General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

latest stable version of PAN OS

Hi All, I am looking for the latest PAN OS version that is being used( any pointers why it is good would be a plus) , i am looking to update my firewalls and Panorama. also any good links on how to absorb existing running firewalls in the panorama would be helpfull. Regards, ~Harry

Harshit by L3 Networker
  • 5089 Views
  • 6 replies
  • 0 Likes

I don't see a facility to schedule a reboot.

HiI would really like to be able to schedule a reboot at a future time. We are in the process of migrating sites to Panorama from a a local configuration.The config has to be deployed through the single link into the office. This link is a BGP peer. Unless someone is on site then if we lose the BGP peering the device will be inaccessible. The co...

port 2000 and NMAP

I'm having an issue where any traffic through palo alto using destination port 2000 will create a tcp handshake and no more traffic will pass. I've talked to support and no traffic is being dropped by the firewall. i've added a rule to allow tcp 2000 as a service so it shouldn't be doing anything with the appid and no difference in behavior. A...

Mat_FA by L1 Bithead
  • 9177 Views
  • 5 replies
  • 0 Likes

Automatic VPN Failover

Dear Friends, IF 1 ISP link goes down of operator END we unable to automatically forward to another ISP link. please suggest how to do this. i am using PAN-3020 with 1 ISP and Operator END cisco with 2 ISP. Regards Satish

Satish by L4 Transporter
  • 4801 Views
  • 6 replies
  • 0 Likes

GlobalProtect Portal Banner Message

Would anyone have a simple example that would allow me to put a warning banner below the login table on the GP Portal page? I'm no HTML expert and have tried to follow some of the posts and documents here, but am not having any luck. I have made sure to set the custom login page in the portal configuration page, but the text I tried to add doe...

dan731028 by L3 Networker
  • 2723 Views
  • 2 replies
  • 0 Likes

Resolved! SSL Decryption

Hello We have recentley tuned on SSL Decryption for some users. Since then we are getting some SSL sites that cannot be accessed due to cypher mismatch. It is something we were exepcting, but not the amount of URL this is happneing for. My question, is there a setting that I can turn on that will allow the site to be accessed if the SSL Decr...

RC-BHF by L2 Linker
  • 2995 Views
  • 2 replies
  • 0 Likes

Multi-VR routes and security policies issues

I have an issue where we have mulit-VRs in place 1) default and 2nd) VR that is utilized for DMZ and untrust routes Both VR's share a common zone name "public" for example. I have issues routing where for instance I have my internal network segments in the VR's FIB's and my routed networks fail to return back through the correct interfaces....

CZaloba by L0 Member
  • 3911 Views
  • 2 replies
  • 0 Likes

Global Protect DNS Suffix Not Propogating to Client

Hi, I have a strange issue where my Global Protect SSL Client connects to the firewall with no issues. I get the IP, the routes and the DNS servers but I don't get anything listed in the DNS Suffix entry. I have configured the DNS Suffix correctly under 'Global Protect Gateway', 'Client Configuration', 'Network Settings' and can even see the...

MHaran by L1 Bithead
  • 8249 Views
  • 5 replies
  • 0 Likes

syslog configuration

Hi, I have attached my syslog configuration . but in my syslog i missed most of the logs . then assigned to the policy To forward all the logs , attached configuration what if i choose another facilty ? if i put one interface in tap mode can i forward the log to syslog server Thanks

Palo alto syslog server.png
server pofile.png
sib2017 by L4 Transporter
  • 5628 Views
  • 4 replies
  • 0 Likes

Wildfire

So currently I am using wildfire but only choosing to forward the file. Is anyone using the block option? If so are what are the pros and cons?

jdprovine by L4 Transporter
  • 4843 Views
  • 7 replies
  • 0 Likes

vwire & VLAN tagging?

Hi all,Is there any issue with configuring a vwire for both tagged and untagged traffic. For example use VLAN tag 0 AND whatever my real tags would be, like 1, 100, 200, etc. I'm assuming it will be fine since there is an option for 0-4094.Any issues or limitations I should be aware of? Thanks for your support!

BigIr0n by L0 Member
  • 11260 Views
  • 6 replies
  • 0 Likes

User-ID Group Mapping for Multi Domain Single forest

Hi everyone. I'm trying to setup a User-ID installation for our multi-domain Active Directory environment. Here is a rundown on what we have DomainA = Workstations, groups, users, servers, etc. The main domain where everything is conducted DomainB = legacy domain where some user accounts are located. I've installed the User-ID agent on a Win...

Resolved! Manual failback for PBF

Is there a way to force PBF rules to have to be manually failved back? As it is now, if our primary ISP fails, we failover to a secondary ISP using PBF. However, once the primary is back up, things fail back to it immediately. We would like to prevent the immediate fail back and not use a timer. ISP recoveries often times flap for a period of ti...

cburke by L1 Bithead
  • 7562 Views
  • 9 replies
  • 0 Likes

Losing group mappings suddenly

Hi, We have a PA3020 with PanOS 6.1.10. We are having problem with any groups, suddenly the Palo Alto loses group mappings in 2 groups and the rule stops matching, we dont know why PA stops identifying the groups. I have checked the useridd.log file and i see these errors in the groups...why? Error: pan_ldap_ctrl_search_single_group(pan_l...

Aggregate Ethernet Considerations

Hello Everyone, I just want to double check my understanding of AE interfaces limitations indicated below. Appreciate your feedback. 1. I cannot mix 1G copper interfaces with 1G fiber interfaces in the same AE. Is this correct for all platforms and OS versions? 2. I cannot create more than 8 AE interfaces on the same box. Is this correct...

  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels