General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4116 Views
  • 0 replies
  • 0 Likes

Resolved! Migrating old FW Config to new device

I have 2 PA-500's and have been planning to purchase a new device. Perect timing with the new PA-800's, fits my needs and then some. Is it possible to migrate my current configurations from the 500 to the 850? Network-ethernet-Radius-Users wtc as well as the policies and rules.

Resolved! Is the Intel Atom c2000 platform in any Palo Alto Products?

There is an advisory released by Intel (and probably Cisco) about the Intel Atom c2000 platform and a clock signal component failure that can brick devices using that platform. The Atom c2000 was marketed towards (among other uses) networking equipment. Does anyone know if Palo Alto used the Intel Atom c2000 platform in any of our devices? Than...

bshelton by L0 Member
  • 3977 Views
  • 2 replies
  • 0 Likes

License Transfer

Hello, I am not sure if this is the right place to seek this type assistance. Is it possible to transfer subscriptions from PAN-3050 to VM-300 or VM-500? The client has a pair of PAN-3050 with TP, URL4 and Wildfire subscriptions which will be expired on April 30, 2017. They want to move to VM model as soon as possible. Thanks, Michael

MiZhang by L0 Member
  • 3032 Views
  • 2 replies
  • 0 Likes

Resolved! Skype is not working with allow rule

Hi, We have a demand to allow skype for internal employees. However, we've created a security rule to allow the following applications: -skype-skype-probe-ssl/web-browsing Still skype couldn't connect with an error message "please check your internet connection and try again". So I've added *.skype.com/* in the URL filteration > still doesn't...

URL Reclassifications to Unknown in 20170207.20264

Hello, I was just wanting to see if anyone else has noticed that in URL DB 20170207.20264 many sites are being reclassified to Unknown? sites include www.maxtend.com.au fairfaxstatic.com.au (used for Australian Financial Review website)cdn.newsapi.com.au (where news.com.au keeps its image resources) We block uknowns by default so we have had man...

PhilH by L2 Linker
  • 4059 Views
  • 5 replies
  • 0 Likes

Natting issue with new subnet.

I am applying destination nat. Natting public ip(untrust zone) to internal ip(trust zone). Public ip subnet is /28.When access public ip in the monitoring logs it shows me dst zone as Untrust whenit should show dst zone as Trust.I have policy in place and natting but its not hitting any policy and goes to expicit deny.

Cisco AnyConnect over IKEv2 killed by PAN-OS 8.0

Hi. I've been running PAN-OS 8.0 since release, and immediately got problems with Cisco AnyConnect over IKEv2. Even if the session is very much alive, PAN-OS 8.0 kills it of after a random amount of time, usually a couple of hours. If I change the AnyConnect policy to use SSL instead, everything runs fine. PAN-OS 8.0 recognizes AnyConnect over I...

GI-1 by L1 Bithead
  • 3520 Views
  • 5 replies
  • 0 Likes

Light blue vs dark blue IP's

I have noticed that in the policies that some IP addresses show a dark blue and underline all the time and then there ar IP's that are a lighter blue and the underline only appears when I have my cursor over the IP. anyone else seeing this and is it significant?

jdprovine by L4 Transporter
  • 6258 Views
  • 12 replies
  • 0 Likes

Multicast questions

Hi, I am not famliar with Multicast at all, please forgive my ignorance. I need to replace Fortigate firewalls with Palo Alto devices and the Fortigates are currently running Multicast. There are no "groups" defined on the fortigate, and if I run "get router info multicast pim sparse-mode table" on the fortigate I can see many groups listed. Can...

Resolved! Panorama CLI adding address objects to a specific firewall

We use Panorama for all of our firewall changes. We have 22 sets of HA firewalls. I am trying to load a long list of IP addresses into only one firewall (so these are not "shared" addresses). I know how to add them to the templates but I wan to add them to the level below that, the actual firewall. Any help would be appreciated!! Mike

Resolved! SSL Decryption issue (wrong certificate)

Hi All, Having SSL Decryption issue with one of the websites at the moment (https://wiki.freeradius.org/Home)So testing without decryption and checking certs chain: Can see root CA on Palo: So all looks good. Implementing SSL Decryption (test version only) with two certs generated on PA one for forward trust another is for forward untrust: Do...

PA1.PNG
PA2.PNG
CERTS.PNG
BBC.PNG

Resolved! Feed / data control

Use Case: Ofice 365 Access Control What happens if MineMeld deletes all the IPs from a feed, and the firewall sees there are no more IP’s from that feed. Will the traffic be blocked? What happens on the firewall if there is no data from a feed where there was data from the last time it pulled? Will it delete the local cached copy of the data a...

  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels