General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1985 Views
  • 0 replies
  • 0 Likes

Resolved! Site-to-Site IPSEC issue and MTU

Greetings all!

 

I've run into an interesting issue and I'm hoping someone here may have some previous experiences or maybe something on best practices I'm missing.

 

Basically, we have a site-to-site loopback interface set up and we have several tunnels

...

jsalmans by L4 Transporter
  • 27617 Views
  • 7 replies
  • 0 Likes

Virtual Wire & Virtual System assignment issue

Hi,
I hope this message finds you all well 

I have some configurations questions regarding virtual wire in PAN-OS FW that support multiple virtual systems, i would like to get some official documents regarding virtual wire configuration and assign it

...

T.Zidane by L0 Member
  • 801 Views
  • 0 replies
  • 1 Likes

add TWISTLOCK_CONSOLE env variable to twistcli

i am not sure if this is the right place to suggest this, but i think it will be really handy to have such an env variable i can set up in my zsh profile file (for example), and not having to write `--address $TWISTLOCK_CONSOLE` every time. similarly

...

NGal by L0 Member
  • 821 Views
  • 1 replies
  • 0 Likes

RabbitMQ App-ID Misidentified

We have a Security Policy Rule with Application rabbitmq, and Service is application-default. In the same Security Policy Rule, we allowed the dependant applications amqp and SSL. When we test traffic, in the Traffic log, we see it matching the zones

...

DNS Rewrite and NAT Traffic and without NAT Traffic

Hi,

 

We have scenario in which two different subnets in DMZ Zone communicating with Internal Zone but 

  1. One subnet is allowed to communicate with Internal Subnets (Internal Zone) without NAT (Source or Destination).
  2. 2nd subnet is allowed to communicat
...

A.jauhar by L0 Member
  • 981 Views
  • 0 replies
  • 0 Likes

Resolved! Wildcard URL for Non-HTTP/HTTPS traffic

 

Hi, this question may have been answered before, but I can’t find it anywhere on the LIVEcommunity. We need to allow traffic for the mssql-db app for a specific wildcard URL (*.example.com). It needs to be a wildcard because the alternative is to a

...

R8787H by L0 Member
  • 2636 Views
  • 2 replies
  • 0 Likes

GlobalProtect Client Certificate not Found

Hi All,

 

I am trying to demo pre-logon and am really struggling with the client certificate authentication side of things.

 

I've generated a Root CA on the firewall which has been imported into the Personal and Trusted Root Stores of the machine.

The po

...

Global Protect switching from Pre Logon to User

Hello,

 

We have an issue where many times Global Protect clients are not switching from the Pre Logon user to their logged in user name.  Certs are deployed and Pre-logon access works.  IT can remote on to troubleshoot a PC that is just at the windo

...

ksauer507 by L3 Networker
  • 5397 Views
  • 3 replies
  • 0 Likes

Upgrade from 9.1.x, to 10.1.x, 10.2.x, 11.x

Upgrade to from 9.1.X, to 11, 10.2.X, 10.1.X ?

 

Hello, good afternoon, how are you? I have a question regarding which is the recommended version to update from PAN-OS 9.1.X.

Personally I consider that version 10.1.X ( 10.1.8-h2 ) is the recommended

...

Metgatz by L4 Transporter
  • 18165 Views
  • 5 replies
  • 0 Likes

How to remediate overly permissive any- any rule

  • We have an overly permissive rule with Source, destination and ports as Any. We are working to remove this rule but this  is widely used. Please suggest what's the best way to identify the traffic using this rule and to create rules with specific sou
...

  • 24213 Posts
  • 117 Subscriptions
Top Liked Authors
Labels