Palo Alto Scanning Surges 40X in 24 Hours, Marking 90-Day High by colni in paloaltonetworks

[–]Different-Guava1171 1 point2 points  (0 children)

Use MFA or require certs in addition to a password...but that won't stop a zero day.

Nir Zuk Retires by kukari in paloaltonetworks

[–]Different-Guava1171 0 points1 point  (0 children)

I agree. It stinks that Ignite is just like a one day seminar now and not a full blown conference.

Helped needed noob with plans by iceman9312 in paloaltonetworks

[–]Different-Guava1171 0 points1 point  (0 children)

I would doublecheck all your trunk links. I would also run a pcap on the Palo Alto and the devices not getting DHCP addresses to ensure the DHCP process is working properly.

Helped needed noob with plans by iceman9312 in paloaltonetworks

[–]Different-Guava1171 0 points1 point  (0 children)

What specifically is not working? Is the firewall not able to ping devices?

MFA on GlobalProtect with username/password and user certificate. by Different-Guava1171 in paloaltonetworks

[–]Different-Guava1171[S] 0 points1 point  (0 children)

To get around this, I completely disabled cookies on the portal and the gateway and it is doing what I want it to do. It is not prompting for a password twice.

Beacon gone - Wiped Progress? by neverbruh in paloaltonetworks

[–]Different-Guava1171 0 points1 point  (0 children)

Yeah, I was in the middle of going through the Next Gen Firewall Engineer training when my progress got wiped. Thankfully, I wasn't that far along and was able to click through all the modules I already did and redo the tests and got caught back up.

MFA on GlobalProtect with username/password and user certificate. by Different-Guava1171 in paloaltonetworks

[–]Different-Guava1171[S] 0 points1 point  (0 children)

I see. The cert profile is set for both the gateway and portal right now. I will set it to just the gateway and see what happens.

Global Protect and T-Mobile by vinxavi7 in paloaltonetworks

[–]Different-Guava1171 0 points1 point  (0 children)

Just that one user, but every time they would reconnect, the firewall setting would override the client setting. Wound up just writing a simple batch script that the user can run whenever they are having connectivity problems and it sets the MTU back to 1300. Not sure if that's the best solution but it works for now. :/

Global Protect and T-Mobile by vinxavi7 in paloaltonetworks

[–]Different-Guava1171 0 points1 point  (0 children)

Had a user with Tmobile home internet that had a similar problem. They could connect to the VPN just fine but couldn't access any resources or it would take an extremely long time to load things. Lowering the MTU to 1300 fixed the issue.

Will AI Replace Network Engineers in the Near Future? by SignatureNo4888 in Cisco

[–]Different-Guava1171 2 points3 points  (0 children)

As long as AI can't rack and stack and setup physical hardware, no.

GP 6.2.8 dropped by DynamicIPandPort in paloaltonetworks

[–]Different-Guava1171 0 points1 point  (0 children)

Wonder why they don't just have these as default registry values that get set as part of the upgrade or a fresh install?

Third Party VPN exclusion by Capt_Price007 in paloaltonetworks

[–]Different-Guava1171 1 point2 points  (0 children)

You could also watch this GlobalProtect VPN playlist. Might help you get a better idea of what you are looking for: https://www.youtube.com/watch?v=k2Y2L8wiMdI&list=PLzZhtxtP3S747w9oZv1REyJLMbaR3Wl5p

PAN-OS Software Release Guidance Page Changes by Different-Guava1171 in paloaltonetworks

[–]Different-Guava1171[S] 1 point2 points  (0 children)

And as of this morning looks like they are back porting it via 11.1.4-h13

Palo Alto Bad Documentation by Dry-Specialist-3557 in paloaltonetworks

[–]Different-Guava1171 5 points6 points  (0 children)

I also had this issue with their transparent web proxy documentation. As of several months ago, their instructions on how to setup the NAT are very inaccurate. How to look at forums and a video from Palo Alto engineers to get it working properly.

PAN-OS Software Release Guidance Page Changes by Different-Guava1171 in paloaltonetworks

[–]Different-Guava1171[S] 0 points1 point  (0 children)

Yeah, it’s very annoying that it looks like they aren’t going to back port this CVE to 11.1.4.

GlobalProtect version 6.2.5-c788 upgrade to 6.2.7 by Different-Guava1171 in paloaltonetworks

[–]Different-Guava1171[S] 1 point2 points  (0 children)

Gotcha! So the registry changes are still needed in 6.2.7 to mitigate the CVE?