General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

QoS limiting download bandwidth for multiple subnets behind LAN interface.

Hi, I need to limit download bandwidth for multiple (more than 😎 subnets which are behind LAN interface. They need to have different limit values. I can't believe there is only 8 classes and I am limited to them. So is this a hardware limitation? What is the purpose of it? And most important, is there anything to workaround it? Thanks, Rahman

Can Not Registered My PA-200

Hello, I have registered the PA-200 on support web site, and the license is showed correct on the web GUI and on command "request license info", but it still show "device registered: no" on "show wildfire status".Do anyone know why ? And how can I make it to the "yes" so I can use the wildfire function? Please help me ! Thanks.

WS000003.JPG
mjkssg by L1 Bithead
  • 6990 Views
  • 9 replies
  • 1 Likes

Resolved! MineMeld outbound calls impacted by SSL interception

I could see the node was having problems pulling the external resource due it being decrypted and our CA being used. I added our CA to the Ubuntu store with the processes used here, but still no juice. http://askubuntu.com/questions/645818/how-to-install-certificates-for-command-line Thoughts?

Change to HTTP decoder

Did I miss a notice that the http decoder was being changed so that most of my rules based on the web-browsing app would break? Nearly all of my web-browsing traffic is suddenly being identified as unknown-tcp. I notice in the release notes for 646 app update that the http decoder was modified.

epeeler by L2 Linker
  • 2252 Views
  • 1 replies
  • 0 Likes

Palo Alto deny All policy reason non-syn-tcp

Hi, We realised our PA in version 7.0.6 is having any issue with the traffic. We see many traffic being dropped by DENY all rule (the last rule in the rule set). Looking in application we see "non-syn-tcp" in all the connections. These denies connections always ocurrs each 30 minutes. For example: 4.01pm, 4.31pm, 5.01pm, 5.31pm. we have disab...

logs.JPG

Resolved! Multiple VLANs through Network Interface

Hopefully this is a very simple question, but I wanted to make sure I was actually researching the correct thing. I am planning on connecting a hypervisor (Hyper-V 2012), directly to one of my Network Interfaces on my PA. The hypervisor has multiple VLANs, and I need them all to go through the PA. I incorrectly thought if I just set the VLAN/...

Exceeding IPs in one list

Hi, The miner Ransomware IP has > 10000 so I'am wondering how I could solve this issue. Should have some output feed that you can define to take a certain amount of IP's so you can map that on your hardware. And then create a second output that is skippen a defined amount of IPs an creating output feed with next range of IPs Something like:...

Forwarding streaming traffic to a second Palo

Hi all. We have two Palo 3020s, each connected to a different ISP. At the moment the 1st firewall handles all our LAN internet based traffic, whereas the second firewall is mainly used for our VPN connections. We're looking at forwarding streaming traffic from the 1st firewall to the second firewall, to reduce the bandwidth usage on our primary ...

Router or Firewall for S2S VPN

We are standing up a new data center and there is some disagreement about whether the Firewall or the Router should host the IPSec VPN. The Security Team suggests the Firewall for a few reasons (Logging being the biggest)while the Networking Team would like to use the Cisco Router (Speed and ease being their reasoning.) Has anyone run into a s...

jsanford by L0 Member
  • 4313 Views
  • 3 replies
  • 0 Likes

Captive Portal with Radius and groups of users

HelloI'd like to consult with You one problem. My users authenticate with Radius on Captive Portal web page.Problem that comes to me is how to assign access according to groups of users. My FreeRadius has only one group of users, I can add more but how to use it in PAN?I read How to Configure RADIUS Authentication and there is "Retrieve user gro...

_slv_ by L4 Transporter
  • 9104 Views
  • 6 replies
  • 1 Likes

GlobalProtect with multiple sites

Hello all, At my location we have 3 internet connections each at a different building. We have private and leased fiber inbetween so our entire organization is one internal network. At the internet connection points I have been replacing the Cisco ASA's we had with PA-3020's. I just finished the second one and will most likely get the 3rd one w...

why do we update wf-content-version on WF-500 appliance

Dear Experts, I was wondering that why do we update wf-content-version on WF-500 appliance, what is the reason for it. As I have configured WF-500 to generate the signature locally, what additional value will be added by downloading why do we update wf-content-version on WF-500 appliance. Best Regards, Fozail

fozail by L3 Networker
  • 4860 Views
  • 6 replies
  • 0 Likes

Resolved! Output does not work

I have created a miner with prototype ransomwaretracker.RW_IPBL., and processor and outputs. Miner shows 11497 indicators but processor and outpus shows 0 indicators. It cloned the model with default. I have attached a pdf with setup. I would appreciate help. Thank you.

Screenshot_1.png
Screenshot_2.png
Screenshot_3.png
Screenshot_4.png

Palo Alto firewall as Default Gateway at Branch location

Hi all, I am working on redesigning my branch location network and there is a requirement where we will need to move the Default Gateway to the Palo Alto firewall at the branch which the Palo Alto will be handle inter-vlan routing at the branch. Currently my Cisco router is handling this function today. I wonder if this can be done with Palo Alt...

datran by L0 Member
  • 2958 Views
  • 2 replies
  • 0 Likes
  • 24381 Posts
  • 123 Subscriptions
Top Solution Authors
Top Liked Authors
Labels