General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Traffic Logs not showing up on Monitoring Tab

Hi All,

 

Device Type: PA-220

Software Version: 8.0.11-h1

 

Im having an issue with old traffic logs not showing up on the monitoring tab. I can see live logs but if I want to check the logs for the previous day or previous 2 days then nothing shows up. I

...

Error fetching External Dynamic List (EDL)

Hello,

 

When trying to fetch an EDL from a web server configured without support for TLSv1 (only support TLSv1.1 or 1.2) the result is "Server error : URL access error".

 

I don't know if PAN-OS 7.1.18 fetch client for EDL only support TLSv1. Checking c

...

fjmjugr by L1 Bithead
  • 4792 Views
  • 6 replies
  • 0 Likes

Resolved! requesting connection status via code or through CLI

Hey there, I'm designing windows 10 app which needs to connect to a office based database via a remote laptop.

The laptop will have access to the office through the GlobalProtect VPN.

I need a way to query the GlobalProtect windows agent to see if ther

...

BGP Import AS Path regex to accept/remove my own ASN

I have  a standard L3 VPN setup where I have VR on each side acting as the CE (customer edge) device.  CE-PE protocol is BGP on both sides.  So, essentially, i have an eBGP peering in which I have to receive prefixes from the distant end, which of co

...

Asymmetric Routing and TCP syn check (Pulukas Solution)

Hi Everyone,

 

Asymmetric Routing and TCP syn verification is a common issue and there were many articles on how to resolve that, basically

1 - To change routing itself and make sure there are no asymmetric routing in the network - best from PA point of

...

Dimitrus by L0 Member
  • 2176 Views
  • 2 replies
  • 0 Likes

Does Palo Alto (VM) firewall supported in VirtualBox?

Has anyone managed to installed and run Palo Alto (VM) firewall successfully in VirtualBox?

I've been trying to setup my own lab for learning purposes. Basically, this lab contains client, firewall, and server with different network segment.
 
Client --
...

PA-VM 8 v1.jpg
prenatip by L1 Bithead
  • 5226 Views
  • 1 replies
  • 0 Likes

VPN certificate expires

Hey!

My firewall is a PA-3020 with 8.0.7. There is a Global Protect gateway and portal, users can connect via Global Protect.

As portal address in the global protect app, we are using an address that is availabe in public dns.

Additionally, there is a p

...

MPI-AE by L4 Transporter
  • 7328 Views
  • 7 replies
  • 0 Likes

Resolved! Use Domain EDL for purposes other than DNS sinkholing?

 Can you use a domain EDL for other purposes or only for DNS sinkholing?

 

In other words, can you use a domain EDL in any policy rule in the same way an FQDN object can be used?

 

I would expect that you can, but wanted to ask.

RISI by L2 Linker
  • 3007 Views
  • 4 replies
  • 0 Likes

Linux and TCP keepalive

Hi

 

Is there some reason that PA have a 1 hour keepalive value, where linux has a 2 hour timeout value.

 

Whats considered best practices ... reset the PA to 2 hours or bring down the linux keepalive value to say 1800

 

A

  • 24208 Posts
  • 99 Subscriptions
Labels