General Topics
Showing results for 
Search instead for 
Did you mean: 


Join Us for a Tech Deep Dive Miniseries!


Stop Zero-Day Threats in Zero Time with Nebula PAN-OS 10.2.


Join us live for an in-depth look at the latest advancements in cybersecurity, best practices, tips and tricks, demos and
more to protect your business and defend against threats in real


jforsythe by Community Team Member
  • 3 replies

ISP failover in PanOS 7.0.4



We are moving from Juniper ScreenOS SSG firewalls to PanOS 7.0.4, 3020 clustered firewalls. 


On our Junipers we make use of a feature called track-ip for Interface failover between ISP's...This basically works by pinging a far device on the


Policy Based Forwading Capability Question

Hello All, Was just wondering if anyone may be able to help with this our question.


Please see the attached High Level Diagram. Both Firewalls are PA 3020's with the full licence set enabled. We need to replace the ISA server which is not providing


Data Flows.jpg
WesNeary by L1 Bithead
  • 5 replies

Does Palo Alto support Reverse Route injection?

As title, does Palo Alto support something like CISCO "Reverse Route injection" which can inject a /32 route to the campus network for a dial-in user? Or can I create a /24 loopback interface for VPN users and redistribute the /24 to campus network?


Exclude Traffic from the VPN Tunnel with scripts (GP 2.3)

Dear community,


have you ever tried to exclude IPs from the VPN tunnel using the GP 2.3 feature:


Hithead by L4 Transporter
  • 0 replies

Shared gateway and BGP setup problem ?


Hello all,


This is the first time I post to the community. Before posting this message I've read a lot of information and I only can thanks everyone for all the interesting information found here.


We have some difficulties to set up a "working" shar


FTBZ by L1 Bithead
  • 2 replies

DirectPath I/O

I currently have a marathon support case open and support's latest reply includes an internal-only link (I'm pretty sure), so I can't read it. 


The release notes for 7.0 specify: 


"High Availability (HA) Link Monitoring is only supported on VMware E


BGP Peering Issue

I have a PA connected to my upstream provider exactly how it is with the same provider at two other locations, but I cannot for the life of me get BGP to establish. I've got a case open, but they're being hilarious slow and only responding with canne


6.1+ update stops tagged interfaces from working

I tried updating a PA3050 HA active/passive setup from 6.0.10 to 6.1 to eventually go to 7.
The update works for both devices, everything seems to be working like it should, except for the tagged subinterfaces of the aggregated interfaces. They simply