General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4243 Views
  • 0 replies
  • 0 Likes

Resolved! IP address for NAT

Hello Experts I was checking confiugration on my PA firewall and I foud for every source and destination NAT, the public IP for NAT with /32 was assigned to external interface of firewall. In my opinion there is no need to assign public IP /32 to external interface of firewall? Can any body explain to me this

Global Protect Client Backward Compatibility

Hi, We have around 500 concurrent SSL clients connecting to our Palo Alto Gateway using Global Protect version 3.0.1. If I activate the newest version on the Firewall (Version 3.1.3), will the existing clients be unaffected by this activation and continue to work. Due to PC lockdown's in our organisation, I can't easily enforce an auto upgrade f...

MHaran by L1 Bithead
  • 3311 Views
  • 1 replies
  • 0 Likes

Resolved! PA support point to multipoint IPSEC VPN?

Hello Does PA support point to multipoint IPSEC in hub and spoke VPN envorirnmet? Means Only one tunnel interface we create on hub and through NHTB protocol, nexthop is bind to SA. Regards, GR

Resolved! Static bidirectional NAT or soruce/destination NAT

Hello Experts Someone from PA told me that for public service like email server, where bidirectional NAT is required, it is best practice to use source NAT and destination NAT for the same public IP instead of using static NAT because static NAT will create the rule from every zone to server zone NAT. Can any body confirm this, really it is a be...

Resolved! Security policy and NAT - zone direction

Hello Experts When I confiugre the NAT and associated security policy then I always confuse about the direction of zones. As I understand NAT zones are always determined by ingress interface zone (source zone) and route lookup gives the outoing interface zone (destination zone) but my question is when we confiugre the associated security policy ...

Proxy id between Palo Alto firewall and Cisco ASA

Hello Experts PA side there are two subnets: 10.0.1.0/24, 10.0.2.0/24 and Cisco side there are also three subnets 172.16.1.0/24 , 172.16.2.0/24. On PA firewall, I defined the proxy-id as below:proxy-id1: local: 10.0.1.0/24 remote: 172.16.1.0/24 proxy-id2: local: 10.0.1.0/24 remote: 172.16.2.0/24 proxy-id3: local: 10.0.1.0/24 remote: 172.16.1.0/2...

Blocking Bittorrent

I have setup two rules for blocking bittorrent on a particular zone. First rule is set to Deny Trust to Untrust using an application filter built with P2P applications. Second rule is set to Deny Untrust to Trust using the same application filter. I am able to block any uploading content, but the filter doesn't block any torrents from downloa...

u10723 by Not applicable
  • 14886 Views
  • 18 replies
  • 1 Likes

Adding NAT rule order in Panorama cli

Hi all, I am looking to add around 60+ NAT rules for monitoring over IPsec that requires a policy NAT. I need to have them above another rule in the list for it to work. It is a very messy NAT list that I don't have the freedom to clean up. The NAT entries are being added to a device group in Panorama. Thanks in advance, Danny

PA allowing IM (viber,line,zalo) | PA policy process

Hi, target is to allow im apps but modify categires. I have created a policy allowing IM and modify most categories as block. Policy sample:Policy is SRC: 192.168.x.x | DST: any | Srv: any | App: IM (viberbased,im,googlebased,ssl) | Url:BLK_CATEG BLK_CATEG (list of blocked categories)News / MediaTravelVehiclesSports / recreationsSociety and Lif...

Resolved! Public email attachment

Is there any way to block users' uploading attachment for public email (gmail, yahoo mail and hotmail) ? I created a security policy for allowing applications (gmail, hotmail, yahoo-mail) and associated with file blocking profile but didn't work. Please advise if the configuration is correct.

Resolved! Assign a new QOS profile to just one tunnel on a tunnel interface

Hi Guys, I'm rather new to Palo and this community, so forgive me if I don't do this right. We need to restrict the Egress Max of just one tunnel (out of 9) on a tunnel interface.The config looks like this right now: I would like to change just tunnel 9 to 1Mbps. How would I go about doing that? Thanks in advanceRonelle

Capture.PNG
Ronelle by L0 Member
  • 2238 Views
  • 1 replies
  • 0 Likes

Resolved! Crossover cables on PA-7050

Hello, I found that for HA1 when there are directly connected, Palo Alto recoments to have them interconected with crossover cables.is this the same with PA-7050?https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/high-availability/configure-active-passive-ha because at this point it's working with straight thru cables. Could you ple...

Kaliman by L2 Linker
  • 2634 Views
  • 1 replies
  • 0 Likes

URL Filter vs. Type in firewall?

Does the URL filter at urlfiltering.paloaltonetworks.com have anything to do with how a Palo Alto firewall classifies the 'type' of site?I noticed that there are some sites that our firewall classifies as 'spyware' that the URL filtering site classifies as other (not malicious) categories. I'm trying to understand what is the most expedient way ...

StacyE by L0 Member
  • 2821 Views
  • 2 replies
  • 0 Likes
  • 24359 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels