General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Discussions

Resolved! Howto delete sub-interace from cli

Hi,

I`m trying to delete a sub-interface from CLI but cant seem to find the correct command, i managed to remove the IP address and tag but not the entire sub-interface.

admin@PA-200# delete network interface ethernet ethernet1/4 layer3 units ethernet1

...

u18830 by Not applicable
  • 14800 Views
  • 16 replies
  • 0 Likes

Destination NAT Mismatch error

Hi I'm configuring a new PA-500 and have it working for source NAT going from Tusted to Internet. Now I want to create a destination NAT rule to allow traffic in to a web server located on the trusted net. I have created a rule almost exactly as it s

...

Resolved! QoS on Tagged VLAN Sub-interface

Hi there,

I try to implement QoS on Tagged VLAN sub-interface. Found some configuration on main interface but not sub-interface one.

Any suggestion? ^^

Thank you    

Amnuay by Not applicable
  • 8424 Views
  • 6 replies
  • 1 Likes

Defining patch management in HIP objects.

Hi All,

We are configuring global protect with HIP enabled.

Our requirement is, If the patch defined in the HIP object is missing in client machine then access should be denied. Below screen shows the patches (windows updates) for windows 7 machine.

Fro

...

Gururaj by L4 Transporter
  • 7025 Views
  • 11 replies
  • 0 Likes

Exclude www.google.* from decryption

Hello,

are you able to exculde https://www.google.com ; https://www.google.de and other domains from SSL decryption?

Or clients complain about the slow loading of the website when they open Google or try to search something.

Currently i add in a white c

...

Hithead by L4 Transporter
  • 7155 Views
  • 17 replies
  • 0 Likes

SysLog setup not working

Hi,

I am using PA-2050, with PAN OS 4.1.3.

From few days I am trying to configure the syslog to be sent to a central logging system. I followed every possible documentation, but I am not getting any syslogs coming to the syslog server.  I tried on sys

...

Resolved! BGP Graceful restart in an Active/Passive cluster?

All,

Quick query, we are in the process of implementing a HA cluster that will be BGP peering with several upstream routers, both route import and export, and in trying to reduce the interruption due to a failover we are looking to implement the Grac

...

Resolved! USER ID MAX USERS IN A GROUP???

Hello,

I've configured on PA5060 an Idenfication with AD:

PA5060: 4.1.6    USER ID AGENT : 4.1.4-3

LDAP SERVER 389

I do a group mapping  by group but this group have more than 16000 users.

when I do a show user usersIDS , I can't see all my users. I know

...

alle by L3 Networker
  • 13913 Views
  • 10 replies
  • 0 Likes

Exporting URL Filter objects/groups

Is there a way (CLI or WebUI) to export the URL Filtering objects and their details?  We are looking to export the objects and their block/allow categories so we can put them in front of management.

sconley by Not applicable
  • 6441 Views
  • 3 replies
  • 0 Likes

allowing MS product activation and denying web access

I have a network that I want to allow MS product activation to work but web browsing and other internet activity to be denied.

I have two main security policies that apply just to this network although DNS and ntp is also allowed:

The first one is an a

...

kjh by Not applicable
  • 8858 Views
  • 3 replies
  • 0 Likes

Secondary IP and DHCP

Greetings,

Say we have an interface that is configred the following way:

e1/2.240

Tag: 240

IPv4 Address (two addresses on the interface):

-10.10.100.1/24

-192.168.100.1/24

Now, if that interface is configured as a DHCP relay, which network is it going to se

...

mrsold by Not applicable
  • 8633 Views
  • 9 replies
  • 0 Likes

nslookup on the management port ?

I would like to check a few DNS issues I'm seeing on the management port.

I had hoped to find nslookup in the CLI, but it isn't there.

Is there something equivalent ?

Thanks.

DSTR by L0 Member
  • 26866 Views
  • 4 replies
  • 1 Likes

Authentication Fallback

Hello,

So, we currently authenticate administrators to our PA's via Radius (TACACS).  Is there a way to configure the PA's that it will only use the local DB / Administrators if Radius isn't available? 

Thanks!

mrsold by Not applicable
  • 8705 Views
  • 10 replies
  • 0 Likes
Labels