General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 407 Views
  • 0 replies
  • 2 Likes

how to clear TCP options using Palo Alto firewalls?

At the moment we are replacing our Cisco ASA firewalls with Palo Alto firewalls and one thing we cannot still figure out is how to make the Palo Alto firewalls to clear the TCP options on TCP sessions. This can be done, in Cisco ASA firewalls, using

...

netexgb by L1 Bithead
  • 4537 Views
  • 8 replies
  • 0 Likes

Resolved! L2 "switch" ports?

Hi All,

Am I right in saying if I configure a selection of interfaces (in this case on a 3020) as L2, and then assign them to a VLAN with a L3 VLAN interface all those ports will sort-of act like a switch (or more likely a hub)?

A bit like the handful

...

Dpeters1 by L2 Linker
  • 2806 Views
  • 2 replies
  • 0 Likes

Resolved! minimum PanOS version for UserID version

PanOS release notes call out the minimum User ID agent version supported. UserID agent release notes do not call out a minimum PanOS version. Is there any issue in getting ahead on the UserID agent version? For example, we have several devices runnin

...

gmparis by Not applicable
  • 2562 Views
  • 1 replies
  • 0 Likes

Resolved! All sites registering as "unknown"

Came in today with users screaming that they were getting blocked on all websites.  Finally extracted enough information from them that the category was coming up as “unknown” for all sites…even Google.  Decided it had to be an issue in the URL filte

...

mmartin by L1 Bithead
  • 14379 Views
  • 34 replies
  • 1 Likes

PBF rule

Hi,

Could you please help me with the below query.

What exactly it happens when I enable "Disable this rule if nexthop/monitor ip is unreachable" in the PBF rule - > Forwarding Tab - > Monitor Check Box.

Suppose , if the Monitored IP is not reachable ,

...

Upgrade to 5.x - the good, the bad, the ugly?

OK, one for you guys who have upgraded to the 5.x stream.

Ignoring the steady furore over the UserID agent and CPU issues, what are the advantages/disadvantages of upgrading from 4.1.x to 5.0.x?

I have a single HA pair, no Panorama, no Wildfire subscri

...

darren_g by L4 Transporter
  • 3421 Views
  • 5 replies
  • 0 Likes

PA 2000 platforms rebooting in our network

We have deployed around 10 pairs of PA 2000 platforms in different networks within our environment.

These networks almost generate the same type of traffic. What we experience is that, these firewalls which ever is active, goes in for an automatic reb

...

User-ID on-box Best Practice

Hi,

Can anyone clarify for me what the best practice recommendations are for the User-ID agent?  Prior to V5 it was clear that they should ideally run on the domain controllers or servers close to them.  However with the option of running on-box, is t

...

djr by L4 Transporter
  • 7634 Views
  • 6 replies
  • 0 Likes

Shrew Soft VPN (XAuth) connected but no traffic

  I can connect successfuly thru the Shrew Soft VPN but I cannot get access to the internet.

I tried both "Obtain Topology Automatically or Tunnel All" and setting manually Remote Network Resource 0.0.0.0/0 but neither one worked.

Any ideas?

nkavoulis by Not applicable
  • 2502 Views
  • 2 replies
  • 0 Likes

Resolved! multiple interfaces in a Zone

All

I only setup Vwire and Zone, Each zone has one interface. we have a few (5)zones. For example

zone1=interface1

zone2=interface2, etc

so user started ftp session, it will pass two zones  Z1-Z2--->Z3-Z4---->ftp.sample.com, so we see two sessions for sa

...

Resolved! Management CPU is 100%

Hi Guys,

We are having an issue with the Palo Alto 2050 running OS 5.0.2. Earlier it happens when we do a commit or generating some reports. Then we cleared the all logs and update to 5.0.2 and now the Management CPU is always 100% even though we didn

...

ajay by Not applicable
  • 14578 Views
  • 19 replies
  • 0 Likes

tunnel interface in PBF rule

Hi,

Can anyone please help to resolve a small issues.

1) Can we use tunnel interface in PBF rule if yes please provide a sample configuration.

2) I have 2 ISP's terminated on my PA firewall, i require a failover to 2nd ISP if my Primary ISP is down by m

...

  • 23695 Posts
  • 110 Subscriptions
Top Solution Authors
Labels