General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

How do people manage certificates for the MGMT interface at scale?

Wondering how other manage the SSL/TLS Service profile that you attach under Device>Setup>Management>General Settings at any sort of scale. We manage quite a few firewall, via panorama, and the intent would be for each firewall to have a unique certificate for this? Is there a way we can template this would using SCEP in some way? The...

Claw4609 by L5 Sessionator
  • 4544 Views
  • 4 replies
  • 0 Likes

checkpoint R77.30 to palo450 migration

I plan to migrate checkpoint R77.30 firewalls (40 firewalls) to Palo450 devices. checkpoint is configured in a full mesh fashion. Can someone share some ideas on the SD-WAN configuration that is required between all Palo Firewalls, with the Palo backbone designated as SD-WAN. I'm thinking like For a seamless transition, we will set up tunnels ...

PAN-OS System Log - Max MIB size reached: LLDP neighbor addition failed...

Since upgrading to 9.0.X we have been seeing these messages in the system log: subtype eq lldpseverity eq higheventid eq 'too many neighbors'description contains 'Max MIB size reached: LLDP neighbor addition failed for <REDACTED> on interface 715' What do these messages represent? Why are they a severity of "high"? How do I resolve? TIA...

Resolved! QoS on Tagged VLAN Sub-interface

Hi there,I try to implement QoS on Tagged VLAN sub-interface. Found some configuration on main interface but not sub-interface one.Any suggestion? ^^Thank you

Amnuay by Not applicable
  • 12233 Views
  • 6 replies
  • 1 Likes

HIP logs to Panorama

I am looking to export HIP logs to Panorama. Firewalls are in Active-Passive mode. Since firewall sync HIP logs in between them I was getting two logs in panorama for each log entry (one from each firewall). Even though I configured active firewall only to send HIP logs to panorama, it is getting synced with passive firewall and there by passive...

Rajesh12 by L3 Networker
  • 2263 Views
  • 1 replies
  • 1 Likes

Recommended PAN-OS version

Hello, I'm running a PA-VM with PAN-OS version 10.2.X and need to check the TAC guidance for preferred / recommended version of PAN-OS I have tried to access: https://live.paloaltonetworks.com/t5/customer-resources/support-pan-os-software-release-guidance/ta-p/258304 however, it returns an "Access Denied" error. Regards,

ahammad by L0 Member
  • 6842 Views
  • 1 replies
  • 0 Likes

Palo Alto and Cisco Wireless Controller

Dear All,We have a Cisco Guest Wireless controller in the DMZ. A tunnel is established by the Cisco wireless controllers in the internal network to the wireless controller in the DMZ. The issue is the Guest users loose their connection intermittently and when our network admin, disables and enables the port of the wireless controller, the issue ...

ashraf1 by Not applicable
  • 5876 Views
  • 2 replies
  • 1 Likes

GlobalProtect has DNS issues after waking from sleep mode

GlobalProtect on Windows. User locks computer and computer goes to sleep. They return and unlock. If GlobalProtect has disconnected while in sleep mode, they user reconnects succsfully. User's drive mapping fail and apps fail. Pings name of server and that fails. PIngs IP address of server succeeds. Restarts PC and everything is fine agai...

jrauman by L2 Linker
  • 18961 Views
  • 15 replies
  • 1 Likes

Resolved! Code Recommendations

I am currently running two 1420 HA pairs at 2 different sites. Current SW version is 11.0.4 h1. I see newer versions of code out there such as 11.0.5 and 11.1.3-h1. Questions: * Do I need an upgrade * What code should I go to * If 11.1.3-h1 is recommended, can I upgrade straight to it or do I need to first upgrade to earlier versions of 11...

BRasicot by L0 Member
  • 2033 Views
  • 2 replies
  • 0 Likes

IPSEC phase 2 rekey

We are having problems with a site to site IPSEC VPN between a PA-500 and a Cisco ASA. The PA is always the initiator and the tunnel comes up and passes traffic just fine. The problem comes when the tunnel needs to rekey, basically it seems that the PA does not bother to renegotiate until between 30 and 120 seconds of the lifetime remains. Now t...

Sigma by L0 Member
  • 16436 Views
  • 6 replies
  • 0 Likes

Resolved! activated global protect portal page although only gateway was configured

Hi, I observed that our PaloAltos in our branches host the website shown in the screenshot, although only a gateway and NO portal was configured on this PaloAltos. The website looks very strange, especially with the login dialog hanging at the top of the page. We use only one global protect portal at our main location and the portal website has ...

Can't get NAT/Security rule to work with multiple ports

PA220 on PANOS 10.1.10-h5 Have an NVR that needs 6x ports accessible from the outside - 3 TCP and 3 UDP. I set up 6x new services and then put them into a service group called NVR Services. Created a security rule 'Allow incoming to NVR' from untrust zone, any address, any user, any source device to the 'Camera' security zone, destination addres...

  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels