Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hello,I have a an IPSEC tunnel between an ASA5510 and PA820. When sourcing ping from 1.1.1.1 to 10.16.40.199, there are no replies. Encapsulated packets do increment on each side of the tunnel, according to each firewall. It appears as if the ASA doe...
Hello,Users have complained of slow Gmail acccess. After close inspection, it turns out that traffic is being redirected to an address of 192.168.42.46:8443. The address is in the WSA's configuration. It reads as follows:<prox_etc_error_page_logo_url...
Hello,
We are seeing URLs categorization shifts. Why would this happen?
The Talo website - https://talosintelligence.com/ - lists the site as Non-governmental Organizations, but ever so often we lose access because the site gets re-categorized as a...
Hello.
Any and all help appreciated.
Please see the attached diagram.
7ks are at the core.
2ks are at the distribution/agg layer(layer 2 only)
The port-channel comes up and all appears well. However Netapp cannot ping(communicate) with Core-A's I...
I'm a little confused.Traffic wouldn't originate from 10.16.40.199 and be destined for DMZ-2 because 10.16.40.199 is in DMZ-2.I believe the rule in my last snapshot would permit traffic into DMZ-2. I understand. Thanks for the clarification.
Hmm, there is no rule with a source of DMZ-2 to Palo_VPN. Are you implying one is required? I'm not familiar with ASA vpn filters. How would I check for this. Thank you
10.16.40.199 lives on interface DMZ-2 off of the ASA. If I understand you correctly, you're saying I might need an access-list permitting traffic into dmz-2 from palo_vpn, right? Well, I do have an acl for this that permits anything...