General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Recommended PAN-OS version

Hello, I'm running a PA-VM with PAN-OS version 10.2.X and need to check the TAC guidance for preferred / recommended version of PAN-OS I have tried to access: https://live.paloaltonetworks.com/t5/customer-resources/support-pan-os-software-release-guidance/ta-p/258304 however, it returns an "Access Denied" error. Regards,

ahammad by L0 Member
  • 6685 Views
  • 1 replies
  • 0 Likes

Palo Alto and Cisco Wireless Controller

Dear All,We have a Cisco Guest Wireless controller in the DMZ. A tunnel is established by the Cisco wireless controllers in the internal network to the wireless controller in the DMZ. The issue is the Guest users loose their connection intermittently and when our network admin, disables and enables the port of the wireless controller, the issue ...

ashraf1 by Not applicable
  • 5806 Views
  • 2 replies
  • 1 Likes

GlobalProtect has DNS issues after waking from sleep mode

GlobalProtect on Windows. User locks computer and computer goes to sleep. They return and unlock. If GlobalProtect has disconnected while in sleep mode, they user reconnects succsfully. User's drive mapping fail and apps fail. Pings name of server and that fails. PIngs IP address of server succeeds. Restarts PC and everything is fine agai...

jrauman by L2 Linker
  • 18742 Views
  • 15 replies
  • 1 Likes

Resolved! Code Recommendations

I am currently running two 1420 HA pairs at 2 different sites. Current SW version is 11.0.4 h1. I see newer versions of code out there such as 11.0.5 and 11.1.3-h1. Questions: * Do I need an upgrade * What code should I go to * If 11.1.3-h1 is recommended, can I upgrade straight to it or do I need to first upgrade to earlier versions of 11...

BRasicot by L0 Member
  • 1988 Views
  • 2 replies
  • 0 Likes

IPSEC phase 2 rekey

We are having problems with a site to site IPSEC VPN between a PA-500 and a Cisco ASA. The PA is always the initiator and the tunnel comes up and passes traffic just fine. The problem comes when the tunnel needs to rekey, basically it seems that the PA does not bother to renegotiate until between 30 and 120 seconds of the lifetime remains. Now t...

Sigma by L0 Member
  • 16355 Views
  • 6 replies
  • 0 Likes

Resolved! activated global protect portal page although only gateway was configured

Hi, I observed that our PaloAltos in our branches host the website shown in the screenshot, although only a gateway and NO portal was configured on this PaloAltos. The website looks very strange, especially with the login dialog hanging at the top of the page. We use only one global protect portal at our main location and the portal website has ...

Can't get NAT/Security rule to work with multiple ports

PA220 on PANOS 10.1.10-h5 Have an NVR that needs 6x ports accessible from the outside - 3 TCP and 3 UDP. I set up 6x new services and then put them into a service group called NVR Services. Created a security rule 'Allow incoming to NVR' from untrust zone, any address, any user, any source device to the 'Camera' security zone, destination addres...

Resolved! Global protect VPN server certificate error

Hi All, I am new to this community I am here to get some help on a issue I am experiencing with my organization vpn network gp vpn server certificate is not trusted. Here is the error screenshot. Any help to troubleshoot this issue would be greatly appreciated 👍 Regards Sanjib

image.png

GlobalProtect 6.0.8 disabling adapter issue

Hello all! I am having an issue with my GP VPN. Every few minutes, it drops my connection for about 20-30 seconds before establishing it again. Looking through the logs, it appears that something is disabling the PANGP virtual adapter and then reenabling it. Has anyone experienced this before? I've even tried going into the settings on the virtu...

Active/Passive HA L3 only using Bowtie connectivity between PA3410 and Cisco ISR4431

I have a request from my customer to implement the following HA setup where the PA 3410s are Active Passive to their partner that has 2 MPLS connections from different telcos where one side is generally the active side we'll call it Sprint and the failover side is Ma Bell. There is an image of diagram floating out there that shows bowtie looking...

br8523 by L1 Bithead
  • 2420 Views
  • 3 replies
  • 0 Likes

GlobalProtect multiple authentication profiles? External contractors, ldap users with certs

Hi 🙂 Im looking for solution. I need to configure global protect to: Login LDAP users. For ldap users it has to check if client has machine certificate on it Login external contractors. They have accounts created on palo device and there is no need to check for certificate And im stuck to be honest. Im coming from cisco networking where i can...

typovy_0-1719334094268.png
typovy_1-1719334313928.png
typovy by L0 Member
  • 2064 Views
  • 2 replies
  • 0 Likes

Resolved! Two WAN Ports on one Switch. Split of physical VPN and Internet port.

Hello, I hope theres someone here who´s more capeable than me for my problem 🙂I searched the forum and the documentations for quite a while but i cant figure it out.Current Situation: All incoming traffic gets sourced through port eth1/7 with the zone 'Untrust' and all other IPs ( XXX/29) provided from our ISP are handled via loopbacks also si...

  • 24393 Posts
  • 123 Subscriptions
Top Solution Authors
Labels