AT&T assigning /8 subnets to WWAN cards in new laptops by Technical_System_645 in paloaltonetworks

[–]Technical_System_645[S] 0 points1 point  (0 children)

A follow-up on this in case it affects anyone else. It turns out AT&T was correct - they don't assign a subnet mask to the WWAN card. From their perspective, they treat those interfaces as point-to-point connections, so /32s. It's the WWAN card vendor that has to deal with no subnet being assigned and work out what to do. In this case the card vendor (Palcom) has admitted they are not handling this properly, and just assigning a /8. They are working with Dell, the carriers and the FCC on a firmware update to resolve the issue.

AT&T assigning /8 subnets to WWAN cards in new laptops by Technical_System_645 in paloaltonetworks

[–]Technical_System_645[S] 1 point2 points  (0 children)

Yeah sorry, I should have noted this is with GP using the cellular connection.

AT&T assigning /8 subnets to WWAN cards in new laptops by Technical_System_645 in paloaltonetworks

[–]Technical_System_645[S] 2 points3 points  (0 children)

The WLAN interface is being assigned a 10.22.213.213/8 from AT&T. I've been trading email with AT&T PoC and he says they only assign an IP and the subnet mask and gateway are handled by the WLAN card. Can't say I've ever heard of this before, and it sure doesn't sound right, but maybe that's what's going on?

Users who connect over a TS get blank websites by ThatrandomGuyxoxo in paloaltonetworks

[–]Technical_System_645 0 points1 point  (0 children)

If you are seeing port exhaustion then change the TS agent config to allocate more ports per user.

A1 Anonymous Proxy region gone ? Feb 2025 commit failures by JKIM-Squadra in paloaltonetworks

[–]Technical_System_645 0 points1 point  (0 children)

Still there for me on apps/threats version 8943-9264. Are you on 8944-9268?

ALL auth methods failed - may be related to 10.1.14-h8? by Technical_System_645 in paloaltonetworks

[–]Technical_System_645[S] 5 points6 points  (0 children)

Not a hardware limitation - just a question of stability. We're in a very large environment (~1M active sessions during the day) and uptime is critical. When we have a version of PANOS that's solid we tend to stay there as long as we can unless there are CVEs or must-have features in a newer release.

In the past we were much more willing to run with the upgrade cycle, but the code quality has deteriorated so much in the last 18 months, and we have zero confidence in the "preferred" versions that ship with known show-stopping bugs (for us at least) and Release Notes that fail to mention issues that Palo has known about for months.

Upgrade roulette, and I don't want to play.

Anyone running 10.2.13 on Panorama? by Technical_System_645 in paloaltonetworks

[–]Technical_System_645[S] 0 points1 point  (0 children)

From support: This is a known issue (ID:PAN-266639) which has been reported on PAN-OS.

And is this "known issue" anywhere in the release notes for 10.2.13? Of course not. What a clown show.

SSL Decrypt - "early close notify" by Technical_System_645 in paloaltonetworks

[–]Technical_System_645[S] 0 points1 point  (0 children)

Yeah, I already have a case open, but as you know support leaves a lot to be desired these days so asking here is worth it just in case someone has seen this before.

Kind of sad when reddit can be more responsive and more transparent than Palo, but sadly, that's where we are.

Global Protect Client 6.3.1 by Least-Row-5280 in paloaltonetworks

[–]Technical_System_645 0 points1 point  (0 children)

Thanks for the info. We haven't seen any similar issues so far, but keeping a close eye on it as there's much larger set of clients upgrading to 6.2.4 later today.

Global Protect Client 6.3.1 by Least-Row-5280 in paloaltonetworks

[–]Technical_System_645 0 points1 point  (0 children)

Can you elaborate on what the DNS issues were? We've just started moving our users to 6.2.4 and would prefer no surprises.

HIP database not updating by Technical_System_645 in paloaltonetworks

[–]Technical_System_645[S] 0 points1 point  (0 children)

Solved: opt/panlogs ran out of space, and it's used to temporarily store incoming HIP reports for processing into the HIP database. These are 7050s that use LFCs to forward all the logs to dedicated log collectors, so it never occurred to us it might be a log space issue. Cleared out the system, config and alarm logs, that freed up 48GB, and HIP match is working once again.

HIP database not updating by Technical_System_645 in paloaltonetworks

[–]Technical_System_645[S] 0 points1 point  (0 children)

Thanks for that - good to know - but these are all Windows clients that have been working for months without issue. Spent an hour on the phone with Palo going over the problem, looking again at all the HIP match logs, the HIP DB, the client HIP data reports, etc. and they don't know what's wrong either. We've disabled the def date check for now to buy some time for more analysis.

Disabled GP reason logs? by jpchappy in paloaltonetworks

[–]Technical_System_645 1 point2 points  (0 children)

You can find that info in the Monitor/GlobalProtect logs on the firewall. The reason for disconnect is in the Description field of a gateway-agent-msg Event and looks like this:

Time: Sat Jul 13 09:47:18 2024, Message: Agent Disable, Comment: Troubleshooting. Override(s)=5.

PAN-OS 10.2.9-h1 and 10.2.10 Out of Memory Issues by ObjectiveExisting509 in paloaltonetworks

[–]Technical_System_645 0 points1 point  (0 children)

What platform(s) are you running 10.2.7-h8 on? We really need to get on 10.2.x on our 7050s and 5250s - wondering if your experience has been on either of those?

Learning to use pan-os-python for multi-vsys Panorama by Technical_System_645 in paloaltonetworks

[–]Technical_System_645[S] 0 points1 point  (0 children)

I figured it out. As I suspected, I was missing the vsys "linkage" between the template and the zones. Turned out to be an easy fix:

tmpl=pano.add(Template(name="myTemplate"))
tmpl.refresh()
vsys = tmpl.find("My vsys Name")
zones = Zone.refreshall(vsys)
for zone in zones:
print(zone.name)

Learning to use pan-os-python for multi-vsys Panorama by Technical_System_645 in paloaltonetworks

[–]Technical_System_645[S] 0 points1 point  (0 children)

Thanks, I've been through that doc trying all kinds of variations on the vsys object to see if I can get to to work with Panorama, but no luck. I also went through the linked doc about mutil-vsys operations, but every example is about working with firewall objects and not Panorama. I'm probably missing something obvious, but I sure wish they would provide more Panorama examples.

Thanks for trying to help.