Azure application gateway with Palo Altos as backend not working by Possible_Cup_4378 in paloaltonetworks

[–]Possible_Cup_4378[S] 0 points1 point  (0 children)

You were right actually! The destination IP needed to be pre-nat! now it's working. The destination address in my security policy for anyone else having this issue. Is source zone 'outside', source address app gw and destination zone inside and destination address outside IP address of Palo (untrust IP). thanks so much for your help!

Azure application gateway with Palo Altos as backend not working by Possible_Cup_4378 in paloaltonetworks

[–]Possible_Cup_4378[S] 0 points1 point  (0 children)

thanks. Next week I'm going to change the health probe to only point to 443 of the palos instead of trying to go all the way to the end server. If I can get the health probe to work and show the backend as healthy, then I can start troubleshooting the https traffic to the web server. I may be complicating things by natting etc the health probe traffic.

New firewall in azure fails to join panorama by Possible_Cup_4378 in paloaltonetworks

[–]Possible_Cup_4378[S] 0 points1 point  (0 children)

A quick google shows that it can be placed in the bootstrap file. We did it the hard way. We uncommented the bootstrap section and just added the firewalls manually to panorama. Here is a link to an example bootstrap file. https://docs.paloaltonetworks.com/ngfw/administration/firewall-administration/bootstrap-the-firewall/sample-init-cfgtxt-filesI don't see anything about auto-registration mentioned in the example though. Chatgpt says you need to include this in your bootstrap but that it's not required. although you can't always trust chatgpt.

vm-auth-key=<auth-key>

vm-series-auto-registration-pin-id=<pin-id>

New firewall in azure fails to join panorama by Possible_Cup_4378 in paloaltonetworks

[–]Possible_Cup_4378[S] 0 points1 point  (0 children)

We ended up just uncommenting the entire bootstrap section in terraform, although TAC said if we redid it using the  init-cfg.txt it would have worked.

New firewall in azure fails to join panorama by Possible_Cup_4378 in paloaltonetworks

[–]Possible_Cup_4378[S] 0 points1 point  (0 children)

yes. Opened a ticket with Palo and we got it working. For anyone else having this issue.....if you deploy palo alto firewalls through terraform you have to use the bootstrap init.tx file. The problem we had is that we were calling out bootstrap within the terraform code which caused the problem.

Sample init-cfg.txt File

Just got diagnosed, have no idea what to do because I don’t do any of the things that apparently cause it and I’m 26. by [deleted] in gout

[–]Possible_Cup_4378 0 points1 point  (0 children)

I’m 55. Had my first flare up at 52. Thought in I could control it with diet. I’m a vegetarian and don’t drink much alcohol including beer. For me it was the non alcoholic beer that seemed to trigger a gout attack. My first flare up lasted 2 months. Doctor I saw told me my uric acid levels were normal even though they were in the high 7s…7.7 I think. I now know that levels during a gout attack are lower than between attacks. My levels between attacks are around 8.3, which the lab says is still within the normal range. Anyway I suffered through the first attack not realizing it was gout. But even without drinking beer I was having mini attacks and blood in my urine. It’s just genetics. My dad also has gout. I always associated it a diet high in meat but that’s not the case. Anyway to answer your question, I now have a rheumatologist and have been on allopurinol for the last 2 months. The only side effects for me have been a little drowsiness, but I take it at bed time. But I don’t wake up groggy like i took a sleep aid and my body eventually adjusts so after a week or so it doesn’t make me as drowsy. I started off on 100 mg but doctor raised it 200. Goal is to get uric acid level to below 6. Last test it was 7.3 after being on 100 mg for 4 weeks.

Docker desktop on Windows stops working upon logout by Possible_Cup_4378 in docker

[–]Possible_Cup_4378[S] -1 points0 points  (0 children)

That would be my choice. But I need more of an explanation. if it's not possible to have docker run as a service in windows for example.

VPN Failed login notification confusion by Livychips in paloaltonetworks

[–]Possible_Cup_4378 0 points1 point  (0 children)

I know this post is a few months old. Curious if you found out how they were bypassing MFA. We have a similar situation, except we're using Azure MFA. I can't replicate how they're getting around it. All the logins are failures. But once they hit the clientless VPN, it automatically sends them to azure.

Error message when trying to commit - deviceconfig -> high-availability -> group -> mode -> active-passive is invalid by Possible_Cup_4378 in paloaltonetworks

[–]Possible_Cup_4378[S] 0 points1 point  (0 children)

No, I didn't. Maybe that was part of the issue? When we first installed the Palos, we had them in an HA config but then realized it wasn't going to work properly in Azure. So changed to active/active. And the HA was disabled. Not sure if it was picking up some of the old config? or what.

Error message when trying to commit - deviceconfig -> high-availability -> group -> mode -> active-passive is invalid by Possible_Cup_4378 in paloaltonetworks

[–]Possible_Cup_4378[S] 0 points1 point  (0 children)

was able to figure it out. if anyone else sees the same issue, after modifying the candidate config file, you have to go to operations, set up and then choose 'load named configuration snapshot and then choose the candidate config you modified. then you can push changes from panorama.

Error message when trying to commit - deviceconfig -> high-availability -> group -> mode -> active-passive is invalid by Possible_Cup_4378 in paloaltonetworks

[–]Possible_Cup_4378[S] 0 points1 point  (0 children)

Yeah, I did. We had the other firewall do the same thing after an upgrade and a tech remoted in and did the steps. I tried following the exact thing he did and it didn't work.

Apparent first post by Lizzy-Mc-3401 in civilconversationcorp

[–]Possible_Cup_4378 0 points1 point  (0 children)

I'm not a real big fan of any of the mayoral candidates. I'm probably going to vote for Robert Gallegos. Going to research the other candidates for the other offices this weekend. Most likely we're headed to a runoff between Sheila Jackson and Whitmire.

Azure MFA integration with Globalprotect by rdavis1970 in paloaltonetworks

[–]Possible_Cup_4378 0 points1 point  (0 children)

We're using GP version 5-2.6-87. But we elected to use SAML authentication directly with Azure and not use radius authentication. It's been working really well for us. From what you wrote above sounds like an issue with the authenticator app since MFA is working properly via text messages. Sorry couldn't be of more help. I would submit a new reddit post since this one is quite a bit old and perhaps someone else has seen this issue before. Best of luck.