General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Getting .merged-running-config.xml from a version 7.0.2 firewall?

After upgrading a Panorama-managed firewall from 6.1.x to 7.0.2, a generated techsupport file no longer contains the .merged-running-config.xml as described in doc-7904. I need to obtain the merged configuration from a firewall managed by Panorama, but on my upgraded firewalls, the TechSupport file does not have a "saved-configs" subdirectory ...

Resolved! VPN s2s with Juniper ScreenOS with multiple networks on PA side

Hello I have to connect by ipsec vpn PA200 PANOS6.1.6 with NS5GT 6.2.0r15 ScreenOS.Problem that I have is that clients behind NS must have access to two LANs on PA and to internet throuth tunnel. LAN_A———LAN_B——— PaloAlto……….tunel_IPSec………………Netscreen———LAN_MInternet —— How to do it? At the moment I have working config like https://www.corelan...

_slv_ by L4 Transporter
  • 4978 Views
  • 4 replies
  • 0 Likes

SSL Decryption Woes

Hi, I am not able to get to https://platinum.netnames.com/ with SSL decryption on, on PAN 7.0.1 / PA-3020 (IE11 / FF40 == TLS failure). Also, speed seems capped to 3Mbit/s with some CDNs (S3 AWS). Am I missing something? thanks.

Nested groups problem

Hello all, 3 domain and single forest.(root domain) named as domainA and domainB and domainC we created 3 LDAP profile for each domain.we can see members from all domains.we can see groups for each domain also. But problem is, if we create a group named ALLVPN in root domainA and there are 3 members in this group.member1-groupC which is member ...

PanIst by L3 Networker
  • 6019 Views
  • 5 replies
  • 0 Likes

TCP Echo Service on an interface

Hi all, Is it possible to get an interface to respond to the TCP Echo Service on Port 7 via a management profile or some other way? I don't mean a ICMP echo request (Ping) but what's described here https://en.wikipedia.org/wiki/Echo_Protocol https://tools.ietf.org/html/rfc862 I have an appliance that tests network connectivity by using t...

eugenep by L3 Networker
  • 2517 Views
  • 1 replies
  • 0 Likes

brightcloud active option unavailable

Hi, We couldn't activate brightcloud url filtering with our old database.I have attached the screenshot for you reference, kindly look into it and help. with regards,Ram

PA_URL_license.png
Gururaj by L4 Transporter
  • 3506 Views
  • 3 replies
  • 0 Likes

Resolved! PA Zones

I have several subnet routed through the PA for Internet Access. All the subnets are conencted via the same NIC.I wanted to seperate the one of the subnet into a PA zone , but since it is connected to one NIC I cannot have two zones on the same NIC. Is this corerct ?

RC-BHF by L2 Linker
  • 4378 Views
  • 6 replies
  • 0 Likes

vpn s2s with Mikrotik router - proxy id problem

HelloI'm trying to connect PaloAlto PA200 PANOS 6.1.6 and Mikrotik RB951 6.32.2Phase 1 is estabilished properly but I cant get phase 2 working.Logs from Mikrotik says:Sep/22/2015 20:09:34 ipsec,debug,packet HASH computed:Sep/22/2015 20:09:34 ipsec,debug,packet f85f12d1 b77dc7a6 3690e85b ed9102d9 62f29649Sep/22/2015 20:09:34 ipsec,debug,packet ge...

_slv_ by L4 Transporter
  • 12113 Views
  • 15 replies
  • 0 Likes

PA-2020 in HA commit are just a nightmare

Dear Community, Is there a official way to improve the commit on those models ? It could take more than 15 minutes sometime, it really hard to work with those appliance.the upgrade for 3030 appliance is insane too, about 40 000 € with 3 years support. To improve the commit cmd, I have to use CLI to restart the management plane with the following...

Can you create two virtual firewalls inside one physical PA-200?

I am wondering if you can create two virtual firewalls inside one physical PA-200 box?If this is possible I would like two physical ports to be allocated to each virtual firewall. One virtual firewall and its set of ports will be for a production network and the other virtual firewall and ports will be used for a visitor network. I am trying t...

Logs related to load old configuration from Panorama

Hi all, From Panorama web interface, if I load an old committed configuration into a managed device (I mean from Panorama->Managed devices-> Backups tag), where I can see the logs related to these operations?In the local configuration system logs I can see that the operation has been done by Panorama , but from Panorama device how can I se...

JLBravo by L1 Bithead
  • 1843 Views
  • 1 replies
  • 0 Likes

Resolved! GlobalProtect connect via batch

Hello, Our GlobalProtect Agent will be installed on different kind of PCs. Some external (the PCs of some suppliers or computer maintenance), and some internal (laptops with 3G connections). So I've chose the "on-demand" connection. For the internal laptops (Windows), I'd like to do a batch to launch the 3G connection, then when it's ok to launc...

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels