General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Active/Passive - Failed to check Antivirus content upgrade info due to generic communication error

I am getting a daily notification that states that Failed to check Antivirus content upgrade info due to generic communication error . I have a HA Active/Passive set up on my network. The Active is connecting to updates.paloaltonetworks.com fine and is getting the most recent verison, and there is a Green Dot that connection is okay from the Ma...

Tunnel between PaloAlto and PaloAlto

Hello,i'm trying to get this constellation running:Two PA 200 behind a DSL-Home-Router and a firewall with a fixed public IP at the passive site.This image is just an example how it looks like....First i want to get the active site ("PA-Active"; PA 200; Version 5.0.6) running...I configured the IKE Gateway, Tunnel interface and also the IPSec Tu...

Hithead by L4 Transporter
  • 9352 Views
  • 16 replies
  • 0 Likes

Site to Site VPN from PA 200 to Juniper 5GT

Hi all,Anyone have a guide on how to set site to site vpn between PA200 and Juniper 5GT?. I tried a luck but now enable to establish a connection. In Juniper the tunnel i created the status is ready.A little help please.thanks,Jun

JunNOC by Not applicable
  • 3523 Views
  • 3 replies
  • 0 Likes

Scheduled Log Export : Path

Hello Guys,Just a quick question, I tried to dig in the forums but i can't find the right answer. the guide isn't helping too.I would just like to know the configuration in adding the Path in the Schedule Log Export.What I understand in the Path is I will just have to add the path on where the file will be saved. (am i right?)so for example the ...

DHCP server and descriptions for reserved addresses

HelloI'm using dhcp server on PAN for few small LAN. I'd would like to have ability to put label for reserved addresses. I beleave that it's usable for most of us but impossible in 5.0.5 PAN.Did someone asked for such FR?With regardsSlawek

_slv_ by L4 Transporter
  • 7646 Views
  • 6 replies
  • 0 Likes

Resolved! Can you set policy based forwarding in a virtual wire deployment?

I have our PA firewall set in virtual wire deployment. Can i set PBF's so I can do things like route things like audio-streaming to a cable modem that we have attached to the firewall? I've tried and when trying to set the zone/interface it doesn't list the vwire interfaces as options.

Netwerx by L2 Linker
  • 5159 Views
  • 4 replies
  • 0 Likes

Resolved! Unable to ping the ip address assigned to untrust interface.

Anyone can help on this issue? I just set up a new PA 200 device. My problem is i am not able to reach the ip address from outside which i assigned to my Untrust interface. Outbound traffic is ok. I have full access to the internet from internal LAN.

JunNOC by Not applicable
  • 3794 Views
  • 3 replies
  • 0 Likes

vpn between nortel and PA-500

Hi All,I have nortel vpn router 1750 in our main site and PA-500 in the branch, I need ipsec tunnel between devices. Nortel has static IP, but PA dynamic. I found that Nortel has site-to-site, initiator and responder options. which option I have to use site-to site or responder? can PA become Initiator in this case?Thank you.

Aslidin by Not applicable
  • 2954 Views
  • 2 replies
  • 0 Likes

Anyone Blocked a specific file from being downloaded?

Hello All, I am wondering if there is a way to block a specific file from any internet source. We would like to block users from grabbing a specific unsupported browser. (when you have 85k+ workstations - you need to keep them uniform for supportability ) I am looking at the File Blocking option and it doesn't seem to allow for specificatio...

Art by L3 Networker
  • 8201 Views
  • 7 replies
  • 0 Likes

Resolved! page cannot be viewed properly

Hi,There is a web page that cannot be viewed properly because of ssl decryption.Decryption is made for gmail applications by using custom urlIs there a way to fix that without disabling ssl decryption ?

Resolved! DHCP Server Delay

Hey all,Has anyone ever encountered a delay when the PA is handing out DHCP? I have a test network setup to do some captive portal testing for our guest network and I'm noticing it's taking anywhere between 5 - 25 seconds to get an IP address. Wireless network is set for open with no encryption (just for testing remember).Not saying it's not s...

mrsold by Not applicable
  • 5504 Views
  • 3 replies
  • 0 Likes

Resolved! Threat Log filter by 'Name' field

I've got a potential client that is trying to filter the threat log by the threat 'Name' field. He wants to see all from a specific threat.Normally you click on the item and it puts it in the filter bar but here when you click on the name you get a pop up with the details on that threat. I've tried a bunch of combinations and can't find anythi...

icmp redirect support

Hello,simple question:Does PA devices send / support icmp redirect ?Use case:PA device is the default GW for local LAN subnet (A).PA device has a route to an another subnet (B). The next hop is on his LAN Interface.Local Clients devices has only a default GW to PA LAN Interface.From my understanding and some tests:PA device does not send ICMP re...

glebon by Not applicable
  • 7842 Views
  • 3 replies
  • 0 Likes
  • 24428 Posts
  • 125 Subscriptions
Top Solution Authors
Labels