General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Authenticating external users to firewall like Sonicwall?

Hi all,I am configuring a PA-500 for a POC exercise with a customer who is currently using a Sonicwall.While there are obviously other/better ways to accomplish this and I realize how silly this is, given the limited scope I'm presently working in, I need to find a way to replicate a feature they presently "require".In Sonicwall world, a user ou...

Resolved! Slow VPN throughput after update to 5.0.7

Hello CommunityHas anyone recognized some performance issues (extremely slow ip-sec throughput, hanging sessions) after updating to 5.0.7A Firewall reboot solves this issue, but it's coming up again after some days.Many thanksHannes

Resolved! SSL VPN

Hi,Noob question: Where is the guide for configuring SSL VPN? Can't find anything in the getting started or admin guides.TIAStuart

Wildfire flow

Hi,For the desicion flow of wildfire, where is the hash update and wildfire database update ? can someone tell the real place of both in that chart.Document's very clear but it is written before subscription service was released.WildFire Decision Flow

Resolved! Loopback Interfaces in VPNs

In my configs, I generally reference the actual egress interface on the PAN device. I have run across some configs where the original engineer tied the GP portal to a loopback interface which basically just pointed to the same IP tied to the egress interface. Is there a benefit to using the loopback instead?

SDorsey by L4 Transporter
  • 4616 Views
  • 2 replies
  • 0 Likes

PA-200 Multiple WANs

Hi,I'm getting my second WAN line installed this week and need to integrate it into my current setup on my PA-200.Ideally, I'd like the PA-200 to load balance between the two WAN interfaces so my initial thought is to add the new WAN interface into the current virtual router. Not having tried this on a PA box before, I'm wondering if there is a ...

HA Questions

Hi all,I have 2 simple questions:Q1: proper procedure to physically move the standby firewall PA3020 connected to primary firewall within the same datacenter (need to power off and move)?Q2: proper procedure to switch the primary to standby and standby to primary firewall?Thanks a lot!!Peter

Resolved! pa200 ha

Im in the process of setting up a pair of pa200 for ha, ive read through the documentation but im not clear on a few things.The PA200, if i do an update on the FW for either software of dynamic updates it uses the management port to do the work.If I configure HA I will need to use the management port and one of the ethernet ports, the other thre...

Buccaneer by L1 Bithead
  • 10125 Views
  • 12 replies
  • 0 Likes

NAT Help - Reaching DMZ Server via NAT

Hi,I'm having an issue setting up my DMZ test environment. My set up is basic and is as follows (IP information is an example) --e1/1 - Internet (1.1.1.160/28 - ISP assigned)e1/2 - Internal (10.10.10.0/24)e1/3 - DMZ (10.10.100.0/24)DMZ Web Server (Internal IP 10.10.100.10/24 with NAT rule for external IP mapping of 1.1.1.171)I've set up a NAT p...

jmeyer1 by Not applicable
  • 6192 Views
  • 5 replies
  • 0 Likes

Getting User-ID when using 802.1x Wireless

Hi,I was wondering if any of you chaps and/or chapesses have come across a problem getting the correct User-ID information when using wireless authentication.The problem I have is that I have a Palo Alto firewall that happily uses the User-ID Agent from AD/Security Event log to get User-ID information about wired connections to their network. T...

Resolved! CVE-2013-3893

What is the Vulnerability Signature status?Microsoft Security Advisory (2887505)Vulnerability in Internet Explorer Could Allow Remote Code ExecutionPublished: Tuesday, September 17, 2013https://technet.microsoft.com/en-us/security/advisory/2887505

dill by Not applicable
  • 5043 Views
  • 6 replies
  • 0 Likes
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels