General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 264 Views
  • 0 replies
  • 1 Likes

Resolved! IPV6 how to protect the hosts

Hi everyone, I learn the palo alto firewalls as I configure them.

 

I have a PA firewall with 3 vlans, with management allowed over main vlan.

 

My ISP provided the Ipv6/48 block and I have manage to redistribute it over the networks it works great.

...

nevolex by L3 Networker
  • 966 Views
  • 1 replies
  • 0 Likes

PA-7000 Series PANOS-10.1

Hello,

 

We have a PA-7050 firewall that we are looking to upgrade from 9.1.15 to 10.1.10-h2. 

 

We are following the upgrade path provided by Palo Alto however when we upgrade to the recommended 10.0 release or the 10.1 release the entire firewall c

...

Owen1 by L0 Member
  • 431 Views
  • 1 replies
  • 0 Likes

Sending logs to SIEM one file per type

I am an administrator of a SIEM, for this I have usually asked the paloalto administrator to send me the logs via Syslog using port 514 to the IP of the server I administer.

 

After informing me that the process has been done, I check a specific rout

...

Error: failed to handle CUSTOM_UPDATE

HEllo,

 

I am using 5220 series firewall in 2 different DC. versions 9.0.9 and 9.1.6. When I commit on both firewalls, I get a custom_update error. After check now the dynamic updates, I commit again and the problem goes away.

Any suggestion,
Thank you K

...

Resolved! Using HA without a virtual mac possible?

Hello,

as the title says: I want to implement an HA active-passive setup on a virtualization platform that doesn't support MAC address changes on the VM side. Therefore, a newly generated virtual MAC is unfortunately not an option.

So, is there a way

...

User-ID with OpenLDAP

Hi,

I'm looking for a guide or guidelines on how to set-up User Identification with OpenLDAP. I've already set-up User-ID with Active Directory for an other customer but I fail to see how this is doable on a non-Windows machine (no PAN agent).

Any help

...

Resolved! Internet and internal network sepration via virtual router

Hello,

 

I am new to Palo Alto. I have basic question. 

 

Traditional setup I worked on my last project was as below,

 

 

VRF on cisco router for 

- Internet -0 bgp

- Production - bgp

- DMZ  - bgp

 

FW connects to all 3 VRF. Route between VRF is via

...

gondolf by L1 Bithead
  • 2032 Views
  • 4 replies
  • 0 Likes

cluster PA-5020 migrating to PA-1410

Hi Experts,

We are migrating from Cluster PA-5020 to PA-1410, I have some queries below if you guys can help me out please.

1. For platform migration(PA-5020 to PA-1410), we can just upload configuration files on the new PA-1410, just recheck physica

...

SNMP response on two interfaces? Possible?

I'm configuring NetFlow on our PA-5200. I'm collecting the data in What's Up Gold.  WUG has a limitations (it appears) that the NetFlow IP that I use for the IP address also has to be respond via SNMP on the same address.  However, the PA-5200 cannot

...

LIVEcommunity System Update - Delayed

UPDATE 11/8/23 11:43 a.m. EST:

LIVEcommunity’s System Update will be delayed. This means your use of LIVEcommunity will not be impacted this week (11/8-9), and you can proceed with business as usual.

 

Thank you again for your patience and stay tuned

...

jforsythe by Community Team Member
  • 697 Views
  • 0 replies
  • 0 Likes

Resolved! rx-bytes, tx-bytes mean

Hello everyone,

 

I wonder if the meaning of rx-bytes and tx-bytes in the "show system state browser" command represents bps or byte.

 

'rx-bytes':xxxxxxL, xxxx/s

'tx-bytes':xxxxxxL, xxxx/s

 

Thank you in advance.

 

 

Resolved! cannot find matching phase-2 tunnel for received proxy ID

Hello,

 

We have a site to site VPN setup between our PALO ALTO and a firewall of our customer that was allowing one IP. On the ipsec tunnel sec proxy-id allow local (172.18.23.61/32) and remote (172.21.88.191/32) . When we made this the VPN is enabl

...

  • 23630 Posts
  • 107 Subscriptions
Top Liked Authors
Labels