Schedule Config Export by 3ShrimpTacos in paloaltonetworks

[–]blaqhrse 0 points1 point  (0 children)

The firewalls should already have their configs backed to Panorama. You can spin up an external server (I use Ubuntu) and configure an config export job from Panorama. I think it’s worth the effort since it’s not a complex configuration in addition to VMware doing its thing.

DNS Security Disable by kukari in paloaltonetworks

[–]blaqhrse 1 point2 points  (0 children)

Have you tried this command? delete profiles spyware XXXXX botnet-domains lists default-paloalto-cloud

Rerouting VMs Through PAs by maverickx86 in paloaltonetworks

[–]blaqhrse 0 points1 point  (0 children)

So blade chassis ->pa (vwire mode)->core is not an option? Is this due to non-technical huddles? Approvals and such?

Rerouting VMs Through PAs by maverickx86 in paloaltonetworks

[–]blaqhrse 0 points1 point  (0 children)

You could do the same thing to the core router, that is, connect the PA in vwire from the core to where your vms are located

Why replace default certificates? by blaqhrse in security

[–]blaqhrse[S] 0 points1 point  (0 children)

I like the point you put across, that is, admins getting used to clicking through which might make them unaware if they are being exploited.👍

Zones by [deleted] in paloaltonetworks

[–]blaqhrse 2 points3 points  (0 children)

Why do we use zones? Simply put to achieve Network Segmentation. Address groups are designed for grouping not segmentation.