General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

40 g connectivity

Hi,

I have the below topology 

 

 

PA has two 40 g ports and my core has 4 40g ports . server SW  also has  40 g ports ( the switch is for connecting servers ) 
core required two 40g Ports for cross-connection.

So remaining two 40g connections,

Do I need to

...

pa1.png
simsim by L4 Transporter
  • 2427 Views
  • 6 replies
  • 0 Likes

Resolved! Transparenlty NATing IPsec traffic to other device

Hello,

 

We have an issue with forwarding an IPsec connection to a VPN device behind the PAN-OS FW.

 

So the setup is supposed to be the following:
* PAN-OS is using outside interface 192.168.1.1/24
* 192.168.1.2 is an address with DNAT to 10.10.10.1 on an

...

ifstciss by L1 Bithead
  • 1866 Views
  • 1 replies
  • 0 Likes

Resolved! Cannot reach server at DMZ via Nat

Hi 

NAT is setup at PA for outside users to reach DMZ server based on protocol
The topology is like the below:

SW1(f1/1) -------- (e1/1,DMZ)PA(Outside,e1/5)--------(f1/5)SW2

Interface config:

e1/1 10.100.255.1/24
f1/1 10.100.255.2/24 as inside Server

e1/5 4

...

DavidyPalo_0-1640193938552.png
DavidyPalo_1-1640192264988.png
DavidyPalo_2-1640192562824.png

Agentless User-ID Not Connected (RESOLVED)

EDIT: I have resolved my issue... adding this in case someone runs into the same issue I did. Basically, I'm an idiot lol. Issue was because my AD servers are in a security zone and I needed to add a security policy that allowed the management IP add
...

Resolved! Firewall Events as Report

Hi All,

 

Is there a way where, I can generate report of firewall events, Like login events from system logs, As daily basis. And I will share through email. 

 

NGFW 

Migrate Panorama from VMware to AWS

Has anybody migrated Panorama from on prem to AWS? There are a few options that are available to us, and I am trying to decide which option is the best. Also, if you can list any "gotchas" during the migration that would benefit us, that would be rea

...

Fr4nk4 by L2 Linker
  • 3014 Views
  • 2 replies
  • 0 Likes

Resolved! IPSEC ON SECONDARY ADDRESSES

Hello,

just a little question it is possible to terminate a vpn-ipsec with a secondary adresses on external interface or I must use the main interface?

thks,

ALex

alle by L3 Networker
  • 3447 Views
  • 3 replies
  • 0 Likes

Resolved! SSL forward-proxy certificate import

I've gerenated a CSR to give my enterprise CA. Now, I've recieved the enterprise CA-signed certificate ann imported it onto the firewall.

The status reads "valid". The "Key" box is checked, however the "CA" box isn't. 

Also, when I select the certifica

...

Geoblocking Missing

We are on 8.1.21 - When creating a geoblocking rule I do not have the option for 'Regions' in my rule drop down.  Is this due to my version OR do i need to upload a geoblocking list [how?]

 

thanks!

NAT before IPSEC

Hi folks,

 

We have a vendor requiring a public IP for the encrypted traffic.  Their guidance is based on Cisco configurations using "NAT before IPSEC" configurations.  Can anyone share/link a guide for this configuration on Palo?  Currently on PAN-OS

...

  • 24195 Posts
  • 100 Subscriptions
Labels