General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.


Problem with IPSec tunnel monitor


We have an issue with one IPSec site-to-site tunnel. The PAN usually doesn't recognize when a tunnel is down. We can correct this by setting up monitors on all tunnels with a "wait-recover" action after 3 subsequent failures. This works for all


oschuler by L4 Transporter
  • 2 replies

Resolved! Viewing all URLs visited by a user

Hi there

I'm trying to track down an incident here and I'd like to get a report on a particular user for all URL activity. I've set up a custom report using the URL Log, with a time frame of the last 12 hours and added the username in via the query bu


Panorama commit devices with different results


We have a device group in Panorama with 4 devices members. When we've committed changes sometimes devices had the result "Commit succeeded with warnings", because we have some dependence warnings, but one of them has the result Commit Succeeded".


session browser source=

seeing a lot of sessions in the session-browser with a source ip of (in the internal "trust" zone) - these tend to be UDP protocols, RTP, bittorrent, skype etc and the session browser shows them not matching any rule or having any bytes.  Are


Test commnad on the nat policies


I did an upgrade from a 500 model to a 3020 model. All the configurations work just fine. The problem that I see is that I cannot test the nat-policy rules. I have the following configuration:


snat-all-LANs {

        from inside;



Resolved! NAT based on URL or FQDN

Hi, I want to make a NAT based on a URL or FQDN.

I only have one public IP but several URL that I want to NAT to different inside servers.

I have this working on a ISA and want to do the same in the PA.

I have a PA 500 with 5.0.8.

Protecting private clouds

We are in the process of testing the deployment of Internet-facing services into Azure, such that they are accessible from the public Internet via Azure but have a VPN connection back into our environment. Obviously in this scenario we must rely on M


KGC by L3 Networker
  • 2 replies

Google-calendar-base from iOS devices


I applied an SSL decrypt profile and with no blocking configuration if decryption would fail. Now I notice that on iPad with IOS7.0.x the calendar from google is not working.

It appears in the traffic log as decrypted and the application is seen on


  • 24034 Posts
  • 102 Subscriptions
Top Liked Authors