General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

How to use Panorama to deploy standardized remote sites?

I'm looking for a way to use Panorama to deploy about 100 remote sites.Let's say that we have the following scenario:Site 01 has local subnet 192.168.101.0/24Site 02 has local subnet 192.168.102.0/24Etc through site 99 has local subnet 192.168.199.0/24On each site, .1 is the firewall, .3 through .5 are onsite resources, .6-10 are switches, .11-1...

Resolved! using url categories in security rule base blocks allowed traffic

Hey all,We have a security rulebase which is causing some bizarre issues.rule 1:trust to untrustservice: tcp-80url category: online-storageurl filtering profile: alert-allallowrule 2:trust to untrustservice: tcp-80url category: /url filtering profile: alert-allallowwhen we do some web traffic to www.bing.com we get 2 different type of resultsA) ...

mr.linus by L4 Transporter
  • 9844 Views
  • 8 replies
  • 0 Likes

DHCP not passing thru the 500 in wire mode

I am using a pa-500 as just a web proxy, I have clients sitting in different vlans connected to a ASA5512 that is acting as the router/FW and has DHCP Relay setup and was working fine. I added the PA500 between the ASA and the other network as a web proxy, since then DHCP has failed to work. The PA 500 is running in wire modeAny Suggetions

jtribble by Not applicable
  • 3553 Views
  • 2 replies
  • 0 Likes

BGP setup - "max prefixes" question

We have a pair of 7050s that are Internet-connected via three ISPs. The ISPs are sending a limited set of routes (essentially the IP space they "own) down to our border routers. We want to replace the static default route we're using with BGP between the firewall and our border routers, but the total routes come to around 100k, which is over the...

Resolved! Cannot ping PAN from srx

Hi guys,I just got my hands on a new PAN. I have setup an srx100 behind the PA-500. The interface Ethernet 2/8 is in the trust zone, is setup as a L3 interface and has an IP of 10.1.1.1. The SRX's IP is 10.1.1.2. The SRX's next-hop address is the PAN's gateway IP (10.1.1.1). A show route on the SRX confirms the route has been setup properly. Now...

Cisco Wireless Networks, ACS, Syslog-Senders, and AD Groups !

Hi,I've worked out how to recover the User ID, or UID, from a wireless network logon by sending syslog messages from the Cisco Access Control Server, or ACS, to a syslog-sender configured on my firewall. For wired connections I can recover UID and AD group membership through the PAN UID Agent and Group Mapping Settings.But I still can't figure ...

Resolved! Filename capturing not working...

Hi everyone,Is it possible to capture filenames as they are uploaded to dropbox, box.com, justcloud.com, etc...? We "should" be decrypting the traffic according to our decryption policy. Well it at least shows the flag decrypted in the packet capture. But.....I'm not seeing the filename anywhere. We'd like to know who transferred what to where a...

Crash28 by L1 Bithead
  • 4481 Views
  • 3 replies
  • 0 Likes

How to configure a pa-500 with 2 inputs

I have a PA-500 running as a web proxy, The connection from the inside is a ASA-5512 (required), except that I have 2 5512's running in active-standby failover mode. How do I connect both 5512's into the PA500 so that if a failover happens the traffic from the back 5512 is scanned?

jtribble by Not applicable
  • 8163 Views
  • 10 replies
  • 0 Likes

Zone Configuration

Firstly, apologies if there is already a thread on this.I have a pair of PA5020's running in HA mode with PAN-OS 6.0.5-h3When trying to create new interfaces I get the following errors Interface X has no zone configuration.Interface Y has no zone configuration After looking at other threads it says to configure the zones using the CLI However t...

JulianH by L1 Bithead
  • 2926 Views
  • 1 replies
  • 0 Likes

Panorama 6.0.4 and PA-200 6.1.0

Seems like the PA-200 will not connect to Panorama after software Update to 6.1.0Just wanted to check if this is the case. (Panorama needs to be at least 6.1.0 to get the PA with 6.1.0 connected, or if i have an other issue)thanks,Kai

MFB123 by L1 Bithead
  • 3141 Views
  • 1 replies
  • 0 Likes

Resolved! Kipmi0 process eating up to 100% cpu

Hi all,Please I would need your help. After upgrading to Panorama 7.0.1 (current PAN-OS is 7.0.0) I´m having constantly CPU peaks up to 90-100% caused by the process Kipmi0. Did anyone else have the same problem?? What this process is used for?? Is possible to re-start this process??Many thanks in advance.Marcos.

Carracido by L4 Transporter
  • 5959 Views
  • 1 replies
  • 0 Likes

GlobalProtect Prelogon - using non-cached AD account

So i 've been having some issues getting GP prelogon working correctly. As of right now - GP will make the VPN connection before logon(i am able to ping my device prior to logon) and after i login with a cached account it maintains its VPN connection and i have full network access, no issues. However, when i log in using a non-cached account - ...

sross79 by L1 Bithead
  • 7915 Views
  • 7 replies
  • 0 Likes

VPN flapping

Hi, we have configured a VPN site-to-site between Juniper SSG and PA3020. The tunnel is flapping up/down. The VPN is well-configured and we have configured VPN monitor with Rekey option in the SSG. How could we know why the tunnel is flapping all the time??? i attached the PA logs2015-07-30 16:52:11 [PROTO_NOTIFY]: ====> PHASE-2 NEGOTIATION...

SOC_CSG by L4 Transporter
  • 5416 Views
  • 2 replies
  • 0 Likes
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels