General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Integrating MineMeld with IBM QRadar

Hi, I am new to minemeld. I went through the documentation for integrating minemeld with qradar. Succesfully added the TAXII feeds in Qradar. I couldnt see any values getting populated in reference set defined in Qradar or updates shown in threat intellegence TAXII configuration section in qradar. Regards Thanzeer

Terminal Server Agent Installation on Windows Server 2016 (with secure Boot enabled)

Hi, Does anyone managed to install the terminal server agent version 8.0.0 on a windows server 2016 with secure boot enabled?Unfortunately I only get a message (after the installation) when the service is about to get startet that a digitally signed driver is required. Anyone else having this problem or maybe already a solution? Regards,Remo

Remo by L7 Applicator
  • 3347 Views
  • 2 replies
  • 2 Likes

Resolved! Configuring the Proxy-ID for phase 2 IPSec using PAN 6 CLI

there's this great example below for setting up an IPSec tunnel using the CLI. BUT it's missing how to add in the proxy IDs. I have some clues that it's like.. set network tunnel ipsec IPSEC-Tuna-TUNNEL proxy-id tuna1 protocol any Local xxxx Remote yyyy ..but I'm just guessing. Can anyone supply me with the real mojo - perhaps from a cleaned wor...

palomed by L3 Networker
  • 13485 Views
  • 3 replies
  • 0 Likes

Application Incomplete For One Site But OK at Another

I have an IPSec tunnel with source address NATting to a partner. 443 web traffic from site A triggers the IKE and the IPSEC-SA session. In PAN monitoring the application is correctly identified as SSL and in my browser I pull up the site from the partner without an issue. 443 web traffic from site B triggers IKE and IPSEC-SA so that tunnel is o...

palomed by L3 Networker
  • 8884 Views
  • 9 replies
  • 0 Likes

VPN Access

How do you configure the globalprotect VPN's so they won't route on the internal network but will only let users access it from outside the internal network

jdprovine by L4 Transporter
  • 3309 Views
  • 5 replies
  • 0 Likes

Upgrading 7.1.5 HA Pair

My HA 3050 pair is currently running 7.1.5 and I am planning an upgrade spree. The upgrade process that I read seems straight-forward. My main concerns are with IPSEC tunnels and GP clients. My options right now are upgrading to 7.1.9 or just going to 8.1. Has anyone run into any issues with tunnels and/or clients no longer being able to connect...

HA PANs

Hello, I am trying to design a new solution in our network infrastructure. Here's are the requirements: - Single ISP -- Two active Internet circutis --- (Corrected from Two ISPs to a single ISP)- Current topology: Two Internet circutis connected to two cisco edge routers in active/active mode, both circuts are used.- Two core switches: Two co...

Resolved! PAN-200 upgrade to 7.0

For some reason, I had to RMA my PAN-200 which is used to demonstrate PAN-OS features. My previous box was 7.0.3 but before the upgrade between 7.0.2 to 7.0.3, I noticed that 7.0.0 was no longer available in the Software list in the Device tab. The new box arrived with a version 5 which I upgraded to version 6.0.0 which unlocked 6.1 and then I...

CharlesP by L0 Member
  • 4514 Views
  • 5 replies
  • 0 Likes

PAN-DB URL Filtering activation problem

Hi All! i am trying to activate URL Filtering from PAN-DB, but i have problems.I upload the license manually and i haven't error, but when i try to download the database this error appear:"URL database download: not available."Then i do the "Retrieve license keys from license server", but this error appear:"Failed to fetch licenses. Failed to ge...

DKanta by L2 Linker
  • 7265 Views
  • 9 replies
  • 0 Likes

A/A Cluster Routing problem

Hi, I´ve a A/A Cluster Setup, where the firewall 0 is primary and the most traffic goes that way.We use OSPF for the routing over the VPN tunnel and some tunnel are configured with a better metric overthe secondary firewall. We want to make some loadsharing over two different internetconnections.When I take a look in the routing table of firewal...

mschwab by L1 Bithead
  • 4227 Views
  • 6 replies
  • 0 Likes

Log Field

where have the document that explain the each log field in traffic log and threat log?

WildFire - how to configure the frequency of file submission to Wildfire cloud for analysis?

Hello Everyone, I did not manage to get this information in other online resources and in Wildfire -> General Settings does not seem to have this option. Hence I am asking for your help on these questions: How can I configure the "frequency" of my PaloAlto as to when it will send sample files to WildFire cloud for analysis? (e.g. time interva...

Setting up Policy Based Forwarding with two ISPs and 1 VPN tunnel

I've already read the articles in the live community for starters. Never setup a branch office before. This new branch office has 2 isp's and 1 VPN tunnel from there to HQ. I have the firewall completely configured already for using 1 ISP and the 1 VPN tunnel. Cannot follow the articles that exist on this subject. There are too many assumptions ...

bvadmin by L0 Member
  • 1962 Views
  • 1 replies
  • 0 Likes
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels