General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Meraki behind PA - Unfriedly NAT

Hello community, another person with the problem. I know, I know. Finding a solution to this problem is obviously not easy. I have a problem with a Meraki cluster behind a PA cluster.The problem is the familiar “Unfriendly NAT”.I just can't figure out how to configure the PA so that it works. Countless articles on the internet don't help eit...

Resolved! Internet Bandwidth comsumed, who?

Hello Team, Firstly, thank you all for your cooperation. I have an issue that is I have my internet connection fully utilized most of the time. is there a way or work arround to find out which host IP is utilizing the bandwidth, knowing that I am not running the SD-Wan. software version 11.1.2-h3 TIA,

End users selects DENY on the MFA prompt on the phone still are able to connect to GlobalProtect agents

I need some advices on this GP VPN Client with MFA issue: End users selects DENY on the MFA prompt on the phone still are able to connect to GlobalProtect agents The current auth environment is that users use Active Directory in Azure for MFA and use Radius to authentication process in Globalprotect.

Resolved! SSL Decryption: Forward Trust unavailable

Hello, After creating a external CA cert, the Forward Trust Certificate, Forward Untrust Certificate and Trusted Root CA are greyed out. So I can't select. All options are available when a create a self-sign certificate. Any idea? Thanks

KTarver by L1 Bithead
  • 5537 Views
  • 7 replies
  • 0 Likes

Automatic Deploy of Firewalls into Panorama trough api or sdk

Im trying to automate the deploy of a firewall into panorama using the python sdk (pan-os-python)It seems I can add devices to panorama by the serial number, but i cannot make them connect cause it need the auth key to be set when adding the firewall to panorama, the SDK does not provide that option, and I cant find a way to do it on the API as ...

HIP check report interval

1. What is the interval for HIP reports that the GP client sends to the gateway? 2. Is it configurable?3. What triggers HIP report sending?

ET by L3 Networker
  • 25186 Views
  • 6 replies
  • 0 Likes

Resolved! Intermittent UserID - Syslog Parser -

Anyone see this behavior? we are using syslog parser string for userid, no logout action, timeout set to 45 minutes ( default). You can see here that a flow within the same second shows a userid and then blank with same source address. FW running 10.2.7 h-8 . Any ideas?

NSutfin_0-1723726668467.png
NSutfin by L2 Linker
  • 1905 Views
  • 2 replies
  • 0 Likes

Native VPN not connecting after integrated with SAML Identify provider.

( description contains 'failed authentication for user \'xxxxxxx\'. Reason: Internal error, e.g. network connection, DNS failure or remote server down. auth profile \'AZURE-MFA\', vsys \'vsys1\', From: xxxxx.' ) The above error is getting after introducing the SAML in mobile same we tested from the Laptop and it working without any issues. For t...

CyberEye by L3 Networker
  • 11161 Views
  • 9 replies
  • 0 Likes

Resolved! How to get all EDL entries with XML api?

Hi gurus, I am using /api/?type=op&cmd=<request><system><external-list><show><type><ip><name></name></ip></type></show></external-list></system></request> to get EDL entriies, but the api only returns first 100 of total 205 entries. <response cmd="status...

jyao by L1 Bithead
  • 13806 Views
  • 3 replies
  • 0 Likes

Resolved! SSH Service Profile

Question regarding SSH Service Profiles. If you create a SSH Service Profile in Panorama for a template that is associated with firewalls running 10.x and 9.x, will it fail when you commit the changes for the 9.x firewalls? I'm in the process of upgrading all firewalls to 10.1, so in the meantime I've been creating the profiles locally, but w...

  • 24443 Posts
  • 125 Subscriptions
Top Solution Authors
Labels