General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4131 Views
  • 0 replies
  • 0 Likes

Adding NAT rule order in Panorama cli

Hi all, I am looking to add around 60+ NAT rules for monitoring over IPsec that requires a policy NAT. I need to have them above another rule in the list for it to work. It is a very messy NAT list that I don't have the freedom to clean up. The NAT entries are being added to a device group in Panorama. Thanks in advance, Danny

PA allowing IM (viber,line,zalo) | PA policy process

Hi, target is to allow im apps but modify categires. I have created a policy allowing IM and modify most categories as block. Policy sample:Policy is SRC: 192.168.x.x | DST: any | Srv: any | App: IM (viberbased,im,googlebased,ssl) | Url:BLK_CATEG BLK_CATEG (list of blocked categories)News / MediaTravelVehiclesSports / recreationsSociety and Lif...

Resolved! Public email attachment

Is there any way to block users' uploading attachment for public email (gmail, yahoo mail and hotmail) ? I created a security policy for allowing applications (gmail, hotmail, yahoo-mail) and associated with file blocking profile but didn't work. Please advise if the configuration is correct.

Resolved! Assign a new QOS profile to just one tunnel on a tunnel interface

Hi Guys, I'm rather new to Palo and this community, so forgive me if I don't do this right. We need to restrict the Egress Max of just one tunnel (out of 9) on a tunnel interface.The config looks like this right now: I would like to change just tunnel 9 to 1Mbps. How would I go about doing that? Thanks in advanceRonelle

Capture.PNG
Ronelle by L0 Member
  • 2216 Views
  • 1 replies
  • 0 Likes

Resolved! Crossover cables on PA-7050

Hello, I found that for HA1 when there are directly connected, Palo Alto recoments to have them interconected with crossover cables.is this the same with PA-7050?https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/high-availability/configure-active-passive-ha because at this point it's working with straight thru cables. Could you ple...

Kaliman by L2 Linker
  • 2605 Views
  • 1 replies
  • 0 Likes

URL Filter vs. Type in firewall?

Does the URL filter at urlfiltering.paloaltonetworks.com have anything to do with how a Palo Alto firewall classifies the 'type' of site?I noticed that there are some sites that our firewall classifies as 'spyware' that the URL filtering site classifies as other (not malicious) categories. I'm trying to understand what is the most expedient way ...

StacyE by L0 Member
  • 2797 Views
  • 2 replies
  • 0 Likes

Global protect error certificate

Hi, We are having problems with globalprotect. We have tried installing several GP client versions 2.3.1,2.3.5 and 3.1.3 but the result is the same.We cant connect using Windows or MAC, we receive a certificate error.We read in the KB paloalto that could be because the FQDN of the computer must match the machine name on the certificate, we tried...

Resolved! HA pair issue PA-500

Hi Guys, Interesting one. Devices are in HA pair of the PA-500. Suddenly we are no longer able to access the active device through the GUl, but able to ping mgmt interface and SSH to it. When SSHing getting the screen below: A firewall in not producing any command output and doesn't see itself as in HA pair, no (active). The passive device stil...

ssh error.PNG
error.PNG
state.PNG
int-state.PNG

How can I block web access for one mac address on my network?

Hi all, I have a PA-3050 that I've been asked to configure so that it blocks web access for one of the machines on our network, but I can't seem to find the right place to add the mac address of this machine, and searching has failed me so far. I'd appreciate any help anyone could offer.

jlaschuk by L0 Member
  • 7760 Views
  • 2 replies
  • 0 Likes

Unable to download updates

I have a PA-200 running 6.1.14. I am able to generate a list of software updates, global protect clients and the dynamic updates, but when I attempt to download any of the files, I get the following error: Failed to download due to network failure. Please try again later.Failed to download file I have the update server set to the IP address inst...

Resolved! Certificate error when accessing Gmail using SSL Decryption

Hi, I've implemented SSL Decryption in our environment and it worked find for most of the domains but "sometimes" when we access Gmail using Chrome it will give us a certificate error. We are using internal CA and the Root certificate was distributed to all machines using GPO. I checked the trusted CA on Chrome and the certificate was there, del...

  • 24337 Posts
  • 124 Subscriptions
Labels