General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 2182 Views
  • 0 replies
  • 0 Likes

Panorama Audit Logs

Hello Experts

 

I am using Panorama to push configs to firewalls. But the problem is that there are alot of users, doing configuration but in audit logs of Panorama, it is showing config by <user> thats it. I would like to see what actual changes/comma

...

Wildfire .docx

Hi,

 

i am testing wildfire at the moment for forwarding .doc, .docx and EXE Files to the wildfire cloud.

 

This is my rule:

 

 

But it seems, that only .doc and .exe Files are forwared to the cloud (first Forward but then upload skip because the cl

...

WF Rule
DF Log
iweltag by L2 Linker
  • 6055 Views
  • 10 replies
  • 0 Likes

Resolved! Traffic processing when user information may be outdated

Hello!

Could you please expalin what's the default traffic policy when new authentication agent/AD DC info is unavailable for some reason.

Does the user-based rules get automatically turned off or someting?

Does the traffic which gets under user-based f

...

MilosS by L0 Member
  • 2625 Views
  • 3 replies
  • 0 Likes

Resolved! policy muliple search syntax

I have a large list of IP addresses that I need to search on.  I am not necessarily interested in if these systems are getting traffic, but moreso interested if they are present in any policies.

 

Is there a way to search for multiple host/net objects

...

helfman by L0 Member
  • 2593 Views
  • 2 replies
  • 0 Likes

Qos policy and order of precedence

Hi,

If  a qos profile  class 3  set  limit 10 and no quarantee set . And a qos policy created and it kept on top of the policy list .

Lets say there are other classes  also  set  like below 

 

qos policy 

1 ) 10.0.100.10   class 3 

2 ) 10.0.101.11  class 2

...

sib2017 by L4 Transporter
  • 1607 Views
  • 1 replies
  • 0 Likes

Resolved! Copying firewall rules from one firewall to toher

Hello Experts

 

We have communication between DC and there are four three firewalls in between. So for bidirectional policy, I need to create same two rules on fw1, two rules on fw2 and two rules on fw3 (the only difference is offouce zone names and po

...

Resolved! IP address for NAT

Hello Experts

 

I was checking confiugration on my PA firewall and I foud for every source and destination NAT, the public IP for NAT with /32 was assigned to external interface of firewall. In my opinion there is no need to assign public IP /32 to ext

...

Global Protect Client Backward Compatibility

Hi,

 

We have around 500 concurrent SSL clients connecting to our Palo Alto Gateway using Global Protect version 3.0.1.

 

If I activate the newest version on the Firewall (Version 3.1.3), will the existing clients be unaffected by this activation and con

...

MHaran by L1 Bithead
  • 3149 Views
  • 1 replies
  • 0 Likes

Resolved! PA support point to multipoint IPSEC VPN?

Hello

 

Does PA support point to multipoint IPSEC in hub and spoke VPN envorirnmet? Means Only one tunnel interface we create on hub and through NHTB protocol, nexthop is bind to SA.

 

Regards,

 

GR

Resolved! Static bidirectional NAT or soruce/destination NAT

Hello Experts

 

Someone from PA told me that for public service like email server, where bidirectional NAT is required, it is best practice to use source NAT and destination NAT for the same public IP instead of using static NAT because static NAT will

...

Resolved! Security policy and NAT - zone direction

Hello Experts

 

When I confiugre the NAT and associated security policy then I always confuse about the direction of zones. As I understand NAT zones are always determined by ingress interface zone (source zone) and route lookup gives the outoing inter

...

Proxy id between Palo Alto firewall and Cisco ASA

Hello Experts

 

PA side there are two subnets: 10.0.1.0/24, 10.0.2.0/24 and Cisco side there are also three subnets 172.16.1.0/24 , 172.16.2.0/24.

 

On PA firewall, I defined the proxy-id as below:

proxy-id1: local: 10.0.1.0/24 remote: 172.16.1.0/24 

proxy

...

  • 24253 Posts
  • 119 Subscriptions
Top Solution Authors
Top Liked Authors
Labels