General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4117 Views
  • 0 replies
  • 0 Likes

Resolved! interface and subinterface configuration for untagged VLAN 1

I have a switch that is allowing all VLAN 1, 44, and 120. I have the following configured:on the physical interface I am using 192.168.0.1/24 which is VLAN 1created two sub interfaces for each VLANsubinterface .44 tagged 44 IP address 172.20.44.1/23sub interface .120 tagged 120 IP address 172.20.120.1/24Is this the correct configuration?

Ipsec VPN issue with checkpoint

Hi Friends,We have an IPsec VPN tunnel configured with CheckPoint firewall. Basically, when our Phase 1 expires after 24 hours, if a Phase 2 key is still within its 1 hour lifetime, we receive no response back. Only after the Phase 2 key expires and a new Phase 1 SA is negotiated that we can pass traffic. This happens every day, ...

Satish by L4 Transporter
  • 11525 Views
  • 4 replies
  • 0 Likes

Resolved! Static user-id to IP-address mapping

Hi All,Is there a way in PanOS 6.1.x to manually map a user-id to an ip-address.Or is there a way to set an IP-address to be exempt from the user-id mapping policy.I have PA-500s being staged behind a generic firewall inside a production network with a PA-3000 on the perimeter. The PA-500s NAT their external connections via the generic firewall...

Resolved! High Availability VWire

I am setting up a HA pair of 5060s in vwire mode between two Cisco ASA's and the internal switch. the ASAs are set up has HA.What is the best way to set up the 5060s in HA to ensure they notice when the ASA fails. I do not want a scenario where the ASA fails but the Palo does not. Then the secondary ASA will be active forwarding traffic to the s...

How to use Panorama to deploy standardized remote sites?

I'm looking for a way to use Panorama to deploy about 100 remote sites.Let's say that we have the following scenario:Site 01 has local subnet 192.168.101.0/24Site 02 has local subnet 192.168.102.0/24Etc through site 99 has local subnet 192.168.199.0/24On each site, .1 is the firewall, .3 through .5 are onsite resources, .6-10 are switches, .11-1...

Resolved! using url categories in security rule base blocks allowed traffic

Hey all,We have a security rulebase which is causing some bizarre issues.rule 1:trust to untrustservice: tcp-80url category: online-storageurl filtering profile: alert-allallowrule 2:trust to untrustservice: tcp-80url category: /url filtering profile: alert-allallowwhen we do some web traffic to www.bing.com we get 2 different type of resultsA) ...

mr.linus by L4 Transporter
  • 9434 Views
  • 8 replies
  • 0 Likes

DHCP not passing thru the 500 in wire mode

I am using a pa-500 as just a web proxy, I have clients sitting in different vlans connected to a ASA5512 that is acting as the router/FW and has DHCP Relay setup and was working fine. I added the PA500 between the ASA and the other network as a web proxy, since then DHCP has failed to work. The PA 500 is running in wire modeAny Suggetions

jtribble by Not applicable
  • 3438 Views
  • 2 replies
  • 0 Likes

BGP setup - "max prefixes" question

We have a pair of 7050s that are Internet-connected via three ISPs. The ISPs are sending a limited set of routes (essentially the IP space they "own) down to our border routers. We want to replace the static default route we're using with BGP between the firewall and our border routers, but the total routes come to around 100k, which is over the...

Resolved! Cannot ping PAN from srx

Hi guys,I just got my hands on a new PAN. I have setup an srx100 behind the PA-500. The interface Ethernet 2/8 is in the trust zone, is setup as a L3 interface and has an IP of 10.1.1.1. The SRX's IP is 10.1.1.2. The SRX's next-hop address is the PAN's gateway IP (10.1.1.1). A show route on the SRX confirms the route has been setup properly. Now...

Cisco Wireless Networks, ACS, Syslog-Senders, and AD Groups !

Hi,I've worked out how to recover the User ID, or UID, from a wireless network logon by sending syslog messages from the Cisco Access Control Server, or ACS, to a syslog-sender configured on my firewall. For wired connections I can recover UID and AD group membership through the PAN UID Agent and Group Mapping Settings.But I still can't figure ...

Resolved! Filename capturing not working...

Hi everyone,Is it possible to capture filenames as they are uploaded to dropbox, box.com, justcloud.com, etc...? We "should" be decrypting the traffic according to our decryption policy. Well it at least shows the flag decrypted in the packet capture. But.....I'm not seeing the filename anywhere. We'd like to know who transferred what to where a...

Crash28 by L1 Bithead
  • 4241 Views
  • 3 replies
  • 0 Likes

How to configure a pa-500 with 2 inputs

I have a PA-500 running as a web proxy, The connection from the inside is a ASA-5512 (required), except that I have 2 5512's running in active-standby failover mode. How do I connect both 5512's into the PA500 so that if a failover happens the traffic from the back 5512 is scanned?

jtribble by Not applicable
  • 7751 Views
  • 10 replies
  • 0 Likes
  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels