General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4121 Views
  • 0 replies
  • 0 Likes

How To Get the the Config of a Virtual Systems (VSYS)

Hello all! I am new to Palo Alto FWs and have a simple question. We have a PA-5050 and one of the users has been assigned a "Virtual Administror" role to a specific VSYS. The Administrator type is "Dynamic". This user was trying to get a dump/copy of the configuraiton of the specific VSYS he is assiged to; however, when he did that he was able ...

Resolved! Traffic processing when user information may be outdated

Hello!Could you please expalin what's the default traffic policy when new authentication agent/AD DC info is unavailable for some reason.Does the user-based rules get automatically turned off or someting?Does the traffic which gets under user-based firewall rules get passed or dropped?

MilosS by L0 Member
  • 2808 Views
  • 3 replies
  • 0 Likes

Resolved! policy muliple search syntax

I have a large list of IP addresses that I need to search on. I am not necessarily interested in if these systems are getting traffic, but moreso interested if they are present in any policies. Is there a way to search for multiple host/net objects in the Policies tab in one search, or does this need to be done serially? Thanks!-jgh

helfman by L0 Member
  • 2770 Views
  • 2 replies
  • 0 Likes

Qos policy and order of precedence

Hi,If a qos profile class 3 set limit 10 and no quarantee set . And a qos policy created and it kept on top of the policy list .Lets say there are other classes also set like below qos policy 1 ) 10.0.100.10 class 3 2 ) 10.0.101.11 class 2 class 2 10 class 1 10 class 5 10 class 6 10 class 7 10class 8 10 class 4 30 Total 100 Mb . S...

sib2017 by L4 Transporter
  • 1696 Views
  • 1 replies
  • 0 Likes

Resolved! Copying firewall rules from one firewall to toher

Hello Experts We have communication between DC and there are four three firewalls in between. So for bidirectional policy, I need to create same two rules on fw1, two rules on fw2 and two rules on fw3 (the only difference is offouce zone names and policy name). All firewalls are managed through Panorama. How I can quickly copy and paste firewall...

Resolved! IP address for NAT

Hello Experts I was checking confiugration on my PA firewall and I foud for every source and destination NAT, the public IP for NAT with /32 was assigned to external interface of firewall. In my opinion there is no need to assign public IP /32 to external interface of firewall? Can any body explain to me this

Global Protect Client Backward Compatibility

Hi, We have around 500 concurrent SSL clients connecting to our Palo Alto Gateway using Global Protect version 3.0.1. If I activate the newest version on the Firewall (Version 3.1.3), will the existing clients be unaffected by this activation and continue to work. Due to PC lockdown's in our organisation, I can't easily enforce an auto upgrade f...

MHaran by L1 Bithead
  • 3276 Views
  • 1 replies
  • 0 Likes

Resolved! PA support point to multipoint IPSEC VPN?

Hello Does PA support point to multipoint IPSEC in hub and spoke VPN envorirnmet? Means Only one tunnel interface we create on hub and through NHTB protocol, nexthop is bind to SA. Regards, GR

Resolved! Static bidirectional NAT or soruce/destination NAT

Hello Experts Someone from PA told me that for public service like email server, where bidirectional NAT is required, it is best practice to use source NAT and destination NAT for the same public IP instead of using static NAT because static NAT will create the rule from every zone to server zone NAT. Can any body confirm this, really it is a be...

Resolved! Security policy and NAT - zone direction

Hello Experts When I confiugre the NAT and associated security policy then I always confuse about the direction of zones. As I understand NAT zones are always determined by ingress interface zone (source zone) and route lookup gives the outoing interface zone (destination zone) but my question is when we confiugre the associated security policy ...

Proxy id between Palo Alto firewall and Cisco ASA

Hello Experts PA side there are two subnets: 10.0.1.0/24, 10.0.2.0/24 and Cisco side there are also three subnets 172.16.1.0/24 , 172.16.2.0/24. On PA firewall, I defined the proxy-id as below:proxy-id1: local: 10.0.1.0/24 remote: 172.16.1.0/24 proxy-id2: local: 10.0.1.0/24 remote: 172.16.2.0/24 proxy-id3: local: 10.0.1.0/24 remote: 172.16.1.0/2...

Blocking Bittorrent

I have setup two rules for blocking bittorrent on a particular zone. First rule is set to Deny Trust to Untrust using an application filter built with P2P applications. Second rule is set to Deny Untrust to Trust using the same application filter. I am able to block any uploading content, but the filter doesn't block any torrents from downloa...

u10723 by Not applicable
  • 14601 Views
  • 18 replies
  • 1 Likes
  • 24336 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels