General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 310 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3654 Views
  • 2 replies
  • 14 Likes

Client VPN traffic and routing over IPsec Tunnel

Hi there,

Here is our scenario that I am trying to figure out.

We have two sites (main office and a rack in a data center) that are connected via PAN-2020's on both sides through a IPsec Tunnel. I am trying to route Client VPN traffic that connects at

...

cmateam by L3 Networker
  • 6696 Views
  • 5 replies
  • 0 Likes

PA-200 Multiple WANs

Hi,

I'm getting my second WAN line installed this week and need to integrate it into my current setup on my PA-200.

Ideally, I'd like the PA-200 to load balance between the two WAN interfaces so my initial thought is to add the new WAN interface into t

...

Resolved! pa200 ha

Im in the process of setting up a pair of pa200 for ha, ive read through the documentation but im not clear on a few things.

The PA200, if i do an update on the FW for either software of dynamic updates it uses the management port to do the work.

If I

...

NAT Help - Reaching DMZ Server via NAT

Hi,

I'm having an issue setting up my DMZ test environment.  My set up is basic and is as follows (IP information is an example) --

  • e1/1 - Internet (1.1.1.160/28 - ISP assigned)
  • e1/2 - Internal (10.10.10.0/24)
  • e1/3 - DMZ (10.10.100.0/24)
  • DMZ Web Server (I
...

jmeyer1 by Not applicable
  • 3253 Views
  • 5 replies
  • 0 Likes

L2 trunk and subinterfaces to Cisco

I am trying to configure a L2 trunk from a Cisco 3750 to a Palo 5020

I cannot find any info on how to configure the Palo, as the terminology is different to me.

As a side note we are also running two 5020's in an Active/Active configuration

I have tried

...

rperkin by Not applicable
  • 8913 Views
  • 7 replies
  • 0 Likes

one trust two untrust

If I have two DSL connections, and 10 network segments, is possible configure on a PAN firewall one "trust" zone, tow "untrust" zone and send five segments for each one?

Resolved! PaloAlto firewall platform upgrade?

Hi,

I'm a customer with two PaloAlto firewalls PA-2020 with active / passive config. We have a 100 Mbps simetrical Internet speed bandwith connected

to the PaloAlto firewalls and all is working fine.

Our ISP provider  is going to upgrade our Internet sp

...

Resolved! Audio Issues with Asterisk via PA-2050

I am currently attempting to cut over our office's internal gateway from a BSD firewall to our PA-2050 (running PAN-OS 4.1.9).  When attempting the cutover, I can get all services to work properly with the exception of our two VoIP servers (running T

...

Isosat by L2 Linker
  • 10053 Views
  • 20 replies
  • 2 Likes

Resolved! Captive Portal -- LDAP Authentication Question

Thank you for your time. I have a lab setup with a PA-500 and a Windows 2008 server with Active Directory. I have a single user in the trust zone on the Palo and I am trying to get Captive portal working for User-ID mappings of unknown users. I have

...

IPSEC Pass Through

Forgive the newbie question, but I've been searching the documentation and I don't see where I can configure the Paloalto FW for vpn passthrough, specifically ESP (Protocol 50) and even ICMP.  I have some routers that I need to provide NAT for their

...

jpvh1234 by L0 Member
  • 5830 Views
  • 4 replies
  • 0 Likes

Problem with new internet connection

I've just changed my internet connection to a new one.

Now I've reconfigured everything with the new address.

The issue is that I can surf the web from inside to outside but the NAT to my internal server is someway blocked.

What I can see in logs is:

I r

...

LDAP and GlobalProtect

Hi,

I am trying to set up Globalprotect.

Would like to restrict the user to a group, but I can not get this to work.

In Authentication profile i have the VPN-group in allow list.

When I logon with a user in this group the log tell me that i have incorrec

...

klumpen by L1 Bithead
  • 3345 Views
  • 3 replies
  • 0 Likes

BGP config PAN-OS 5

Hello,

I was working on a BGP configuration on a PA 500 running PAN-OS 5. It is an internet connection plugged directly into the firewall. (Its an ethernet hand-off). I couldn't find any docs for v5 so I just hacked my way through it. Is there any ste

...

DougB by L0 Member
  • 1572 Views
  • 1 replies
  • 0 Likes
Labels