General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4235 Views
  • 0 replies
  • 0 Likes

Ethernet logs on palo alto

My internet link is terminated on ethernet 1/3 of palo alto firewall, how can i can find ethernet logs on firewall to troubleshoot circuit issue and report it to service provider?

Resolved! Looking for PANOS 8.0 spec sheet

Hi, With the new hardware platform (PA220, 800 series and 5200 series) and new PAN OS 8.0 released. I am looking for a comprehensive cheat sheet that has all the limitation on all the PAN firewalls running on 7.1 and 8.0, ie, # of ARP# of ipv6 neighbor table# of vlan supported # of IPv4 routes# of IPv6 routes# of RIP # of OSPF Peers# of BGP ...

DIPP A/A Enviroment Floating IP

Hi Guys, we´ve an Active/active Cluster enviroment. For the normal Internetconnection we will use Source/Hide NAT (DIPP).At the moment we will NAT on both firewalls the traffic through the interface IP. This works fine, the failover isok only one paket lost during failover. The proble is, that in the case of an failover the Users will access the...

mschwab by L1 Bithead
  • 2949 Views
  • 3 replies
  • 0 Likes

topology

Hi, I have the below topology .Planning to put PA in vwire mode in betweent the asa and core in active standby.If r1 fails and asa1 is active and asa2 is standby ,asa2 will become active .. Lets say pa1 is active and pa2 is standby .When asa changes active standby order ,is it possible pa changes the same order as asa do . Or what is the pros ...

PA.png
sib2017 by L4 Transporter
  • 5461 Views
  • 8 replies
  • 0 Likes

Opened session remains after threat triggered block-ip. WTF!

Hi, I've been testing the block-ip action in spyware DNS signatures. I was an RDP session before the threat triggered the block-ip action. Then, no more connections are allowed (what is OK), but the RDP session remains open. Is this a normal behaviour? I think the FW should reset all the sessions previosly established for the blocked IP, shouldn...

ACortes by L2 Linker
  • 2783 Views
  • 1 replies
  • 0 Likes

http proxy -session end reason decoder.

All traffic via firewall works fine except http-proxy. PC makes connectio with http-proxy but the proxy session keeps on dropping. session end reason decoder. Is that normal for http-proxy app.

Resolved! Console conection using CISCO terminal server

Hi First of all i would like to say that im able to conect with serial cable to the Console Port with my laptop. The issue only occurs when i try to conect to the Console port via Cisco Terminal controller (TTY)At the begining i thought was a problem with the values that Palo Alto recomend for this kind of conection (see below) Bits per sec :...

Confused over EBL size limit

We have a 3020 running 7.0.8 and are experimenting with MineMeld. As soon as we get close to 5k IPs on the combined EBLs we get an error on a EBL refresh that it's been truncated as it's over the limit. Palo Alto's own KB suggests that on an entry level PA-200 there is a limit of 50k items on all EBLs combined. https://live.paloaltonetwork...

Resolved! Migrating old FW Config to new device

I have 2 PA-500's and have been planning to purchase a new device. Perect timing with the new PA-800's, fits my needs and then some. Is it possible to migrate my current configurations from the 500 to the 850? Network-ethernet-Radius-Users wtc as well as the policies and rules.

Resolved! Is the Intel Atom c2000 platform in any Palo Alto Products?

There is an advisory released by Intel (and probably Cisco) about the Intel Atom c2000 platform and a clock signal component failure that can brick devices using that platform. The Atom c2000 was marketed towards (among other uses) networking equipment. Does anyone know if Palo Alto used the Intel Atom c2000 platform in any of our devices? Than...

bshelton by L0 Member
  • 4031 Views
  • 2 replies
  • 0 Likes

License Transfer

Hello, I am not sure if this is the right place to seek this type assistance. Is it possible to transfer subscriptions from PAN-3050 to VM-300 or VM-500? The client has a pair of PAN-3050 with TP, URL4 and Wildfire subscriptions which will be expired on April 30, 2017. They want to move to VM model as soon as possible. Thanks, Michael

MiZhang by L0 Member
  • 3066 Views
  • 2 replies
  • 0 Likes

Resolved! Skype is not working with allow rule

Hi, We have a demand to allow skype for internal employees. However, we've created a security rule to allow the following applications: -skype-skype-probe-ssl/web-browsing Still skype couldn't connect with an error message "please check your internet connection and try again". So I've added *.skype.com/* in the URL filteration > still doesn't...

  • 24358 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels