General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Discussions

Resolved! QoS on Tagged VLAN Sub-interface

Hi there,

I try to implement QoS on Tagged VLAN sub-interface. Found some configuration on main interface but not sub-interface one.

Any suggestion? ^^

Thank you    

Amnuay by Not applicable
  • 8626 Views
  • 6 replies
  • 1 Likes

Resolved! BGP Graceful restart in an Active/Passive cluster?

All,

Quick query, we are in the process of implementing a HA cluster that will be BGP peering with several upstream routers, both route import and export, and in trying to reduce the interruption due to a failover we are looking to implement the Grac

...

PBF with NAT, how does it works?

Hi Guys

According to document , if there's destination NAT , there'll be second routing lookup to decide outbound zone & interface. But I'm very confused when there's routing and PBF together, In the second routing lookup, how does PBF rule work? Does

...

JTR by Not applicable
  • 9359 Views
  • 4 replies
  • 0 Likes

Secondary IP and DHCP

Greetings,

Say we have an interface that is configred the following way:

e1/2.240

Tag: 240

IPv4 Address (two addresses on the interface):

-10.10.100.1/24

-192.168.100.1/24

Now, if that interface is configured as a DHCP relay, which network is it going to se

...

mrsold by Not applicable
  • 8814 Views
  • 9 replies
  • 0 Likes

nslookup on the management port ?

I would like to check a few DNS issues I'm seeing on the management port.

I had hoped to find nslookup in the CLI, but it isn't there.

Is there something equivalent ?

Thanks.

DSTR by L0 Member
  • 27842 Views
  • 4 replies
  • 1 Likes

Shutting down/disabling subinterfaces

I am very new to the PANOS world so I will apologize in advance if this is obvious, however my search of documentation and knowledebase did not yield anything. I have been looking for a way to administratively shut down sub interfaces. Is this possib

...

scourge by Not applicable
  • 16185 Views
  • 11 replies
  • 0 Likes

Resolved! HOW TO CONFIGURE .1q - VLAN TRUNK

     Hi guys ,


I have a lots of doubts about how to configure .1q vlan TAG / TRUNK on PALO ALTO FIREWALL.

It`s possible to work with layer 3 interface ?
I don`t found any documents here.


Does anyone have something to help me.

Nbest Regards


THiago LIma.

Thiago by L3 Networker
  • 2793 Views
  • 2 replies
  • 0 Likes

Avaya 9611G/4610SW VPN to PA-500

Has anyone had success connecting Avaya IP phones via VPN to PA devices?  I am able to complete IKE Phase 1 authentication, but fail Phase 2 due to local/remote proxy IDs not found:

'IKE phase-2 negotiation failed when processing proxy ID. cannot fin

...

itmanager by L1 Bithead
  • 21194 Views
  • 22 replies
  • 0 Likes

Resolved! IPSEC Tunnel to ASA - PeerID issues

I am setting up an IPSec tunnel to an ASA. I am getting an error message about the PEERID type only allowing IP but received FQDN. Per the other KB article, I changed the PAN Exchange mode to Aggressive.

Now the PAN received a FQDN of the ASA side an

...

SDorsey by L4 Transporter
  • 5600 Views
  • 5 replies
  • 1 Likes

GlobalProtect client behind a proxy, configuration help

I am trying to establish an ssl vpn connection using the globalprotect client, but the client is behind a proxy using a configuration script.  I have tried calling paloalto support but they said their client is not proxy aware.  Does anyone know of s

...

bigtone by L1 Bithead
  • 15870 Views
  • 6 replies
  • 0 Likes

Palo Alto BGP: Conditional Advertising

Dear All,

Recently we have been migrating to a non-trivial BGP setup, and I have had to experiment with the conditional advertising BGP feature in Palo Alto. I was familiar with this concept from cisco, but alas I still found the documentation availab

...

Resolved! Aggregate Ethernet Interface with Subinterfaces

Hi there,

I'd like to set up a PA-5060 with an aggregate Layer 3 ethernet interface with no address:

Aggregate Interface

Name: ae1

Type: Layer 3

Address: (none)

Virtual Router: (none)

Tag: (none)

Security Zone: (none)

and then add subinterfaces to it, each of

...

Labels