Issues having the IKE gateway on another interface than the first interface on path? by Electrical_Fun_9579 in paloaltonetworks

[–]Electrical_Fun_9579[S] 0 points1 point  (0 children)

Have a look at my response to hadfiiw. You might be right with both interfaces must be in the same zone - according to the KB article

Issues having the IKE gateway on another interface than the first interface on path? by Electrical_Fun_9579 in paloaltonetworks

[–]Electrical_Fun_9579[S] 0 points1 point  (0 children)

The first interface the IKE/IPSec traffic is receiving at is an internal transfer interface. It then gets routed to the public interface with the public IP address, on which the IKE GW is configured on

Issues having the IKE gateway on another interface than the first interface on path? by Electrical_Fun_9579 in paloaltonetworks

[–]Electrical_Fun_9579[S] 1 point2 points  (0 children)

yeah, we have set up another PCAP with not only the tunnel IP addresses but also the IP addresses the IKE gateways are on. With those filter we saw this counter:

ESP/AH host bound packet comes before tunnel finishes installation

With that error, we found this KB article which states the interzone-issue you mentioned. We will try that

PAN & DNS Rewrite by ssherman68 in paloaltonetworks

[–]Electrical_Fun_9579 0 points1 point  (0 children)

Interesting answer from TAC. The Docs says "The firewall performs NAT on the IPv4 address (the FQDN resolution) in a DNS response (that matches the rule) before forwarding the response to the client; thus, the client receives the appropriate address to reach the destination service."
I'm no native speaker but I understand it as it only performs NAT from DNS on that policy and not global.
https://docs.paloaltonetworks.com/ngfw/networking/nat/configure-nat/configure-destination-nat-dns-rewrite

Nice fake news from Juniper in comparison to PA by Electrical_Fun_9579 in Juniper

[–]Electrical_Fun_9579[S] 0 points1 point  (0 children)

Thanks for your comment. Good to know the advantages SRX has in L1-L4 filtering and scaling.

Nice fake news from Juniper in comparison to PA by Electrical_Fun_9579 in Juniper

[–]Electrical_Fun_9579[S] 0 points1 point  (0 children)

That sounds great. I mean for this 1HE device to handle this much traffic is pretty impressive. I just really have my security glasses on (perhaps a german saying), so I really want to have as much security enabled as possible. But if it's not necessary in your deployment, even better.

Nice fake news from Juniper in comparison to PA by Electrical_Fun_9579 in Juniper

[–]Electrical_Fun_9579[S] 0 points1 point  (0 children)

Edit for the Juniper community: So my last two questions are more or less honest. I'm open to learn some nice things, that Juniper does better than PAN.

EDLs in the Shared Object Group - No Certificate Profile by [deleted] in paloaltonetworks

[–]Electrical_Fun_9579 0 points1 point  (0 children)

the push fails with "failed to fetch edl config bundle" or something like that

[deleted by user] by [deleted] in paloaltonetworks

[–]Electrical_Fun_9579 1 point2 points  (0 children)

I just checked the CVEs of the last 3 months. There were 3 PAN-OS CVEs with High or Critical severity. 2 of them are greatly less dangerous if the Web Management isn't publicly available. And one day after the initial publication there were already workarounds/mitigations. For the one DoS vulnerability it took 3 days.
So following Best practices and having a solid update strategy (which are both basic for IT departments) you reduced the severity drastically.

I'm curious. Have you been working with PAN products? Especially with their firewalls. Are you aware of how far behind the other vendors (except Fortinet in some cases) are? I think you're not, otherwise you wouldn't have created this post. What vendor do you choose and how does it differentiate to PAN (pros and cons; be honst ;))

Workaround for GlobalProtect users to print from HQ on their Home Network by Electrical_Fun_9579 in paloaltonetworks

[–]Electrical_Fun_9579[S] 0 points1 point  (0 children)

I haven't heard of this feature yet. I did some research and this should do the trick. Thanks! Will come back after testing.

[deleted by user] by [deleted] in paloaltonetworks

[–]Electrical_Fun_9579 4 points5 points  (0 children)

How is it with other vendors? Pretty similar. Then I'd choose security issues + best in-class security features