General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4139 Views
  • 0 replies
  • 0 Likes

Resolved! SSL VPN

Hi,Noob question: Where is the guide for configuring SSL VPN? Can't find anything in the getting started or admin guides.TIAStuart

Wildfire flow

Hi,For the desicion flow of wildfire, where is the hash update and wildfire database update ? can someone tell the real place of both in that chart.Document's very clear but it is written before subscription service was released.WildFire Decision Flow

Resolved! Loopback Interfaces in VPNs

In my configs, I generally reference the actual egress interface on the PAN device. I have run across some configs where the original engineer tied the GP portal to a loopback interface which basically just pointed to the same IP tied to the egress interface. Is there a benefit to using the loopback instead?

SDorsey by L4 Transporter
  • 4455 Views
  • 2 replies
  • 0 Likes

PA-200 Multiple WANs

Hi,I'm getting my second WAN line installed this week and need to integrate it into my current setup on my PA-200.Ideally, I'd like the PA-200 to load balance between the two WAN interfaces so my initial thought is to add the new WAN interface into the current virtual router. Not having tried this on a PA box before, I'm wondering if there is a ...

HA Questions

Hi all,I have 2 simple questions:Q1: proper procedure to physically move the standby firewall PA3020 connected to primary firewall within the same datacenter (need to power off and move)?Q2: proper procedure to switch the primary to standby and standby to primary firewall?Thanks a lot!!Peter

Resolved! pa200 ha

Im in the process of setting up a pair of pa200 for ha, ive read through the documentation but im not clear on a few things.The PA200, if i do an update on the FW for either software of dynamic updates it uses the management port to do the work.If I configure HA I will need to use the management port and one of the ethernet ports, the other thre...

NAT Help - Reaching DMZ Server via NAT

Hi,I'm having an issue setting up my DMZ test environment. My set up is basic and is as follows (IP information is an example) --e1/1 - Internet (1.1.1.160/28 - ISP assigned)e1/2 - Internal (10.10.10.0/24)e1/3 - DMZ (10.10.100.0/24)DMZ Web Server (Internal IP 10.10.100.10/24 with NAT rule for external IP mapping of 1.1.1.171)I've set up a NAT p...

jmeyer1 by Not applicable
  • 5664 Views
  • 5 replies
  • 0 Likes

Getting User-ID when using 802.1x Wireless

Hi,I was wondering if any of you chaps and/or chapesses have come across a problem getting the correct User-ID information when using wireless authentication.The problem I have is that I have a Palo Alto firewall that happily uses the User-ID Agent from AD/Security Event log to get User-ID information about wired connections to their network. T...

Resolved! CVE-2013-3893

What is the Vulnerability Signature status?Microsoft Security Advisory (2887505)Vulnerability in Internet Explorer Could Allow Remote Code ExecutionPublished: Tuesday, September 17, 2013https://technet.microsoft.com/en-us/security/advisory/2887505

dill by Not applicable
  • 4840 Views
  • 6 replies
  • 0 Likes

Active passive to active active mode

I have a pair of PA3020 in active-passive mode within the same datacenter pointing to the same ISP. We are planning to move the standby firewall to the new redundancy site and enable active-active mode pointing to a new redundant ISP. The 2 firewalls will be connected by dark fiber within a few kilometers. What are the best practices and steps t...

forward http request to proxy squid

Hi ,i try to forward my wifi mobile users http request to the proxy squid.i have configured the proxy squid to transparant mode (port 80)To the firewall i have 3 zone : LAN (port 1) , DMZ (port 3) and INTERNET (port2)the wifi mobile users are in zone "LAN" and my proxy squid is in zone "DMZ".When the wifi mobile users want access to internet, t...

nmaton by Not applicable
  • 7747 Views
  • 6 replies
  • 0 Likes
  • 24340 Posts
  • 124 Subscriptions
Top Liked Authors
Labels