General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Cannot loggin with my own personal account

Are there more people having trouble login in to websites of Palo Alto.

 

I pass my PCNSE 7 today, but login in the palo Alto Live community website, no way.

The company I work is parner, but we not owning PA firewall our self, juist managing the PA's o

...

Url Filtering Doesnt Works (not-resolved)

We faced with problem in URL filtering. While trying to open any site PA returns blocked mesage and url category : unknown.

This is the output from CLI :

 

test url nasa.gov

nasa.gov not-resolved (Base db) expires in 0 seconds
nasa.gov government (Cloud d

...

Failed to determine issuer

Hi guys,

 

I have a certificate that I need renewing as it's expired, but I am seeing "failed to determine issuer" when attempting to do this.

 

The certificate is a self-signed certificate, but it wasn't generated on the Palo, but rather an external CA.

...

Redistribute Route to GlobalProtect with BGP

Background:


We have a 172.20.0.0/16 internal network that is connected to our Amazon AWS VPC. A route is successfully advertized to our AWS peer using BGP and from the local network I can reach our server instances in the VPC. AWS resources are assign

...

Resolved! Block streaming media for sports only

Hello,

 

We have received a request to block streaming media only for the sports category.  Is that possible and how would we go about doing that?

 

We have a PA-3020 running software version 7.06

 

thank you

mike

JustMike by L1 Bithead
  • 4503 Views
  • 6 replies
  • 0 Likes

Can a IPSec tunnel entry be used by muliple connections

Hi, We have a number of (25+ ) remote 4G modems, that we wish to have VPN'd into our network. The modems can do L2TP/IPSec, IPSec, PPTP. Each modem has a WAN interface which is dynamic and a LAN interface with either one or two devices connected to i...

Resolved! Panorama or Firewall PAN-OS? What to upgrade first?

Hi Guys,

 

We currently have 12 Palo Alto firewall appliances and 1 Panorama management server. Panorama version is currently 5.1.9 and the firewalls are all on version 5.0.14.
We are looking at upgrading the entire estate to version 7.0.8  and it’s a m

...

Help with inter-subnet routing

Looking for input on a subnet routing, issue I am having. 

 

So I have let’s say for argument I have two zones, Trust and Untrust. 

 

Interfaces

Int 1/1 - Untrust Internet 192.168.0.1

Int 1/2 - Trust 10.8.1.20

Int 1/3 - Trust 10.26.96.1

 

I have a vi

...

ckluck by L0 Member
  • 3143 Views
  • 5 replies
  • 0 Likes

Help with network design

So my network consists of a PA200, a Juniper SRX, 2 servers, a VOIP phone, and a WAP. 

 

I recently configured the PA-200 with 3 subinterfaces for the 172.16.2.1/24, 172.16.3.1/24, and 172.16.4.1/24 networks. The Juniper port was configured with as a t

...

Zolson1 by L0 Member
  • 1975 Views
  • 2 replies
  • 0 Likes

PBFand Default route

In our orginazation, we have dual ISP and PAN firewalls. We have configured PBF with ISP 1 and default route for ISP 2

 

Both ISP interfaces on Pan firewall is same zone called untrust

 

example :  ethernet 1/11 

                     ethernet 1/11.200 ---

...

How PA can replace a Proxy

Hi,

 

i search a easy way to see who is surfing on witch web site. where is it and how can i automatically write it to our file server oder any where else to?

So my dream is to put our proxy out of order.

the PA is connected to LDAP i can see a user but

...

Resolved! How to bound an ACL to GP VPN client

Hello
i have a need to provide a contractor with VPN access to certain resource on internal network (let’s call them 10.20.1.0/24)

I have a working VPN GP/Portal and contractor can connect to VPN with no issue. But contractor is allowed to access all i

...

Routing via a new internet connection

We currently route all internet traffic out through an internet connection connected to Ethernet1/4 on out firewall. I have another Internet connection that I'm going to connect to Ethernet1/6, and I want fraffic from one of my VLANs on site to route

...

GC66 by L1 Bithead
  • 1736 Views
  • 1 replies
  • 0 Likes
  • 24195 Posts
  • 100 Subscriptions
Top Liked Authors
Labels