General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4237 Views
  • 0 replies
  • 0 Likes

SSL Decryption and Cisco Jabber client

We currently use Cisco Webex for desktop sharing, video conferencing and IM. Our environment has mostly people using the old Webex connect client and a few 'pilot' users of the Cisco Jabber client.Recently we implemented SSL Decryption and everything in the webex environment worked fine for the Webex connect client but people using the jabber cl...

Howto track a Public IP outside to failover in case of lose of connection ?

Hi,I have a cluster of PaloAlto 3050, I want to monitor a Public IP (by example Google.com) and in case of the PaloAlto lose the connection I want to failover to the second PaloAlto.I already monitor the Interface, but if the Interface is UP, but the after the Gateway the link is DOWN I lose the Internet Connectivity but I didn't failover to the...

GroupeE by L0 Member
  • 3148 Views
  • 2 replies
  • 0 Likes

Proxy ID's question

Can someone clarify Proxy ID's for me? From what I see they're the same thing as encryption domains? What is the syntax, does it have to be one to one: ie SIP 1.1.1.1 DIP 2.2.2.2 ...

dvlacic by Not applicable
  • 4613 Views
  • 2 replies
  • 0 Likes

Bulk Apply Profiles

Hi All,Is there any way to easily bulk-apply a threat prevention profile to a large list of Security Policies? Maybe through the CLI? We have about 600 security policies that do not have threat prevention turned on. I'd like to do so, and have the profile created, I just don't know how to apply to all of the policies.Thanks in advance,-Mike

wocomike by L1 Bithead
  • 3982 Views
  • 4 replies
  • 0 Likes

Problem with incomplete application

Hi all,I have the same problem with incomplete application.!Public zone! <====> PAN Firewall <====> INSIDE Firewall <-----> Server IP.I have nated Server IP to Public ip, and configure rule like the below.Name: (Ping) ; Src zone: (public); Src: (any); Dst zone: (any) ; Dst (any); Appliccation: (icmp, ping) ; Action: (ALLOW);I m...

Resolved! How many to need for HA3 links?

Hello,I'm going to install two PA-3050s with A-A deployment.Based on datasheet, throughput of only app-id is 4Gbps.How many to need for HA3 links? four links? more?I wonder how to calculate for it.Do you have recommendation?Please let me know it.ThanksKC Lee

Resolved! DPD check

Hello,Is there any CLI commands to check if Dead Peer Detection (DPD) is receiving/sending keepalive packets to the remote VPN peer ??Regards,HA

licenselu by L4 Transporter
  • 3656 Views
  • 2 replies
  • 0 Likes

Threats blocked by Wildfire.

How do you distinguish when a threat is being denied or blocked because of Wildfire, versus the standard antivirus definitions in the PA firewall?

Netwerx by L2 Linker
  • 2195 Views
  • 1 replies
  • 0 Likes

Attention : GlobalProtect attempts to create a VPN connection

Hi there,Maybe this question is more relevant to designers of Android Operating System, but I will try with Palo Alto first.I've got Nexus 5 Phone, and Android KitKat 4.4I would like to make Android Phone to connect automatically to VPN and I managed to make single sign-on in a way that I don't have to put my user name and password.However, the ...

Throughput of an Active/Active HA pair

I believe that in an active/active HA pair the total throughput is equal to the performance of a single box, not the sum of both boxes.For the PA-5050, the throughput for an Active/Active HA pair is 5Gbps with threat prevention.Where is this documented?I need to show it to managementDave

Resolved! PA with Two ISPs NAT

Dears,We have four zone in the PA. The naming along with subnet are below mentioned.1. ISP1- 100.100.100.2/292. ISP2- 200.200.200.2/293. DMZ1- 172.16.1.1/244. DMZ2-172.10.1.1/245. Inside- 10.10.10.0/24Inside user are going to internet via ISP1 and ISP2 is used for accessing in the DMZ1 and DMZ2.Since the default route is configured towards the I...

User ID Agent

I deployed a Windows 2008 member server and installed User ID Agent 5.06 to match the code of my PAN's. I had everything working on, I was getting user ID's and everything I needed, but the issues was how much traffic the user agent generated over the Wide Area Network, for example when it queried my AD's servers for about 30 sites, in 60 Minut...

markk96 by L3 Networker
  • 2808 Views
  • 1 replies
  • 0 Likes
  • 24358 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels