General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4244 Views
  • 0 replies
  • 0 Likes

Resolved! How QOS works

Heyjust trying to figure out and play with QOS for understading on how it works for ferther implementaion of QOS policyso my environment is PA-500 with 2 interfaces in VWireethernet 1/11 - vsys3-untrustethernet 1/12 - vsys3-trusthave my computer connected to vsys3-trust (eth1/12)i have configured 2 QOS profiles one for outbound QOS and one for i...

minow by L4 Transporter
  • 5340 Views
  • 1 replies
  • 0 Likes

Pre-Logon without Windows credentials

Hello,I want to test the pre-logon feature of GlobalProtect in our environment.Our clients are using two factor authentication (eToken) for the windows login. So they don't know their windows credentials.We have already installed machine certificates on our clients and the authentication with this certificate works with GlobalProtect. Also when ...

Hithead by L4 Transporter
  • 5369 Views
  • 6 replies
  • 0 Likes

Basic QoS Understanding

So, I'm trying to get a clear understanding of QoS on the PA's. Any feedback / answers would be appreciated:Maximum Egress - Straight forward - the maximum amount of traffic you are allowing out.Guaranteed Egress - This one I'm foggy on. Is it only applied during congestion? Or does it literally "carve out" that much of the pipe for that clas...

mrsold by Not applicable
  • 10934 Views
  • 6 replies
  • 0 Likes

Slow transferspeed over IPSec against ASA5510

One of our customer has a Cisco ASA 5510.We have successfully created a IPSec tunnel and traffic flows both ways, but when trying to transfer a file, the speed caps at ~300KB/s, every 4-5 packets is dropped and the latency goes from ~3ms to 90ms.Both locations has a 100/100Mbit/s access.Any good ideas?

TJ by L1 Bithead
  • 9447 Views
  • 7 replies
  • 0 Likes

User ip mapping with only Global Protect

Hi all,i have a question regarding user ip mapping when only using Global Protect to authenticate users.Without enabling any user-id agent. Neither external on a server, neither on the firewall.It works as Global Protect identifies the logged-on user and uses this information to notify the firewall to place an user-ip mapping.But I have tested t...

Resolved! Let me know how to block virus in SFTP

Hello~As title seeI would like to block virus in SFTPas far as I know SSH Proxy is same as SSL Proxyso I installed Bitvise SSH Server(Personal Version) recentlyI have confirmed be server normallyand than I configured similar as SSL way in PolicyAlso I made Certificatebut Client became bypass PAnot exchange CertificateThere is SSH Server(Linux CL...

User Activity Reports

I really need some help in the correct process of running a user activity report. I have a request to pull the last 30 days of internet activity on a particular user. Every time I attempt this, I get strange results. Either the info only goes back 3 days, or it only summarizes based on application category with no other info. Basically, I want t...

brb by Not applicable
  • 3805 Views
  • 4 replies
  • 0 Likes

Pannorama and HA Cluster

Heyi would like to know how the commit process works when i push commit on pannoaram to HA device group.1) does Panorama send the configuration to both of the device and then commit it?2) does Panorama send it only to one device and it commits it to the other device?i have a situation of a PA HA cluster, and only one device was inserted to the P...

minow by L4 Transporter
  • 4110 Views
  • 5 replies
  • 0 Likes

Destination NAT to address not in same subnet

Hello,I had a quick question about destination NATing to an address not in the same subnet as an interface on the Palo Alto. For example, let's say I have a site-to-site VPN and I am using destination NAT on one side of the tunnel. When traffic comes from one side of the tunnel to the other, destination NAT is performed. One side uses 10.124.4.5...

Accessing web systems using main office's IP trough IPSec tunnel

Hello.We have a few IPsec S-2-S tunnels with different devices on other side and all works nice, but in one of them is required, that users on other side can use internet resources (to get this sides WAN IP address and access few web systems that with restricted usage by IP's) trough main office. What would be the correct or at least theoretical...

JanisM by L2 Linker
  • 5843 Views
  • 6 replies
  • 0 Likes

Resolved! Forefront UAG Direct Access

I was wondering if anyone has deployed Microsoft Direct Access or Forefront UAG behind a Palo Alto firewall, and could share their experiences. Direct Access requires 2 consecutive public IPv4 addresses (no NAT), and we are trying to figure out the best way to route this through a PA-2020 that currently has layer 3 interfaces configured, with a...

  • 24359 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels