General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4451 Views
  • 0 replies
  • 0 Likes

Resolved! User-ID Agent error

Hi, I am getting the below error in domain controllers DCOM was unable to communicate with the computer 10.0.129.3 using any of the configured protocols; requested by PID aec (C:\Program Files (x86)\Palo Alto Networks\User-ID Agent\UaService.exe). Event Xml: Please help to get rid of the problem Thanks

sib2017 by L4 Transporter
  • 5200 Views
  • 1 replies
  • 0 Likes

Searching a Howto for two ISP Connection and two Lan

Hello, i seach a HowTo for configuration two different ISP connections and two different LANs. Both should nothing to do with eatch other. They should be seperate. Is there any where a HowTo for this configuration? I only found twi isp connection for use with Backup connection but nothing for user bothe with different networks.I use a PA200 for ...

Resolved! Pan agent

Hi, I was using windows 2008 Domain controller and Palo alto ldap profile configured. ,Now changing to 2012 So which version of panagent need to be installed.Where can i download the panagent ?Is there something need to be done on paloalto side after migrating dc Thanks

sib2017 by L4 Transporter
  • 3492 Views
  • 3 replies
  • 0 Likes

No traffic being logged at all

Hello, we've got a bunch of virtual palo alto firewalls running 7.0.1. One set are running fine, largely configured with no issues. The other set are in a different environment, all the infrastructure is the same (same type of hypervisor, same version, all that) The only significant difference is that in the second environment, each PA is part o...

PaulAlto by L0 Member
  • 3326 Views
  • 5 replies
  • 0 Likes

management down

Dear engineers.Here again asking for help and advice.Implement a PA500 in L3 mode, in which trust in part through mpls 192.168.1.10 and have to get to the adminstracion that has the IP 192.168.1.20, but from another network that is in the MPLS not get to the administration of equipment such as:172.16.0.12 can not reach the administration of PA, ...

Edluna by L1 Bithead
  • 1945 Views
  • 1 replies
  • 0 Likes

Resolved! Ping outside interface from inside

Can somebody explain how I would be able to ping the IP address on an untrusted interface from inside (trusted). I setup a interface management profile on the interface and I can ping the outside interface IP address from the public internet, but not from inside. I don't see any drops, and creating a policy has not seemed to help either. I'm t...

bbilut by L3 Networker
  • 4710 Views
  • 1 replies
  • 0 Likes

Resolved! Handling Unknown TCP iSCSI traffic

I have a Dell Equalogic SAN that is replication to an offsite location. The traffic is sent over via a VPN tunnel (Certificate based). This traffic is being reported as unknown tcp. I can verify that the traffic in question is in fact the SAN traffic as the source and destination matches. I also read that the PA normally flags certificate based...

jharlow by L3 Networker
  • 4389 Views
  • 3 replies
  • 0 Likes

SSL Decryption

We do SSL Decryption on our PA. Recently we have been seeing a lot of sites that do not decrypt Chrome comes up with ERR_SSL_FALLBACK_BEYOND_MINIMUM_VERSION Firefox does not have any meaning full error message A quick google shows that it is to do with disabling of SSL v3. When the site is added to no decryption policy it works, so obviously...

RC-BHF by L2 Linker
  • 4605 Views
  • 5 replies
  • 1 Likes

Resolved! User-ID Agent questions?

Hello I have few questions regarding user-ID agent that is installed on DC (domain controller) 1- When the user login to machine, agent on DC send the username/IP details to PAN immediately? 2- Say after 10 minutes, user log off then agent on DC send the username/IP details to PAN immediately? 3- Multiple users login to one machine using s...

Kashif by L2 Linker
  • 10717 Views
  • 8 replies
  • 0 Likes

Frequent re-keying of ipsec tunnels

When I look under Monitor -> Logs -> System, I see the following: 1. ipsec-key-delete: IPSec key deleted. Deleted SA <SA info> SPI:<hex dump> 2. ike-nego-p2-succ: IKE phase-2 negotiation is succeeded as responder, quick mode. Established SA <SA info> SPI: <hex dump> 3. ipsec-key-install: IPSec key installed. In...

HA VSYS

Hi, Have anyone tried to configure different HA setup for different VSYS? Let's say VSYS1 is active/active and VSYS2 is active/passive. Thanks, MBS

Resolved! VPN with built in VPN Client of OS X

Hi there, for a special reason I need to setup a dedicated VPN Gateway for the built in iOS/OS X VPN client. Before I start to setup a Linux System for that I would like to find out if it's possible with PaloAlto or not. In the past there was a X-Auth possibility and I also found documents for PAN-OS 4.x but it looks like these possiblities ar...

Panorama Error commit

Hi, We have a cluster PA (Madrid) in version 5.0.14, and two PA in stand-alone (Singapur, Miami) in version 7.0.6. We just commited the panorama config but we got a error in cluster PA Madrid. Panorama in 7.0.6 can handle firewalls in version 5.0.14, right?? How can I get more info about this commited failed??

Captura.JPG
  • 24376 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels