Problem to access the internet on Paloalto Firewall

I am configuring a new AP-850. MGT port works fine and I can access the Internet. Now, I configure ethernet1/1 to access the Internet. 

pa-5.JPG

I also configure the routing. But can’t ping 8.8.8.8. Do I miss something or how do I troubleshoot it?

pa-6.JPG

Troubleshooting: 1. Make sure Virtual router is setup correctly.

2. Make sure Policies>Security is setup correctly.

3. Make sure Policies>NAT is setup correctly.

Please view this step by step video:

Paloalto Firewall routing problem

I am configuring a new AP-850. MGT port works fine and I can access the Internet. Now, I configure ethernet1/1 to access the Internet. 

pa-5.JPG

I also configure the routing. But can’t ping 8.8.8.8. Do I miss something or how do I troubleshoot it?

pa-6.JPG

Troubleshooting: 1. Make sure Virtual router is setup correctly.

2. Make sure Policies>Security is setup correctly.

3. Make sure Policies>NAT is setup correctly.

Please view this step by step vidoe:

Can’t ping FQDN in Paloalto Firewall

Case 1: The client re-configured their new Windows DC and PA-850 Firewall. He can ping a public IP address, but not Full Qualify Domain Name

Troubleshooting: We run show deviceconfig system dns-setting config command to check the DNS settings, it shows 10.0.0.84 and 10.0.0.73, which are older DNS serer IP addresses. Replacing them with the new DNS IP addresses fixes the problem.

Case 2: The client just changes their IPS. They have a problem to access the Internet.

When the client checks the DNS settings on PA-850, it looks good.

Troubleshooting: In reviewing their configuration on PA-850, they still keep the old IPS IP address just in a case they need to switch back.

In this situation, we need to re-configure the DNS service on PA-850.

* Go to Device>Setup>Services

•Click Services Route Configuration under Services.

•Check Customize

•Click on DNS

* Select the new IPS IP Address which you are using, which x.x.x.124/28 in our example.

Now, you should be able to ping FQDN.

Tips: We can use these command lines to check the DNS status.

  1. Enable configuration mode

set cli config-output-format set
configure

2. Run these commands:

Show deviceconfig system dns-setting

Show deviceconfig

Show deviceconfig show session all filter application dns

Please view this step by step video:

https://youtu.be/kq3lpOUobrE

How to modify DNS IP address on Paloalto Firewall

The client just migrated their DNS to a different server using a different IP address. This article shows how to modify the DNS Server on Paloalto Firewall based on PA-850.

1.Login PA-850.

2.Go to Device>Setup>Services.

3.Click on Settings icon.

4. You can modify the DNS Server here.

5. Click OK to close.

6. Click the Commit to save the configuration

Please view this step by step video:

Why do I receive Error Code 0xC004E028 when activating Windows 2019?

If you are receiving error code 0xC004E028 when trying to activate your Windows it means that your computer is already in the process of activation. During the activation process, Windows sends out the Key to Microsoft servers to validate it.

Sometimes validation takes a long time, and if you try to activate it again, you will receive this error code 0xC004E028. Wait for a few more seconds you should be fine.

Fixing “We Need You To Fix Your Microsoft Account (most likely your password changed)”

When login Windows 10 PC, you may receive a pop-up message saying “Microsoft account problem. We need to fix your Microsoft account. (Most likely your password changed). Select here to fix it in shared experiences settings.“ This article shows some cases with resolutions we have been working on this message.

Case 1: The client gets this “Microsoft account problem. We need to fix your Microsoft account” message when he logs in Windows 10 using Microsoft account.

Resolution: Login local user account and check the account settings.

* If you don’t have local account, cerate one by going to Settings>Account.

•Click Family & other users on the left pane.

•Under Other users, click on Add someone else to this PC.

* Click I don’t have this person’s sign-in information.

  • Click on Add a user without a Microsoft account.

* Enter the username, password, and follow the wizard to complete the settings.

•After login the user account, go to Settings>Account to check the account status.

•Then re-login Microsoft account.

Case 2: The client gets this message after sharing a folder.

Resolution: Go to Settings > System > Shared Experiences. Turn off Share across devices. Or Select My Devices only if it is on.

Case 3: Run the Microsoft Account Troubleshooter to automatically resolve the issue.

Click link below or search download the MS account troubleshooter

http://download.microsoft.com/download/F/2/4/F24D0C03-4181-4E5B-A23B-5C3A6B5974E3/microsoftaccounts.diagcab

* After the download, run the application and follow the wizard

Microsoft Account Troubleshooter may fix the following issues:

Corrupt Microsoft Account settings

Can’t connect to the sync service

Problems with Microsoft account Policy

Microsoft Account required

Connection issues due to proxy or certificate issues

Check for roaming GPO enabled status

Problem with system registration

Signed in with a guest account, or Roaming User Profiles enabled

You are not connected to the Internet

Proxy Settings

You have reached your daily sync quote

Sync your settings is turned off Check system not activated.

Case 4: Verify your identity on your Windows 10 PC.

•Go to Settings > Accounts.

•In Verify your identity to sync passwords across your devices, click Verify.

* Select the security code to be sent to you.

* Follow the wizard to complete the verification process.

Case 5: We help client fixing this issue by installing the Windows latest update

Case 6: Change or reset the sign-in option.

•If you use Windows Hello PIN to login, you may want to change to Password or reset the PIN.

•After you change to password login or reset the PIN, try to use the PIN again.

Please view this step by step video: