General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4246 Views
  • 0 replies
  • 0 Likes

Applications using non standard ports - Palo Alto best practice

Ok I'm pretty sure this has been covered elsewhere however I cannot find anything on it. Let me give you some background on the config: Currently using software version 6.0.5SSL decryption in operationTrust to Untrust traffic flow directionOk so I have a rule called "Trust Web Traffic". This rule allows any trust user to any untrust destinati...

Resolved! Site-to-Site VPN - Palo alto to Cisco Router issue

Hi guys,I'm doing a POC for S2S VPN but i cannot get it to work, I'm sure this is a simple thing i have overlooked, a ping from PC2 to PC1, the ping is encapsulated and encrypted ESP on the way over to PC1, but the return traffic is not..... i have the following topology;Now i have set up a site to site VPN from the PA to R2 with the following a...

What are these mysterious pcaps?

Hello,I've noticed a boatload of application-pcaps - between 5-15k, on days where they are captured. There are captures from most days, but not every day.As far as I know, I don't have any traffic captures enabled. All of the following show that captures are disabled:1. debug dataplane packet-diag show setting (capture and logs disabled on all...

Block specific Shared Folder

Is there a way to block access to a specific shared folder of a file server?I need to block the Access from a network , but only one shared folder of a file server.

Resolved! Moving rules

Does anyone know of a faster way to move rules within a policy other than using the buttons at the bottom of the GUI?These are quite cumbersome in a large policy.

Dz3015 by L4 Transporter
  • 5551 Views
  • 5 replies
  • 0 Likes

Resolved! Filtering disable rules in policy window

I know you can filter rules you are viewing in the policy window on many aspects but can you filter out any disabled rules so you are only looking at active ones?Is there a regex guide for the filtering in this window?Thanks

Dz3015 by L4 Transporter
  • 8560 Views
  • 3 replies
  • 0 Likes

About 2 Terabyte Local disk limitation of Panorama.

Hi, After VMware ESXi 5.5 or later ,the maximum supported VMDK size on an VMFS-5 datastore is increased to 62 T. Does it mean that Panorama can utilize more than 2 Terabyte with local disk but not to mount a NFS partition ?Have somebody try this ?Best RegardsEugene Tsai

Resolved! antivirus block action for mail protocols

Hey guys,at a customer's location we have a PA for evaluation. Now we found that 2 viruses have been reported via SMTP. The AV policy was set to block for smtp. Now the question is, how has this been treated. In the ACE exam there was the correct answer that it only alerts even if it set to block, but maybe this has changed in panos 5.0.6? Would...

vertical by L2 Linker
  • 7778 Views
  • 4 replies
  • 0 Likes

Problems creating IPSec VPN to Cisco ASA

Hi,I have been having difficulties trying to configure an IPSec tunnel between a PA500 and Cisco ASA. I can get the tunnel up as it show's as green under the IPSec section however no traffic seems to flow through the tunnel and there is no connectivity. I am essentially using the IPSec VPN to allow a GRE tunnel from a partner companies router ...

DNS Proxy doesn't work

Hi,I configured dns proxy like have been deescribe on palo-alto but it doesn't work at all.I made this steps:1 - enabled dns proxy on l3 vlan interface2 - set two dns servers to use3 - enabled cacheBut i don't see anything in dns proxy cache.Maybe i forgot something?TnxAnswer

puzzel by L0 Member
  • 4361 Views
  • 5 replies
  • 0 Likes

IP Renumbering - trying to avert a slow motion disaster

PAN-200PAN OS 6I am no networking guy, but he left, so there is me dealing with this.We've embarked on a great project to renumber our IP addresses with very little thought in advance.There aren't that many, we said. What could go wrong, we thought. Well, for starters, one host that I've cutover to the new scheme can't see 'the internet' but hi...

bdunbar by L3 Networker
  • 9205 Views
  • 11 replies
  • 1 Likes

ONE External IP to MANY Internal IP NAT

I believe I know the answer after looking around.We have NATs that work fine when it is 1to1.But what about 1 External IP that represents many Internal Hosts? We have multiple websites that when you do a lookup in DNS, they all point to a singular public facing IP. That public facing IP is represented by our ISA. External ...

greeng by L2 Linker
  • 6892 Views
  • 7 replies
  • 0 Likes

Server certificate verification failed

Hi there,I wonder if I can finally resolve my continuous problems with GP and Windows machines.I have 0 problems with Android and Apple devices but Windows XP,7,8 or 8.1 give identical outcome. Problems, Problems and more problems.Please let me start from the configuration:1.2. Gateway3. cert4. cert againHowever, each time I try to logon I conti...

Has anyone been able to correlate performance issues due to the number of security rules present?

I was thinking about writing very specific security rules for around 15 hosts. The rules would essentially whitelist traffic by destination ips and application. I am somewhat concerned that adding this many additional rules could potentially slow traffic down an appreciable amount for traffic that would match on rules below these.Has anyone ru...

bgirdner by L2 Linker
  • 3123 Views
  • 1 replies
  • 0 Likes
  • 24359 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels