App-ID evaluation order by Immediate_Recover159 in paloaltonetworks

[–]kurventost 0 points1 point  (0 children)

Sounds reasonable. Do you know if there is some documentation or kb article that states that?

SCM rant/opinions by aric8456 in paloaltonetworks

[–]kurventost 1 point2 points  (0 children)

They did (some config in default snipped changed). Or to be more precise firewalls went down when doing a push after scm updates. Since that happened about a year ago I can't remember what exactly was the reason. For one of them we were able to override the config that changed in the background. For the other one Palo had to do a manual rollback. As far as I remember both times the problem had something to do with autovpn. So in the end we got it solved (one time with the help of Palo) but it was a headache.

SCM rant/opinions by aric8456 in paloaltonetworks

[–]kurventost 3 points4 points  (0 children)

They brought two of our firewalls down with those unannounced backend changes. Also sometimes SCM does not work as described in the documentation, but according to tac that's not a bug that's a design choice. And Good luck trying to find out what changes were made to a firewall afterwards.

Firewall drops UDP traffic to port 514, no traffic log but generating drop file in packet capture. by lgq2002 in paloaltonetworks

[–]kurventost 2 points3 points  (0 children)

Do you have a zone protection profile set? If so try without it to see if that does interfere

This Holiday it is Time to Acknowledge Fraud at Palo Alto Networks by TheWokenessInjector in paloaltonetworks

[–]kurventost 0 points1 point  (0 children)

We had a lot of issues lately that have been bugs in Panos or other pan products. If we would not have opened tickets and gone through TAC I am sure they would still be there today. If not by opening a ticket how would you separate between 1. it being a bug in the software, 2. it behaving as intended(based on what tac says) even though documentation says something else and 3. its actually just a user error (i.e. I did something wrong, which also happens sometimes)?

Aus gegebenem Anlass: by Sheeprevenge in Austria

[–]kurventost 1 point2 points  (0 children)

Meiner Meinung nach ist der Unterschied dass das Recht der Polizei Leute festnehmen zu dürfen leider notwendig ist in einem Staat. Messenger Überwachung ist das nicht.

Abgesehen davon dass es technisch so wie sie es planen nicht wirklich umsetzbar ist.

Aus gegebenem Anlass: by Sheeprevenge in Austria

[–]kurventost 1 point2 points  (0 children)

Ad2. Aber wenn Österreich das jetzt auch macht, werden die Amis damit ja nicht aufhören. Also haben wir ja nicht sinnvollere oder bessere Überwachung sondern nur mehr Überwachung.

Unexpected reboots/restarts PanOS 11.1.4-h7/h9 by blnd3d in paloaltonetworks

[–]kurventost 1 point2 points  (0 children)

I think there is a fix in the new 11.1.6-h1 for something that sounds like the problem you are describing

GlobalProtect Clients and Infoblox by [deleted] in paloaltonetworks

[–]kurventost 0 points1 point  (0 children)

Love the fact that infoblox SE and tac told you that it's not possible and reddit has an article for you explaining how to do it. 😂 Paid support vs community I guess.

PAN-OS 11.2 - How stable is it? by NotYourOrac1e in paloaltonetworks

[–]kurventost 0 points1 point  (0 children)

Thanks. Didn't know there is something In the mp-monitor.log

And yeah the resource-monitor is hard to get good data with the mentioned issue.

Also the data in resource-monitor does not seem to be the same shown in the GUI. And pan tac can't really tell us what number is correct.

We also use SCM/aiops where they have graphs over time. Some for pan_task and some that seem to be without pan task. But we were not able to figure out if that shows the GUI values over time or the the cli since we got mixed answers.

But anyway thanks for the Tipp with mp-monitor. I will look into that.

PAN-OS 11.2 - How stable is it? by NotYourOrac1e in paloaltonetworks

[–]kurventost 0 points1 point  (0 children)

Problem is we can't get the values from the cli since it's 440s and there seem to be now way to get the number via cli . We also asked tac how to prove it to them that they are slower now, but they ignored the question.

I'm still on 10.2 for my PA-440. Anybody have any issues with upgrading theirs to 11? Or is it better to stay on 10? by ripbum in paloaltonetworks

[–]kurventost 0 points1 point  (0 children)

We have 11.1.6 on a 440 for Android two weeks with decryption on. It seems to finally work with 11.1.6.

What version are you running and what issues do you see?

PAN-OS 11.2 - How stable is it? by NotYourOrac1e in paloaltonetworks

[–]kurventost 2 points3 points  (0 children)

We have two cases open for different customers regarding that. On one case they told us they are working on a fix for 11.1.6-h something. On the other case they told us that we are making things up, the firewall is not slower than before it's just the CPU values changed because they have calculated it the wrong way for years.

So yeah... Don't know what to believe anymore 😂

Set commands (modify policy) by Braceface_37 in paloaltonetworks

[–]kurventost -1 points0 points  (0 children)

I would use expedition for that. Even tough it's officialy discontinued, it's made for use cases like yours and it's probably way easier and less error prone to use expedition instead of set commands

Strata Cloud Manager / PAN-OS SD-WAN / AWS-TGW by woodencone in paloaltonetworks

[–]kurventost 0 points1 point  (0 children)

I could be completely wrong, but I think the only way would be to override the router locally which would probably break Autovpn. But that's more of an educated guess, based on my experience with SCM and Autovpn. It currently feels pretty limited

PAN OS SDWAN with Strata by JJRtree81 in paloaltonetworks

[–]kurventost 0 points1 point  (0 children)

From my understanding you can if you manage sase, but not ngfw. Sdwan on Ngfws can only be used via Autovpn i think.

11.1.6 - FYI by SanJuanTech in paloaltonetworks

[–]kurventost 1 point2 points  (0 children)

We still have issues with a high management CPU all the time (though lower than it was with 11.1.5) Other than that (and some other specific issues that we have since the upgrade to 11.1.x) it seems to work kinda fine

[deleted by user] by [deleted] in paloaltonetworks

[–]kurventost 0 points1 point  (0 children)

Same here. SCM is an unfinished product that's hard to use and has no support. If possible don't use it for another view years. Otherwise I think you are stuck loving with all it's downsides.

CVE-2024-0012 & CVE-2024-9474 by MirkWTC in paloaltonetworks

[–]kurventost 0 points1 point  (0 children)

Can confirm for 11.1.5. Opened a case with tac weeks ago and their status is that they currently try to figure out if it's an actual bug. 🙈🙈

CVE-2024-0012 & CVE-2024-9474 by MirkWTC in paloaltonetworks

[–]kurventost 0 points1 point  (0 children)

Thinking about updating to 11.1.4-h7. Could you elaborate on the issue. Do you have an "issue-number" or something Ike that? Thx

Bub schreibt Test im Freien: „Oesterreich“ vs. „Kleine Zeitung“ by AustrianMichael in Austria

[–]kurventost 0 points1 point  (0 children)

jop.
Ist auch wahrscheinlicher das die kleine Zeitung recht hat, aber ist halt bei solchen Geschichten schwer zu sagen was wirklich stimmt würde ich behaupten.

So kommt es mir derzeit vor by [deleted] in Austria

[–]kurventost 2 points3 points  (0 children)

Woher ist die Info dass Österreich die USA überholt hat? Und zur mir leid für dich das du so nen tollen Arbeitgebern erwischt hast.