General Topics
Showing results for 
Search instead for 
Did you mean: 

The Enhanced LIVEcommunity Experience is finally here! Learn all about it.

Forum Posts

Registration now open - Interactive Event!

Hi everyone, If you haven’t already seen, registration is now open for our first interactive event all about the Best Practice Assessment (BPA) tool! You will be able to connect with subject matter experts, share best practices, and learn how this to...

jdelio by Community Team Member
  • 0 replies

Resolved! GlobalProtect, Working from Home, Prisma Access and Covid-19

To all, Just wanted to post a message about the Hot Topic right now, which is Covid-19. With all of this going around, everybody's health and safely is the utmost concern. Keeping your hands clean, washing your hands (A LOT), using hand sanitizers, a...

jdelio by Community Team Member
  • 45 replies

ISP failover in PanOS 7.0.4

Hi, We are moving from Juniper ScreenOS SSG firewalls to PanOS 7.0.4, 3020 clustered firewalls. On our Junipers we make use of a feature called track-ip for Interface failover between ISP's...This basically works by pinging a far device on the primar...

Exclude Traffic from the VPN Tunnel with scripts (GP 2.3)

Dear community, have you ever tried to exclude IPs from the VPN tunnel using the GP 2.3 feature:

Hithead by L4 Transporter
  • 0 replies

Does Palo Alto support Reverse Route injection?

As title, does Palo Alto support something like CISCO "Reverse Route injection" which can inject a /32 route to the campus network for a dial-in user? Or can I create a /24 loopback interface for VPN users and redistribute the /24 to campus network? ...

Policy Based Forwading Capability Question

Hello All, Was just wondering if anyone may be able to help with this our question. Please see the attached High Level Diagram. Both Firewalls are PA 3020's with the full licence set enabled. We need to replace the ISA server which is not providing a...

Data Flows.jpg
WesNeary by L1 Bithead
  • 5 replies

Shared gateway and BGP setup problem ?

Hello all, This is the first time I post to the community. Before posting this message I've read a lot of information and I only can thanks everyone for all the interesting information found here. We have some difficulties to set up a "working" share...

palaaltoproblem-base.png palaaltoproblem-webexample.png
FTBZ by L1 Bithead
  • 2 replies

BGP Peering Issue

I have a PA connected to my upstream provider exactly how it is with the same provider at two other locations, but I cannot for the life of me get BGP to establish. I've got a case open, but they're being hilarious slow and only responding with canne...

DirectPath I/O

I currently have a marathon support case open and support's latest reply includes an internal-only link (I'm pretty sure), so I can't read it. :( The release notes for 7.0 specify: "High Availability (HA) Link Monitoring is only supported on VMware E...

6.1+ update stops tagged interfaces from working

I tried updating a PA3050 HA active/passive setup from 6.0.10 to 6.1 to eventually go to 7.The update works for both devices, everything seems to be working like it should, except for the tagged subinterfaces of the aggregated interfaces. They simply...