General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Doubt about security rule

Hi,

I have to create a rule bidireccional between two of my servers. My question is, do i have to create two rules to allow the connection in both flows, or i could only create the rule TRUST TO DMZ and the way back would be permit too?

Its a bit trick

...

SOC_CSG by L4 Transporter
  • 1343 Views
  • 1 replies
  • 0 Likes

Resolved! security rule add web

Hi, i have to create a rule to permit my ubuntu server to take updates from es.archive.ubuntu.com and security.ubuntu.com. How can i create the rule for this two webs suing dns name?? the ips are changing so i cant use the web ips in destination....

...

SOC_CSG by L4 Transporter
  • 1966 Views
  • 2 replies
  • 0 Likes

How Does UserID work in Active-Active HA

I have found little information on how this works other than the Primary Device makes the UserID Agent connections and sends them to the secondary.

 

User to IP Mappings

What I have found which is of note is that when the primary sends the userid mappi

...

CHammock by L2 Linker
  • 1527 Views
  • 0 replies
  • 0 Likes

Rate limit port forwards

Hey guys,

Some of the iptables servers I'm replacing with Palo Alto firewall provide port forwards to RDP servers. In order to prevent abuse, they were rate limited, such that a single IP can only connect a few times before being blacklisted for a few

...

daraco by L0 Member
  • 1494 Views
  • 1 replies
  • 0 Likes

Resolved! Recommended cable length for HA

I'm unable to determine from the tech-docs if PAN has a recommended (or suggested) cable length for those cases where the HA ports are directly connected via crossover cable. Does anyone have any intel on this topic? I've set-up many HA pairs and whe

...

tommyluke by Not applicable
  • 3876 Views
  • 5 replies
  • 0 Likes

Automated alerts when Log Forwarding stops / freezes?

Hey Community -

Wondering if anyone has come up with a good way to automate an alert / alarm when there is an issue with a Firewall reporting to a DLC (distributed log collector)?  We have about 27 firewalls all of which send to 1 of 4 log collectors

...

WildFire Capacity Issues - Confirmed by Palo Alto SE

Apparently Palo Alto have confirmed that there are times when WildFire is simply too busy to serve all update requests (we've been seeing frequent failures).

Can anyone from Palo Alto comment on what the capacity situation is, what is being done to re

...

URL Filtering Log shows FORWARD

Hey All -

I have several URL-Filtering logs that come through with a category of FORWARD.  Everything else is blank (URL, From Zone, To Zone, etc.).  Can anyone shed some light on what this means?

Thanks!

Matt

Decryption certificate

Hi,

I have a PA500 (OS 5.0.11)

I already configured it for SSL Decryption with a self signed certificate.

I need to use a Digicert Certificate. I already have a wildcard certificate with Digicert.

Question is: can I use my wildcard certificate for SSL De

...

diennea by L3 Networker
  • 4354 Views
  • 5 replies
  • 0 Likes

FTP

How can I verify whether port 21 ftp traffic is being blocked by the PA 302?

infotech by L4 Transporter
  • 4908 Views
  • 17 replies
  • 0 Likes

Resolved! PA-200 - commit change and then nothing

I have opened a critical ticket, but was looking for community feedback on this issue.

Setting up my new PA-200, troubleshooting a route problem.  I removed a rule to simplify troubleshooting, hit 'commit'  The progress bar reached '98%' then the devi

...

bdunbar by L3 Networker
  • 3849 Views
  • 4 replies
  • 0 Likes

Tunnel

I have a vpn tunnel that works fine most of the time and then is just goes down for no reason any suggestion

infotech by L4 Transporter
  • 9948 Views
  • 30 replies
  • 0 Likes
  • 24195 Posts
  • 100 Subscriptions
Labels