General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Too many open files error in engine log

Hi, As of yesterday morning I'm getting an error in my MineMeld engine log that is indicating too many open files. Also, some of my input and output miners are not updating (they show 0 entries even though there are indicators in the input table in the web interface). The timing indicates these errors are possibly the cause. Examples: 2016...

Resolved! M-100 service routes

Hello, can I setup service routes for M-100 other than the mangemnet Interface? I want to use Eth1 or Eth2 instead of the Management Interface. Please advise. Thank you

Kaliman by L2 Linker
  • 2860 Views
  • 1 replies
  • 0 Likes

disable inbound url filtering for performance

Would it make sense to disable url filtering for inbound traffic to our servers for performance reasons ? Logging is hogging our resources (and that's a real problem on PA-2020). Would it make any difference ? We only host a few low traffic websites...In comparison, we have far more outbound traffic from our users to the internet.

dieter_b by L4 Transporter
  • 3195 Views
  • 1 replies
  • 0 Likes

Resolved! ARP not advertising for NAT translation

Hello, We have BGP routing on WAN interface with WAN IP and an additional subnet ip address which is advertised by the firewall to the ISP. When we create a NAT translation from a private IP address to a public IP address from this additional subnet then we don't receive any traffic for it at all. It's not in under monitor tab. When we check BGP...

Farzana by L4 Transporter
  • 9326 Views
  • 3 replies
  • 0 Likes

Service to Application for more than 100 policies

Hello Experts I have more than 100 policies on PA firewall with service ports and application any. Manually identifying the application for each rule from logs and creating the rule with specific application on top of that rule, is really time consuming and lot of work required. Is there any good way from Panorama or any other script or tool, I ...

Resolved! IPSec and Panorama with Satellite sites

Hello, I'm in the process of preparing two PA200s for our satelite sites. We are using Panorama to configure all of our firewalls and I'm trying to keep all my configs in the templates but am torn when it comes to the VPN configuration. My main concern right now is that we haven't received our IP's and routing info from the ISP and we need to...

Global Protect Client could retrive username's information

Hi All, I have a question for you related to "Global Protect Client".On the endpoint I have a certicate installed, that is trusted by PA firewall imported from an internal CA.With this certificate it's possible when connecting to the "Global Protect Portal" via web, retrive the username and autocompile the related field on the webpage.Is it poss...

Data plane - usage

What would cause the data plane that has been running aroun 25% start running at 35-40%? Is there away to track down the reason

jdprovine by L4 Transporter
  • 7606 Views
  • 13 replies
  • 0 Likes

Resolved! Grouping security policies

Hello Experts Can we group the security policies like all AD related rules in one group. This functionality is there in Juniper NSM and checkpoint. I am wondering how I can achieve this in PA. May be through tags?

Minemeld - best way to backup and move config to new image

I am tring to move the /opt/minemeld/local/config directory to a new image of Minemeld I have running in AWS. I can scp the config directory out of my exisintg Minemeld using winscp but when I try to copy it into my new Mindmeld image it always aborts. It appears to be a permission issue but not sure how to around this. I am logged in via wi...

rschunk by L2 Linker
  • 7691 Views
  • 1 replies
  • 0 Likes

Resolved! Session Lookup for inter-virtual communication

Hello Experts I was just wondering how firewall session is created for inter-vr communication. I have scenario like this: Interface eth1/1 (Trust-VR) Trust Zone ---LAN (10.10.10.0/24)Interface eth1/2 (Untrust-VR) Untrust Zone ---INTERNET In Trust-VR, I have 0/0 default route towards Untrust-VR, I have created the security policy between Trust to...

Resolved! Asymmetric Routing and TCP syn check based on interface or zone?

Hello I have scenario like firewall is connected to two routers R1 and R2 through eth1/1 and eth1/2 interfaces respectively. From firewall, traffic is going through R1 via eth1/1 interface and return traffic is coming through R2 via eth1/2. This is asymmetric routing and firewall tcp syn check will fail. My question is that Palo Alto firewall c...

  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels