General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 195 Views
  • 0 replies
  • 0 Likes

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 878 Views
  • 0 replies
  • 0 Likes

Resolved! Problem connecting SSH

I have a vpn configured (PA<->PA) to manage my FWs.

The problem is that when I open a ssh to the FW ip LAN (10.105.0.7), session ssh runs successfully and I can connect to the FW. But if I open ssh to the management ip 10.98.200.16 ssh remains frozen

...

SOC_CSG by L4 Transporter
  • 17388 Views
  • 29 replies
  • 0 Likes

import config from PA-2020 to PA-3020

Hi,

I need to change a old PA_2020 with a new PA-3020 and would like to use the configuration of old device in the new firewall to avoid to do the work again..

So, Is it possible to import config file from a PA-2020 to a new PA-3020?

If yes, is there an

...

PA-500 and memory upgrade

Recently I ordered and installed the memory upgrade for my PA-500.  It was under $400, is a simple end user install and upgraded the management plane to 2gb (from 1gb).

I will not give any estimates as to improvement as I do not want to exaggerate, ho

...

BobW by L4 Transporter
  • 10069 Views
  • 16 replies
  • 1 Likes

Custom Reports by Interface

Is it possible to get custom reports for traffic on a per interface basis? The only thing remotely close that I have found is under Traffic Reports I can see ingress interfaces and egress interfaces, but all that shows me is a daily total. What I'm l

...

Resolved! Application

I am trying to block some websites such as music.yahoo.com ,mylife.com  Spaces.live.com  and Talkgadget.com . But they aren't one of the listed choices and I am unable to add them to my blocked application list. How can I do that?

infotech by L4 Transporter
  • 5250 Views
  • 11 replies
  • 0 Likes

Global Protect Pre-Authentication with public SSL cert

Folks.

My boss wants me to implement "pre-authentication" for my Global protect clients, so that they authenticate against AD before logging on to their laptops when on VPN, and ergo run login scripts, group policies etc.

I have https://live.paloaltone

...

darren_g by L4 Transporter
  • 4544 Views
  • 9 replies
  • 0 Likes

Resolved! GlobalProtect DNS server ignores the access routes

Hey all,

Just another PaloAlto funkiness I found out today...

When you configure a DNS server under the gateway configuration for GlobalProtect a route will automatically be added to route traffic to this DNS-ip through the tunnel: REGARDLESS of what y

...

mr.linus by L4 Transporter
  • 2672 Views
  • 2 replies
  • 0 Likes

Resolved! FTPS and Service - problem

Hello

I have FTP server on Debian 7 (ProFTPD 1.3.1) and security rule:

and now FTPS connection works.

With "application-default" as a service FTPS sessions hangs on listing directory and sfter some time FTP client was disconected.

I'm on 6.0.2 PAN with l

...

_slv_ by L4 Transporter
  • 10930 Views
  • 20 replies
  • 0 Likes

Resolved! Cannot run GlobalProtect Portal on preferred IP address

Please correct any wrong statements:

1. I connect my PA to the "untrust internet" via ethernet 1/1

2. My ISP assigned me 164.67.80.0/24 block of IPV4 addresses (actually this is a lie...)

3. I assigned 164.67.80.2/24 to ethernet 1/1

4. The PA is capable

...

cstech by L2 Linker
  • 3908 Views
  • 3 replies
  • 0 Likes

Mirror traffic from tunnel interfaces to SPAN port

Hello Everyone,

I'm new to the PA firewall's and trying to figure out how to monitor my tunnel interfaces, and the traffic flowing through them.

I have a PA-3020 running as an endpoint for several tunnels. I want to mirror the traffic from those tunn

...

edevansky by Not applicable
  • 5415 Views
  • 5 replies
  • 0 Likes

Destination NAT on a Vwire?

Is there documentation on how to do this?  All I have found is incomplete.  Is the Destination Zone the same or different than the Source Zone?  Do the addresses have to include the subnet mask?  Are there any complete examples available?

kentjday by L1 Bithead
  • 5558 Views
  • 10 replies
  • 0 Likes
  • 24011 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Authors
Labels