General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 1969 Views
  • 1 replies
  • 11 Likes

Resolved! OpenVPN

Hi,

Since application version 370 released, I have some trouble with openvpn :

Openvpn udp on port 443 didn't work anymore

Openvpn udp on port 1194 works

Maybe there is a bug on the new application version. Openvpn not on the default port didn't be recon

...

Policy Based Forwarding

We have a branch in a different state to which we have a DS3 MPLS circuit. We and our  branch office have there own ISP connections for Internet access. I would like to have redundancy build between both of our companies through IPSec VPN tunnel in t

...

how to clear TCP options using Palo Alto firewalls?

At the moment we are replacing our Cisco ASA firewalls with Palo Alto firewalls and one thing we cannot still figure out is how to make the Palo Alto firewalls to clear the TCP options on TCP sessions. This can be done, in Cisco ASA firewalls, using

...

netexgb by L1 Bithead
  • 3511 Views
  • 8 replies
  • 0 Likes

Resolved! L2 "switch" ports?

Hi All,

Am I right in saying if I configure a selection of interfaces (in this case on a 3020) as L2, and then assign them to a VLAN with a L3 VLAN interface all those ports will sort-of act like a switch (or more likely a hub)?

A bit like the handful

...

Dpeters1 by L2 Linker
  • 2356 Views
  • 2 replies
  • 0 Likes

Resolved! minimum PanOS version for UserID version

PanOS release notes call out the minimum User ID agent version supported. UserID agent release notes do not call out a minimum PanOS version. Is there any issue in getting ahead on the UserID agent version? For example, we have several devices runnin

...

gmparis by Not applicable
  • 2242 Views
  • 1 replies
  • 0 Likes

Resolved! All sites registering as "unknown"

Came in today with users screaming that they were getting blocked on all websites.  Finally extracted enough information from them that the category was coming up as “unknown” for all sites…even Google.  Decided it had to be an issue in the URL filte

...

mmartin by L1 Bithead
  • 11022 Views
  • 34 replies
  • 1 Likes

PBF rule

Hi,

Could you please help me with the below query.

What exactly it happens when I enable "Disable this rule if nexthop/monitor ip is unreachable" in the PBF rule - > Forwarding Tab - > Monitor Check Box.

Suppose , if the Monitored IP is not reachable ,

...

Upgrade to 5.x - the good, the bad, the ugly?

OK, one for you guys who have upgraded to the 5.x stream.

Ignoring the steady furore over the UserID agent and CPU issues, what are the advantages/disadvantages of upgrading from 4.1.x to 5.0.x?

I have a single HA pair, no Panorama, no Wildfire subscri

...

darren_g by L4 Transporter
  • 2982 Views
  • 5 replies
  • 0 Likes

PA 2000 platforms rebooting in our network

We have deployed around 10 pairs of PA 2000 platforms in different networks within our environment.

These networks almost generate the same type of traffic. What we experience is that, these firewalls which ever is active, goes in for an automatic reb

...

User-ID on-box Best Practice

Hi,

Can anyone clarify for me what the best practice recommendations are for the User-ID agent?  Prior to V5 it was clear that they should ideally run on the domain controllers or servers close to them.  However with the option of running on-box, is t

...

djr by L4 Transporter
  • 6294 Views
  • 6 replies
  • 0 Likes

Shrew Soft VPN (XAuth) connected but no traffic

  I can connect successfuly thru the Shrew Soft VPN but I cannot get access to the internet.

I tried both "Obtain Topology Automatically or Tunnel All" and setting manually Remote Network Resource 0.0.0.0/0 but neither one worked.

Any ideas?

nkavoulis by Not applicable
  • 2188 Views
  • 2 replies
  • 0 Likes

Resolved! multiple interfaces in a Zone

All

I only setup Vwire and Zone, Each zone has one interface. we have a few (5)zones. For example

zone1=interface1

zone2=interface2, etc

so user started ftp session, it will pass two zones  Z1-Z2--->Z3-Z4---->ftp.sample.com, so we see two sessions for sa

...