General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Nest a External Dynamic List (type=URL) in a Custom URL Category

Is it possible to nest a External Dynamic List (type=URL) in a Custom URL Category or to nest Custom Categories?Example:Custom URL Category = "Allow List"External Dynamic List (type=URL) = "Immediate Allow List" on external server (http://10.11.30.4/url/immediate.txt)Example Result:Allow List (Custom URL Category)anydomain.com*.anydomain.comNext...

Resolved! Security Policy for IPSec traffic

Hello, We are setting up Site-to-Site IPSec VPN between PA and Cisco router. The examples provided on PA websites do not suggest any security policy for this. When we use a security policy for 'Outside-Untrust' to 'Outside-Untrust' to allow traffic between IPsec tunnel end points, we can see traffic matching this policy. Do we need an intrazone ...

Farzana by L4 Transporter
  • 2960 Views
  • 1 replies
  • 0 Likes

scan-host sweep

Hi,Under threat detection, scan host sweep droped some traffic. And under the rules it did not show anything .What does it meanThanks

sib2017 by L4 Transporter
  • 10662 Views
  • 7 replies
  • 0 Likes

Telegram website is not accessible

Hi, I've one client that cannot access https://telegram.org but he can access all other https website. We tried to use a security rule with one source address and any any allow but still the same. In the traffic monitor we can observe the session end reason is aged-out. We are not using any ssl decryption rule. Regards,Sharief

PA telegramTraffic log.png
PA telegramTraffic log2.png

Resolved! How Many public IP be required to setup full HA Active-Active Mode With two Palo Alto NGFW 3020?

Hello Geeks, I would like to ask for your kind support on my issues of 'How Many WAN IP will be required to setup full HA Active-Active failover mode with two Palo Alto NGFW 3020?' First of all, I would like to appologize you all if my question may make your mind complex. We already bought NGFW 3020 firewalls (Two) to upgrade our organization ne...

Wayne88 by L1 Bithead
  • 4291 Views
  • 1 replies
  • 0 Likes

Resolved! spoof

Hi,How palo alto blocks if ip address is spoofed .Why does it not work in vwire modeThanks

sib2017 by L4 Transporter
  • 4068 Views
  • 1 replies
  • 0 Likes

Link Aggregation Query

We have PA 500 which links to 100 Mbps throughput as mentioned by datasheet.If we do link aggregation would it be possible for us to increase that ? Thanks in advance.

Resolved! Site to Site VPN with error Failed SA

Hi, We have configured a site to site vpn between palo alto and cisco ASA. However, both sites are static and PA is the intiator, ACL is configured properly on Cisco side but I got the error: "IKE Phase-2 negotiation is failed as initiator, quick mode, Failed SA: 213.42.x.x [4500] - 185.141.x.x [4500] message id:xxxxx. Due to negotiation timeout...

"Client cert is invalid to the gateway" error

Hi, I am trying to setup machine cert authentication, but it appears I am missing something. Local user auth works fine without certificates. Gateway and Portal are on a single 3020 with 7.1. I created a local-CA and generated a cert for all windows 7 machines.I imported this cert into the Local Computer personal stores on the windows 7 compute...

BBartik by L2 Linker
  • 4368 Views
  • 2 replies
  • 0 Likes

Changing Global Protect Portal Using plist without Restarting Mac

Here are the steps I've tried in chaning the portal Global Protect.app without restarting the Mac: Packaged up /Library/Preferences/com. paloaltonetworks.GlobalProtect.settings.plist and ~/Library/Preferences/com. paloaltonetworks.GlobalProtect.settings.plist with the new <portal>Deployed package to both paths listed above (Mac does not ta...

ShawnP by L1 Bithead
  • 5845 Views
  • 4 replies
  • 0 Likes

NAT Between VR's

Hello.Despite my best efforts I am unable to get this concept working. We have 1 x Palo Alto 3020.It has 2 Virtual routers configured. Both use 192.168.*.* networks. I'd like to access a machine in the neighbour VR, from the opposite VR. As the networks overlap, I presumed this would be a case of using NAT. I can't get the configuration to w...

PCortes by L0 Member
  • 2843 Views
  • 1 replies
  • 0 Likes

Palo Alto and Polycom Relpresence Issue

Hi All, Having issue using Polycom mobile. On our side: No video and audioOn Dialed no: Video and Audio is working we translate trust network to a specific public address and allow Policy:trust network -> untrust to any destination and service.Untrust (public address of peer) -> Trust any destination and service. Palo Alto ALGs - Disabled ...

Hostname in user id and terminal server agents issue

We are using dns name for user id and terminal server agents in firewall configurtaion like below However intermittelnly we are seeing red light on firewall and while checking directly on terminal server agent software, the firewall connection is vanished.We tried restaring services from server side. but no help. We suspect if something changes ...

fqdn.png
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels