General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 310 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3654 Views
  • 2 replies
  • 14 Likes

PA and ASA n route mode

Hi,

I have the below topology  

PA and  ASA are in routed mode . 

The first question is the design is valid? 

I am facing a problem in this design 

ASA says the secondary is failed  ,primary asa says the secondary and dmz zone interface failed 

 

 

 

Thanks

pa-cisco.jpg
simsim by L4 Transporter
  • 1749 Views
  • 2 replies
  • 0 Likes

Secure web-GUI access for managment

Dears,

When i log in my firewall it is showing the connection not secure.

 

 

For secure connection login, i have gone through these documents and try to configure a secure connection for web GUI access.

 

How To Configure A Certificate For Secure Web-GUI

...

Jafar_Hussain_0-1606198282984.png

Panorama HA

Hi Experts, 

 

We've Panorama in HA mode running on 8.1 and due to some reason, secondary is now active. Once the primary is back, with the preemptive checked, primary is still passive. 

 

Can someone please assist why primary is still passive?

 

Note: pls

...

Global Protect issue with Windown server 10

The issue is that when I connected to a server through Global Protect, I can't connect to another server.
I have to disconnect from Global Protect and then connect to the desired server. So basically he can connect to one server at a time.

However, wit

...

Resolved! PA-2020 Update PAN OS 7.1.11 possible?

Good morning,

we have a PA-2020 with sw-version: 7.1.11

Can I update the software version to latest PAN OS?

We want to use SAML 2.0.

is there a way to achieve this?

 

kind regards,

Roland

 

warten mit Login admin / admin show system environmentals ----Thermal...

Number of chassis

We've been using Minemeld hosted on AutoFocus and now I stood up a new instance based on the docker hub image paloaltonetworks/minemeld/latest. There is a difference in the "# of chassis" shown on the system dashboard - 2 for the AF hosted Minemeld a

...

Krum by L0 Member
  • 1522 Views
  • 0 replies
  • 0 Likes

SD-WAN internet link (DIA) monitoring

I have a PA-220 with dual ISPs (WiFi and LTE). I tried to configure SD-WAN for direct internet access (DIA). Both gateways (routers from both ISP) are localy connected via ethernet. As far as I know, SD-WAN pings the gateway IPs to calculated the lin

...

Problem with routing of NATted reply packets over IPSEC tunnel

I have an IPSEC tunnel to another organisation, they have two endpoints at the other end on addresses which conflict with our networks.  We can just focus on one to keep it simple.

 

  • We have an IPSEC tunnel set up and passing traffic fine (tunnel.3 int
...

djr by L4 Transporter
  • 3255 Views
  • 3 replies
  • 0 Likes

Resolved! SMB & Robocopy

Hi,

I have server 2016  with all patches and I use Robocopy to sync files to the  backup server. RC kill smb "server service" several times per day, no event log. Windows 10 clients cant access shares.The only solution is to restart the  server. Can e

...

rasil66 by L1 Bithead
  • 4214 Views
  • 6 replies
  • 1 Likes

Setup Azure MFA with Global Protect - NPS/ISE

I am building this new but don't have concrete steps to start with. What I understand until now is that we need NPS extension for MFA to work with Azure. We last year moved away from NPS as our radius server to Cisco ISE.  So do I have to figure out

...

raji_toor by L4 Transporter
  • 2373 Views
  • 2 replies
  • 0 Likes

User-id issue.

Hi All,

 

Firewall is 3050 with pan-os version 9.0.9-h1 we are using user-id agent as well as agentless for user-mapping.

Sometimes we are getting machine names instead for ip-address instead of source usernames.we have user-based security policy. Why d

...

Trouble with NAT and VPN

Hi there,

i want to finish an easy setup which needs a simple DNAT and forwarding into a VPN tunnel on my PA5020.

I've created a working VPN tunnel which is the destination for my traffic. And this works fine if i'm using the tunnel ip to reach targets

...

  • 24186 Posts
  • 100 Subscriptions
Top Liked Authors
Labels