General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 778 Views
  • 0 replies
  • 0 Likes

Resolved! PA-500 6.1.4 Policy and URL filtering

Hi,

I have very big problem with my firewall. I have a few URL filtering rules which I block some of sites. 

Example:

1. Allow social network(linkedin) block youtube -> name AllowSN

2. Allow youtube block social network(linkedin) -> name AllowYT

3 an

...

ITBT by L1 Bithead
  • 4265 Views
  • 8 replies
  • 0 Likes

PA 500 stop sending reports automatically by email

Hello,

 

After upgrading two cluster of PA500 to 7.0.1, customized reports cannot be sent automatically using email.

Using the 'Test send email' is working so it's not an issue with the config. The device stop sending the reports after 18 days...

 

Regard

...

licenselu by L4 Transporter
  • 3098 Views
  • 4 replies
  • 0 Likes

VLAN with Palo Alto Networks PA-500

Hello,

 

We need to set up a VLANS in the office with the PA-500 but we don't like to change our address. It's possible to configure a VLANs with MAC address or protocole with PA-500?

Thanks 

RCHAIBI by L2 Linker
  • 5895 Views
  • 12 replies
  • 0 Likes

IPSec VPN issue

Hi All,

 

We have configured IPSec VPN between PAN and AWS. 

 

When i iniate the tunnel, IPSec and IKE SA installed successfully as a initiator.

then, IKE protocol IPSec SA delete message sent to peer. SPI:0x...

After a second, IPSec key deleted. Del

...

Javith by L3 Networker
  • 3547 Views
  • 6 replies
  • 0 Likes

HA Upgrade

I found this link on the knowledge base

https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Upgrade-a-High-Availability-HA-Pair/ta-p/57081

Has anyone used this method or any other method that they would like to share. I am currently at 6.

...

jdprovine by L4 Transporter
  • 3618 Views
  • 3 replies
  • 0 Likes

Resolved! LDAP Server Update DHCP from GlobalProtect

Hi all,

 

As you may know:  When a client is connected on GlobalProtect, they are assigned a dynamic IPv4 Address, not static.  

 

In my situation, I have about 100 GlobalProtect clients.  When the client connects for the first time, they are require

...

mmclimans by L3 Networker
  • 2047 Views
  • 1 replies
  • 0 Likes

Resolved! VPN s2s with Juniper ScreenOS with multiple networks on PA side

Hello

 

I have to connect by ipsec vpn PA200 PANOS6.1.6 with NS5GT 6.2.0r15 ScreenOS.

Problem that I have is that clients behind NS must have access to two LANs on PA and to internet throuth tunnel.

 

LAN_A———

LAN_B——— PaloAlto……….tunel_IPSec………………Netscree

...

_slv_ by L4 Transporter
  • 3894 Views
  • 4 replies
  • 0 Likes

SSL Decryption Woes

Hi,

 

I am not able to get to https://platinum.netnames.com/ with SSL decryption on, on PAN 7.0.1 / PA-3020 (IE11 / FF40 == TLS failure). Also, speed seems capped to 3Mbit/s with some CDNs (S3 AWS). Am I missing something?

 

thanks.

Nested groups problem

Hello all,

 

3 domain and single forest.

(root domain)  named as domainA and domainB and domainC

 

we created 3 LDAP profile for each domain.

we can see members from all domains.

we can see groups for each domain also.

 

But problem is, if we create a group n

...

PanIst by L3 Networker
  • 4290 Views
  • 5 replies
  • 0 Likes

TCP Echo Service on an interface

Hi all,

 

Is it possible to get an interface to respond to the TCP Echo Service on Port 7 via a management profile or some other way?

 

I don't mean a ICMP echo request (Ping) but what's described here

 

https://en.wikipedia.org/wiki/Echo_Protocol

ht

...

eugenep by L3 Networker
  • 2039 Views
  • 1 replies
  • 0 Likes
  • 23986 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Authors
Labels