General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Bazar IPsec with Xauth RSA issue

A couple months ago I noticed my VPN on my phone stopeed working. I was originally using CM 12.1 but have since moved to mashmellow touchwiz for my Galaxy S5. Def not phone related as the issue remains, and is the same no matter what phone or OS versino being used and I'll provide some infra info before decussing the issue. I have two ISP, confi...

Zewwy by L3 Networker
  • 3196 Views
  • 2 replies
  • 0 Likes

Resolved! Deactivate the Licenses

Hi Guys, A quick question? If l am going to deactivate a licenses on the box does it mean that the time will stop on them. So when l will re-activate them later in a couple of months licenses will become active from the deactivation time/period? Can l activate auth codes to the same device/boxes?Also, when the licenses actually becoming active/v...

Block download\upload file from web based email

Hi, I've tried to set a new rule that will block download\upload file from web based email.The problem is that when user downlod files from outlook.com (for example) the service is not recognize as "web based email".Any suggsestions? Thank you!

Erez by L1 Bithead
  • 4815 Views
  • 4 replies
  • 0 Likes

User to IP mapping issues while connecting to WIFI(wireless)

Scenario: User comes to office connects to LAN. The user to IP mapping works correctly.We allow access to internet based on usernames.User disconnects the Ethernet cable and goes to different room where he connects with wifi.However loses internet connection. Because user to IP mapping is still with old LAN IP. What are the best practices to avo...

HA Failover in a Multi Vsys environment

I am currently setting up HA in a multi vsys environment, cant seem to find any documentation on the subject. Currently I have a HA pair of 5050's with 3 vsys, HA has been setup but how do I ensure when vsys1 fails it is the only system that fails over and not vsys2 and 3? HA has been setup with data link and control link and I am monitoring the...

PA-7050 HSCI Ports

I am in the process of a cluster (active/passive) design for two PA-7050 chassis. We have two Datacenters in two different locations. The DC's are connected through a Layer 2 connection.Can I use the HA-2 QSFP+ Interfaces on the SMC to interconnect the two Chassis ?CheersRoland

gafrol by L4 Transporter
  • 6925 Views
  • 4 replies
  • 0 Likes

No internet issue on one sub interface but works fine on other sub interface

I am having a simple setup.I have created a new virtual router.Added 2 sub interfaces. ( 1/1.320 and 1/1.340)Added default route.Can not ping ISP next hop. No block on logs. But Bytes received 0.I have connected my other ASA router to the switch which is connecting ISP everything works fine. Then I have made the same setup with e ½ sub interface...

internet.PNG

Palo Alto updates mails

Hi, My customer recently had problems with Palo alto apps&threats updates. They had SMB connections being allowed but with the last content update these connections were cataloged like "SMB brute force" and connectios were dropped. The best way would be to install manually these apps&threats updates, right?? We receive the palo alto upda...

Resolved! HA not synchronized after commit from Panorama

I tried it twice, same result every time. I commited change from Panorama to Active firewall and noticed 'Not synchronized' message in Dashboard HA tab. I can't even sync Active with Passive manually. I am using 5060 with 7.1.2

niuk by L3 Networker
  • 16353 Views
  • 9 replies
  • 0 Likes

LACP in HA issue

I have a pair of PAN 5060 (v.7.1.2) firewalls in HA Passive/Active connected with LACP to pair of core Nexus 9000 switches. From time to time (every hour or few) connectivity to active firewall is faling (can't ping firewall LACP L3 interface ip address from core) for a few sec. When it happens I noticed presence of MAC adddress of firewall on ...

niuk by L3 Networker
  • 6015 Views
  • 6 replies
  • 0 Likes

Resolved! VPN between 3 sites

VPN Site to SiteI have communication between site A and site B or site A and Site C, but I have not communication between B y C through ASite A (headquarters )Site B (Windows Azure)Site C (Bank)The required communication is the site B to contact C through A.Can you help me please

Updates to firewalls from Panorama show failed, but seem to install properly

When I try to push updates to our firewalls from Panorama, it reports that the job failed, but the jobs seem to complete anyway. This happens when pushing dynamic updates, and I had it happen again to a software upgrade on a PA-200 last night. When I installed the most recent Apps & Threat update, it showed failure on over 90% of our firew...

  • 24381 Posts
  • 123 Subscriptions
Top Solution Authors
Top Liked Authors
Labels