General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4117 Views
  • 0 replies
  • 0 Likes

PA-2020 in HA commit are just a nightmare

Dear Community, Is there a official way to improve the commit on those models ? It could take more than 15 minutes sometime, it really hard to work with those appliance.the upgrade for 3030 appliance is insane too, about 40 000 € with 3 years support. To improve the commit cmd, I have to use CLI to restart the management plane with the following...

Can you create two virtual firewalls inside one physical PA-200?

I am wondering if you can create two virtual firewalls inside one physical PA-200 box?If this is possible I would like two physical ports to be allocated to each virtual firewall. One virtual firewall and its set of ports will be for a production network and the other virtual firewall and ports will be used for a visitor network. I am trying t...

Logs related to load old configuration from Panorama

Hi all, From Panorama web interface, if I load an old committed configuration into a managed device (I mean from Panorama->Managed devices-> Backups tag), where I can see the logs related to these operations?In the local configuration system logs I can see that the operation has been done by Panorama , but from Panorama device how can I se...

JLBravo by L1 Bithead
  • 1786 Views
  • 1 replies
  • 0 Likes

Resolved! GlobalProtect connect via batch

Hello, Our GlobalProtect Agent will be installed on different kind of PCs. Some external (the PCs of some suppliers or computer maintenance), and some internal (laptops with 3G connections). So I've chose the "on-demand" connection. For the internal laptops (Windows), I'd like to do a batch to launch the 3G connection, then when it's ok to launc...

I want to know some details about a specific threat signature.

Hello everyone I have this threat signature.: "NUCLEAR Exploit Detection Kit (38268)" , and I'm researching on what date was it created?I need to know which version of the threats database was included and released this signature? I would greatly appreciate any help. Regards, dicu

SOC_CSG by L4 Transporter
  • 3679 Views
  • 1 replies
  • 0 Likes

Resolved! DHCP relay through a VPN tunnel

Hello,Just curious if anyone has had to go throug this and found a solution. layer3 switch <-> Cisco ASA <-> VPN <-> PAN <-> DHCP server I know the ASA does some funky stuff and uses the 'outside' interface to forward the packets so on the other side you have to do some funky rules. I've been successful with doing this wi...

Resolved! Panorama on 6.1.7, can it manage 6.0.7

Hello all. Tomorrow night I will be upgrading our firewalls to 6.1.7, they (and Panorama) are currenlty on 6.0.7. Can I upgrade Panorama now and still manage the firewalls on 6.0.7 if I need to make any changes between today and tomorrow? Thanks!

ldavie by L2 Linker
  • 4455 Views
  • 6 replies
  • 0 Likes

Historical report on QoS

Hi All,What methods are people using to show history reports for QoS?Are these metrics held in file/memory etc, so that they can be feed out via syslog etc into a system, so that a historical view canbe created of QoS information?I'd like to build this into PoC's, not just be able to show them during real-time, but over the period the PoC was ru...

KatanaNZ by L3 Networker
  • 5814 Views
  • 5 replies
  • 0 Likes

PANOS 7 on PA-2020 ?

Will it work ? I don't mean like is it compatible.I mean: Will it be manageable at all, seeing that version 6 is already a management nightmare ?Is anyone on PA-2020/2050 on version 7 and what are the experiences ? I see some changes that may be useful for alleviating management (eg Time-Based Log andReport Deletion), but will it be enough ?

dieter_b by L4 Transporter
  • 7714 Views
  • 9 replies
  • 0 Likes

Globalprotect still cant report missing patches on MAC OS?

The last version that didn't have this "known issue" was 2.2.0, based on release notes. Even the most recent release, 2.3.1, has bug id 77018 and wont report missing patches on the mac. Any idea when Palo will resolve this? It seems to severely limit a key feature we and others use Globalprotect as a vpn solution if one can't enforce HIP checks ...

ulti by L3 Networker
  • 3385 Views
  • 2 replies
  • 0 Likes

Device Capacity Planning

I am trying to get my head around device throughput maximums. As an example the 3020 is speced as such:2 Gbps firewall throughput(App-ID enabled1)1 Gbps threat prevention throughput500 Mbps IPSec VPN throughputAre these throughputs simultaneous? In other words, can I have 2Gbps of Firewall through put and 500Mpbs of IPsec traffic, or if I have 5...

dpayne by L1 Bithead
  • 2801 Views
  • 1 replies
  • 0 Likes

Lync Federation Traffic

Hi Guys, Recently we've configured Lync 2013 on our network. What i've noticed on the PA external firewall is the Lync federation traffic from the internal lync clients to for example 'Skype clients' on the web or other organizations is classified on the PA as 'unknown-tcp'... on port 443. Currently i've got a security policy purely allowing 'un...

  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels