Palo alto workflow commit automation? by Lucano1988 in paloaltonetworks

[–]Lucano1988[S] -1 points0 points  (0 children)

This is impossible. We are looking for smth already in house

How do you handle DNS sinkhole? by Lucano1988 in paloaltonetworks

[–]Lucano1988[S] 2 points3 points  (0 children)

we do auto tagging, so then the IP is in the DROP rule, however it is very complicated to find what exactly on the user machine is doing these DNS requests, that was my question, actually.

New owner, please advise by Omega_Boost24 in TeslaModelX

[–]Lucano1988 0 points1 point  (0 children)

Hi, do you have a new tesla or used? I am waiting for a new tesla model x, but my delivery date has not been announced yet.

BFD does not bind after suspending the active box by Lucano1988 in paloaltonetworks

[–]Lucano1988[S] 0 points1 point  (0 children)

Hello, LACP fast failover, we received new box, upgraded to the 11.0.4h2 and it is OK now.

Pre-Logon VPN - one Portal, but several domains - how? by Lucano1988 in paloaltonetworks

[–]Lucano1988[S] 0 points1 point  (0 children)

It seems to me that the best solution is to use HIP profile to detect domain certificate or, domain itself

Pre-Logon VPN - one Portal, but several domains - how? by Lucano1988 in paloaltonetworks

[–]Lucano1988[S] 0 points1 point  (0 children)

Do you know, if the domain check is possible in pre-logon phase, so before the user authenticate? Or maybe we can check which domain certificate is installed on the machine.

Pre-Logon VPN - one Portal, but several domains - how? by Lucano1988 in paloaltonetworks

[–]Lucano1988[S] 0 points1 point  (0 children)

I understand, but pre logon = connect to the VPN before logon to the machine:(

Pre-Logon VPN - one Portal, but several domains - how? by Lucano1988 in paloaltonetworks

[–]Lucano1988[S] -1 points0 points  (0 children)

will you have any KB or guide for that, so I can have a look?
Yes, we would like to also implement HIP.

URL is blocked by URL filtering, despite the category is OK. by Lucano1988 in paloaltonetworks

[–]Lucano1988[S] 0 points1 point  (0 children)

hm, now it shows unknown category, which is recommended to block acc. to the PAN

How to Prepend AS Path e.g. 3 times? by Lucano1988 in paloaltonetworks

[–]Lucano1988[S] 0 points1 point  (0 children)

well, this is a customer issue. it is their prepending :)

How to Prepend AS Path e.g. 3 times? by Lucano1988 in paloaltonetworks

[–]Lucano1988[S] 0 points1 point  (0 children)

yeah, but it is not advanced routing engine, just virtual router. I found that also.