General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! TSM backup and app override

Is configuring app overide for backup traffic like TSM best practices?  TSM is always our biggest talker on all our firewalls and we know this traffic.  It seems to me we wouldn't want the fw to inspect it all the way through layer 7.  Please provide

...

treese by L3 Networker
  • 3528 Views
  • 4 replies
  • 0 Likes

PA-500 Boot Time being slow

I have (3) PA-500's, and the one thing I have noticed on all of them, is that it takes up to 10 min. to boot.  It takes 15 min or longer if there is a new release being installed.  What does the PA use for storage, and why does it take so long in thi

...

Resolved! Way to ignore dependency warnings?

We have setup a general web browsing policy and users were being blocked from viewing github.  We allowed github-base to the policy and commited it.  They can now view github without any issues but every time we commit we recieve a warning "Applicati

...

ACESJosh by L1 Bithead
  • 8762 Views
  • 10 replies
  • 0 Likes

Draytek Vigor - Site to Site VPN

Hi there,

I'm looking to setup a few site to site VPNs using a PA2020 at our HQ site with Draytek Vigor 2830n routers at the other end. We have fixed IP addresses on the other end so I don't need to worry about the issues with dynamic IPs.

I was wonde

...

UKRB by L3 Networker
  • 4371 Views
  • 2 replies
  • 0 Likes

FQDN Address Object wont resolve

Hello,

 

I am trying to setup a U turn NAT that runs so that any system trying to contact time.apple.com using the NTP protocol will be rerouted to an internal NTP server. We do not allow NTP out and iPhones and iPads ignore DHCP settings for the NTP

...

PhilH by L2 Linker
  • 11071 Views
  • 9 replies
  • 0 Likes

Youtube getting falsely recognized as google

Shortly, after the APP-ID changes were implemented, I'm having problems with youtube.  By default we disable general access to youtube.  However, we do allow access to specific videos.  When I attempt to connect to youtube.com using http, I get block

...

bwsaloum by L2 Linker
  • 2796 Views
  • 2 replies
  • 0 Likes

migration ipsec rsa vpn from juniper ssg

Hello all,

 

There is 2 juniper firewalls.side to side between them.Side A and Side B

I'm going to change side A with Paloalto and for sideB change configuration is not allowed.

 

So everything is ok except for vpn.inside juniper phase 1 profile is s

...

mathsss by L1 Bithead
  • 3405 Views
  • 6 replies
  • 0 Likes

How custom forward logs to syslog server

We are sending all logs from Palo to SIEM. How can we eliminate those of low or no value to us (exp. Allow_TCP_End) to be sent to syslog server? The server fills up quickly and there's a large amount of logs that provide no insight during analysis; w

...

Arezoo by L0 Member
  • 2480 Views
  • 2 replies
  • 0 Likes

Resolved! Panorama LDAP group mappings not updating for user-id

We have user-id setup and every cluster with a designated master device for user-id mappings. I have the group mapping of the new AD group showing in the gateway itself, however when I go to implement the group in a policy in panorama, it will not di

...

VPNC Ports?

Hi all,

 

I have enabled VPNC for my Linux users who cannot use GlobalProtect.  Does VPNC use port 443 like globalprotect?  Can't seem to find any information about this on the web.

 

-Matt

mmclimans by L3 Networker
  • 2277 Views
  • 1 replies
  • 0 Likes

How to restart the OSPF Process

Hi, I'm trying to do some debugging of some OSPF troubles that we are having and I'd like to restart the OSPF process to see the neighbors comes up and the LSA exchange.  How do I do this via CLI?

 

On a Cisco router it would be "clear ip ospf proces

...

GlobalProtect Client not Connecting

Hi All,

I'm experiencing a problem with GlobalProtect and I'm hoping I can get some assistance.

 

I'm able to log on to the GlobalProtect Gateway. I successfully log in and Download the agent. However, when I click 'Connect'. I get an error that says

...

Bocsa by L3 Networker
  • 6741 Views
  • 3 replies
  • 0 Likes
  • 24034 Posts
  • 102 Subscriptions
Top Liked Authors
Labels