General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4441 Views
  • 0 replies
  • 0 Likes

Palo Alto support Windows Server 2012 R2?

Hi,At this moment we user Userd-ID agents on our WIndows Server 2008 R2 AD servers. But we want to upgrade all the servers to Windows Server 2012 R2. Does Palo Alto already support userd-ID agents on Windows Server 2012 R2 and what firmware needs to be installed on the firewall?

ZEBIT by L3 Networker
  • 3694 Views
  • 4 replies
  • 0 Likes

HA Split Brain After Upgrade from 5.0.8 to 6.0.3

We have a pair of 5050s that we recently tried to upgrade, however we ran into an issue where once both of the PANs were upgraded they went into split brain. Its currently setup with some basic HA active/standby settings for 5.0. so I'm not sure why this would change in 6.0.3. We had to roll back to stay within our maintance window. Has anyone e...

Palo GUI: Selecting lines (Multiselect)

Hello,I would like to put 20 FQDN Names in a Group ir directly in a policy.AAAA1AAAA2AAAA3AAAA4....AAA20You know what I mean, it takes a long time :=(( ... or there is a way how to select more names I do not know.Roman

rkra by L2 Linker
  • 3749 Views
  • 5 replies
  • 0 Likes

QoS on a sub interface

I see from previous discussion, QoS on a sub interface has been a request. I have a 3050 I'm working with and was wondering if there are any updates?

tharpham by L1 Bithead
  • 4099 Views
  • 5 replies
  • 0 Likes

Resolved! How to REJECT instead of DROP?

Try as I might, I cannot find a way to do the equivalent of the venerable iptables target REJECT --with-icmp-ureachable or --with-tcp-reset for basic firewalling on a 4020.This is handy for bouncing internal clients quickly, whereas DROP is better to make things slower for adversaries who are scanning our nets from outside.For example. If I want...

Priyan by Not applicable
  • 19733 Views
  • 11 replies
  • 1 Likes

Dynamic DNS URL Redirect Control

Hello,Most of the "Dynamic DNS" sites are categorized as Computer and Internet Info (PANDB). On occasion a device will get infected because of a Dynamic DNS redirect to a malicious site. The initial URL connection is through one of the DDNS sites. Because we allow "Computer and Internet Info", the connection is allowed to the final (malicious...

MGoodnow by L4 Transporter
  • 3117 Views
  • 1 replies
  • 0 Likes

Resolved! Is there anything in the works for pulling User-ID data directly from a MS NPS server

User-ID integration with Microsoft AD is great, and works nicely, but we have the bulk of our users using RADIUS to authenticate wirelessly with 802.1x, and we're using a Microsoft NPS server to do that job. These users' devices are not necessarily (and often are not) Windows domain computers, so the LDAP lookups aren't providing the needed info...

V-Wire Mode with trunk

Hey Guys, i am about to deploy PaloAlto 5020 in a v-wire mode with trunk on them, does any one has any known issues that i may encounterhere is the topologyCurrent: switch ====(trunk)===== cisco firewallnew: switch======(trunk)=====PaloAlto (vwire)=====(trunk)====Cisco firewall.Any help would be appreciated.Regards,~Harry

Harshit by L3 Networker
  • 2520 Views
  • 2 replies
  • 0 Likes

VPN Global Protect

Hello everbodyConfigured on a global protect our customers and all this working well, just a little problem that we try,can not send icmp packets via hostname only via IP Address, on your local network can ping both via hostname as IP Address. I'm pointing to in the policy area of internal, where is my DNS servers and the reverse of it is worki...

Need to migrate checkpoint firewall config files to palo alto xml file.

Hi All,Kindly let me know the solution for the same....Stopped the services in checkpoint using cpstop command using CLI and and targeted the folder called upgrade_tools directoryRun the command called upgrade_export and named the new export file and output came with file called .tgz successfullyUnzipped the file called Upgrade31.export.tgz and ...

Krish by Not applicable
  • 4992 Views
  • 4 replies
  • 0 Likes

ike policy

What part of the configuration on the PA matching what is called the ike policy on the Cisco?

infotech by L4 Transporter
  • 10288 Views
  • 22 replies
  • 0 Likes
  • 24375 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels