General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! 5050 and 5020 HA Setup

Is it possible to have HA successfully setup between two different platforms? In my case I have a customer with a 5020 and a 5050. I know the documentation states that it must be the same platform, but was curious if anyone has ever tried doing this. Thank you,-Louis

Resolved! Wildfire file exceptions

Hey everyone, sorry if this was posted before and missed it in searching.I am receiving an enormous number of alerts from Wildfire, due to an internal application that our desktop engineering created. Its more or less is just an exe that creates short cuts to our internal HR portal, which Wildfire believes to be malware.What I am looking for is...

jholmes by L1 Bithead
  • 8487 Views
  • 3 replies
  • 0 Likes

Resolved! Firewall Policy Management: Tufin cannot detect PAN interfaces

Hello Everybody,I am running a PoC with Tufin SecureTrack and have some problems with PAN firewalls (PA-500 and PA-2020 running PANOS 4.1.7, PA-5050 running 4.1.12).In a nutshell sounds like Tufin detects only the interfaces that in PAN XML configuration file are listed within the default vsys: <vsys> <entry name="vsys1">... ...

Bucche by L2 Linker
  • 4520 Views
  • 1 replies
  • 1 Likes

Same model for HA to functional properly?

I understand that both firewalls should have the same feature licensing for proper failover, but has anyone implemented HA successfully using two different models? 5050 and 5020 for example? I know in the documentation it states both models must be the same.

Getting device hostname from PANOS DHCP

Hi,I'm currently using the PANOS DHCP server to serve DHCP requests to our guest network, as it's seperated on it's own VLAN. I don't want any traffic from our guest network to reach our domain controllers, which serves as DHCP for our other VLAN's.There is just a couple of features that I feel like I'm missing, and I was wondering if this actua...

arvesynd by L3 Networker
  • 4669 Views
  • 2 replies
  • 0 Likes

bad vpn connectivity\packet loss ip sec vpn

HiI have configured an fixed IP sec VPN tunell on my PA 500. The tunell comes up OK, and I can ping an traceroute an IP adress on the network I am connectod too, through the vpn tunell. But Packet loss lies between 20 and 40 % running ping tests.We experience the same thing on both sides of the tunell.what can be wrong here, to me it seems like ...

knutelde by Not applicable
  • 4601 Views
  • 2 replies
  • 0 Likes

Tweaking DSRI

So I keep hearing that disabling DSRI will improve performance. I thought I read that most vendors do not even offer the option.What are some guidelines for disabling DSRI? I understand that incoming to own internal server is probably ok, but what about disabling for some client security rules. Immediate examples are trusted sites like Netfli...

BobW by L4 Transporter
  • 5793 Views
  • 3 replies
  • 0 Likes

How does it identify unknown application where about flow logic?

Hello everyone;~I am very curiousrefer to bottom image~Where is the unknown application where?I guess that PA App-id check application signatures for the first timeand than If PA doesn't know app, PA App-id might move Heuristics engine;and If PA try what could be checked at the engine;;Does PA change unknown-tcp or unknow-udp?I haven't been look...

Can a A/A Floating IP be set to the interface IP ?

Hello - In the VRRP world, I can have 2 devices active with a single IP (VRRP IP address ) active only on 1.I have a situation where I need to vsys a box (L3 & Vwire) The vwires are replacing Tipping point IDP's , with active traffic, so I need Active Active- fine..the FW vsys only needs a single address active in one interface network at...

dbrenipc by L3 Networker
  • 3257 Views
  • 2 replies
  • 0 Likes

Any experience with MediaFire?

I have an end customer who was attempting to download a file from mediafire (also known as causeway.com). His policy allows the mediafire application, and the initial connection is made, so the web site is accessible.If he is provided with a download link to a file from another user (this seems to be a common usage of this site), the connection ...

Can PAN block proxy traffic originated from other country?

Hello guysI'm trying to block some traffic originated from other country. PAN can block those traffics with its source address and regional info. But what if they use some kind of proxy(like ultra surf) to disguise its original source ip and change its ip to domestic ip , and what if they use ssl proxy? If that ssl server is in my country, its s...

JTR by Not applicable
  • 9165 Views
  • 5 replies
  • 0 Likes

Pan OS 5.0

i have set up Palo Alto to send logs to syslog server.Yesterday i have seen something unusual in THREAT,url log?The length of the URL is 1044 bytes but in the Palo Alto log i can see some of the bytes is truncated?Original URL:http://s.youtube.com/api/stats/watchtime?feature=fvwrel&rt=6.827&cos=Windows&cosver=6.1&len=300&cpn=...

Resolved! Using variable for PANOS version when using CEF (Arcsight)?

According to https://live.paloaltonetworks.com/docs/DOC-2835 the (current) certified formats for use with CEF is:TrafficCEF:0|Palo Alto Networks|PAN-OS|4.1.0|$subtype|$type|1|rt=$cef-formatted-receive_time deviceExternalId=$serial src=$src dst=$dst sourceTranslatedAddress=$natsrc destinationTranslatedAddress=$natdst cs1Label=Rule cs1=$rule suser...

mikand by L6 Presenter
  • 5106 Views
  • 4 replies
  • 0 Likes
  • 24443 Posts
  • 125 Subscriptions
Top Solution Authors
Labels