General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4468 Views
  • 0 replies
  • 0 Likes

My Wish for Christmas - Commit Confirmed Feature

We are newish to Palo Alto, and always working remote ( I’m based in a NOC ), other vendors have the feature were its possible to commit a config and if this is not confirmed after a period of time, the config rolls back. I cannot tell you the peace of mind this gives us that in the worst case scenario we will not find ourselves locked out of ...

wingnut by L0 Member
  • 2367 Views
  • 2 replies
  • 0 Likes

QoS Configuration for Small Upload Pipe

I am configuring QoS on a PA200 for a remote site that only has a 768Kbps upload pipe. When it comes to PA and QoS, there are a ton of config options. I just want to make sure I am configuring the correct ones.These are my goals:- RTP traffic(for VoIP and Video Teleconferencing) to have the highest priority of all traffic. When the pipe is co...

jambulo by L4 Transporter
  • 3869 Views
  • 2 replies
  • 1 Likes

EBL can be seen by PA3020 in GUI, but cannot be read in CLI

I have a pair of 3020s (configured for Active-Passive availability) and I'm trying to build an External Block List. I followed the documentation at Working with External Block List (EBL) Formats and Limitations. My EBL text file looks like this:nnn.nnn.nnn.nnn 20140514 144338where nnn is the octet of an IP address. There are several lines like t...

efritz by L1 Bithead
  • 5253 Views
  • 5 replies
  • 0 Likes

SSL VPN DMZ access issue

Hi Friends,I have configured SSL vpn with AD integration but i am not able to ping DMZ. i have all ready configure access route. please suggests what i need to do in configuration. or where i am missing.RegardsSatish

Satish by L4 Transporter
  • 5330 Views
  • 9 replies
  • 0 Likes

Wildfire Signature creation

Can someone share some facts about the process of the WF signature creation. It was promised by PAN to have a signature ready after 15Mins. a sample has been identified as malicious (Verdict Malware). My observation is that it usually takes much longer than that. We do have a WF subscription.Example in the screenshot below.

gafrol by L4 Transporter
  • 7878 Views
  • 9 replies
  • 0 Likes

Control custom domain name with gmail

Dear Friends,corporate is using a custom domain name in gmail..After opening the gmail page, user should not login to their own account in gmail..user should use their custom domain name in gmail only..How can we do this requirement in palo alto firewall..I have created regex data pattern.. but it's not working. please suggest if you have idea.R...

Satish by L4 Transporter
  • 2718 Views
  • 2 replies
  • 0 Likes

Resolved! URL block

How to send URL blocked categories log files to syslog server

KMallela by L2 Linker
  • 3002 Views
  • 2 replies
  • 0 Likes

how can I check disk enabled in log-collector?

I have configuring log-collector with Panorama.I want to check disk pair enabled on log-collector.I already know how to check Log Storage wih Panorama.But I can access to Panorama, I have not permission.So, I commanded "show log-collector detail" on Log-collector, but appeared following this message.is it trouble?I think it may have some proble...

LeeJuWon by L1 Bithead
  • 2987 Views
  • 1 replies
  • 0 Likes

Disabling ALGs other than SIP?

Hello,We're having a few issues with predict sessions begin created erroneously and unnecessarily. The SIP ALG can be disabled, but when I tried the same process for other applications (ftp, skype, rtmpe, etc), there was no ALG option. How can these ALGs be disabled?Thanks,Ross

Resolved! Zone Creation

Hello Everyone,I'm new on Palo Alto Configuration,I would like to know if it's possible to configure 2 zones for the same physical network.Use case:Ethernet 1: Zone Servers: ip: 192.168.80.254/24Ethernet 2: Zone internet 1 : 193.1.1.254/24Ethernet 3: Zone internet 1 : 193.2.1.254/24I would like to have another network 192.168.90.0/24 so that I c...

PPTP NAT and site-to-site IPSEC VPN on same IP address

Hello.I'm doing a firewall migration where i encountered a following situation:- customer has site-to-site VPNs terminated on public IP address, let's say 1.1.1.1- customer is using PPTP VPN solution which is also terminated on same IP address 1.1.1.1 and DNAT-ed to PPTP server, let's say on address 10.10.10.10- on current fw they have a DNAT ru...

santonic by L6 Presenter
  • 5278 Views
  • 4 replies
  • 0 Likes
  • 24379 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels