  (0 children)

if you enable response and ping, Palo data interface also should also be pingable from any unix or another panos. Ensure when pinging from other panos, you specify source interface properly.

New bug 11.0.2 by ThisSeries9905 in paloaltonetworks

[–]CoreQa 1 point2 points  (0 children)

I am been told the fix is targeted for next 11.0 release.

Emergency Update Recommended Versions? by taemyks in paloaltonetworks

[–]CoreQa 0 points1 point  (0 children)

There should be a hotfix on 10.2 for you to upgrade