General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1639 Views
  • 0 replies
  • 0 Likes

bad vpn connectivity\packet loss ip sec vpn

Hi

I have configured an fixed IP sec VPN tunell on my PA 500. The tunell comes up OK, and I can ping an traceroute an IP adress on the network I am connectod too, through the vpn tunell. But Packet loss lies between 20 and 40 % running ping tests.

We e

...

knutelde by Not applicable
  • 3890 Views
  • 2 replies
  • 0 Likes

Tweaking DSRI

So I keep hearing that disabling DSRI will improve performance.  I thought I read that most vendors do not even offer the option.

What are some guidelines for disabling DSRI?  I understand that incoming to own internal server is probably ok, but what

...

BobW by L4 Transporter
  • 4649 Views
  • 3 replies
  • 0 Likes

Can a A/A Floating IP be set to the interface IP ?

Hello - In the VRRP world, I can have 2 devices active with a single IP (VRRP IP address ) active only on 1.

I have a situation where I need to vsys a box (L3 & Vwire)    The vwires are replacing Tipping point IDP's , with active traffic, so I need Ac

...

dbrenipc by L3 Networker
  • 2865 Views
  • 2 replies
  • 0 Likes

Any experience with MediaFire?

I have an end customer who was attempting to download a file from mediafire (also known as causeway.com). His policy allows the mediafire application, and the initial connection is made, so the web site is accessible.

If he is provided with a download

...

Can PAN block proxy traffic originated from other country?

Hello guys

I'm trying to block some traffic originated from other country. PAN can block those traffics with its source address and regional info. But what if they use some kind of proxy(like ultra surf) to disguise its original source ip and change i

...

JTR by Not applicable
  • 7921 Views
  • 5 replies
  • 0 Likes

Pan OS 5.0

i have set up Palo Alto to send logs to syslog server.

Yesterday i have seen something unusual in THREAT,url log?

The length of the URL is 1044 bytes but in the Palo Alto log i can see some of the bytes is truncated?

Original URL:

http://s.youtube.com/ap

...

Resolved! Using variable for PANOS version when using CEF (Arcsight)?

According to https://live.paloaltonetworks.com/docs/DOC-2835 the (current) certified formats for use with CEF is:

Traffic

CEF:0|Palo Alto Networks|PAN-OS|4.1.0|$subtype|$type|1|rt=$cef-formatted-receive_time deviceExternalId=$serial src=$src dst=$dst s

...

mikand by L6 Presenter
  • 4360 Views
  • 4 replies
  • 0 Likes

with Net Optics bypass switch deployment

Hi,

The bypass switch detects heartbeat from Palo Alto firewall to determine if it is alive.

What happens if, by any chance,  PANOS become unresponsive but the hearbeat ping is still alive? will the bypass mode be ON?

anyone having this experience with

...

cl_wong by Not applicable
  • 2248 Views
  • 2 replies
  • 0 Likes

Resolved! copy security profiles and log options

Hey all,

Do you find it annoying you can not copy security profiles and log options the way you can copy zones, objects, user, applications and services from one security rule to another through the GUI?

Manually adding the same security profile for a

...

mr.linus by L4 Transporter
  • 2657 Views
  • 2 replies
  • 0 Likes

Resolved! DMZ or NAT for web server

Hi there,

I'm looking for some insight on the best security design for several externally accessible web applications. We have several public IP addresses available and can simply do a 1:1 NAT for each web server, put it in a DMZ, or both. Each web se

...

Resolved! panorama user for specific vsys

Hi,

we created a user with device group and template admin role(only selecting monitor allowed)

also created a user with that role and choosing only 1 vsys for access control

when we logged in with that user we can see other vsys's traffic logs which ar

...

panos by L6 Presenter
  • 2222 Views
  • 1 replies
  • 0 Likes
  • 24215 Posts
  • 117 Subscriptions
Top Solution Authors
Top Liked Authors
Labels