General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 266 Views
  • 0 replies
  • 1 Likes

Cisco IPSEC VPN client connecting to PAN 4.1

Hi folks,

there were no way to establish a ipsec connection between a Cisco VPN client and PAN. I was "inspired" by the globalprotect guide but wasn't enought.

  • At the cisco vpn client side, I had configured just the ip address, the group and pwd, and n
...

robclav by Not applicable
  • 6008 Views
  • 7 replies
  • 0 Likes

Static route on Management Interface

Hi all,

how can I define an additional static route on the Management Interface?

I have a setup with a customer were the communication from the management interface to two specific IP addresses has to be routed over another next-hop which is not the de

...

Resolved! TAP Mode and IPv6

Hello Everyone,

Is it possible to monitor mirrored IPv6 traffic in TAP mode?  I have a PA-500 and it has been enabled for IPv6 firewalling.  Apart from checking this option, is there anything else that has to be done to monitor IPv6 traffic?  If it is

...

Resolved! External CA Management Certificate

Hello

Is it possible to use an external certificate from our corporate CA for the SSL Management Interface of the firewall?

I have already Imported it, and the corporate root certificate, but I don't know how to change the management interface configur

...

Resolved! Combining policies from different virtual systems

So we are migrating from ASAs to PA 5050's.  We are trying to do it with as little interruption as possible so what we did is put the PAs inline behind the ASAs using vwire.  Our thought is to build our 4 environments as separate virtual systems in o

...

Brinkman by Not applicable
  • 1864 Views
  • 1 replies
  • 1 Likes

Resolved! Firewall Configuration Essentials 101 Exam Retake Help

The end of last year I took the Firewall Configuration Essentials 101 v.4.1 exam. I didn't pass so I've spent some time studying and playing with Palo Altos. I returned to retake the exam and it doesn't show up under pending evaluations and I request

...

Resolved! Blocking lists of IPs

I'd like to block a list of IP addresses based on the ZeuS IP Blocklist.  What is the best/preferred method for doing this on the Palo Alto?  Thanks

sconley by Not applicable
  • 6180 Views
  • 5 replies
  • 1 Likes

Resolved! about control softether

Hi All,

We would like to control softether with PA5020 which runs PanOS 4.1.10, but we can not find keyword "softether" in the applications.

Anyone knows how to control softether in the PA fw?

Thanks.

Regards,

Joy

Resolved! Manually trigger a logevent for a threat or a rule?

There is a test-command one can use in the CLI to identify which security policy a specific packet will hit.

But is there also a command to issue a log-event?

For example when you are about to manually configure triggers in your logserver to react on -

...

mikand by L6 Presenter
  • 2025 Views
  • 2 replies
  • 0 Likes

Resolved! Need help with BGP in Active/Active HA

We have a pair of 5520's in Active/Active mode at a colocation facility.  The colocation facility is handing off to us 2 separate LC fiber connections, each has it's own public /30 address but utilize the same AS number for our BGP.  We have a /24 fr

...

Commit failure 4.1.10

After my Palo Alto 2050 in HA active/passive is up for about 1 week, I begin to get errors committing policies.

Management server failed to send phase 1 abourt to client logrcvr

Management server failed to send phase 1 abourt to client sslvpn

Management

...

EdwinD by L3 Networker
  • 4923 Views
  • 8 replies
  • 0 Likes

Resolved! The hunt is on - 0day for java 1.7u10

How many hours/days will it take for:

1) Wildfire customers

2) Regular customers

to get protected by a threat-db update regarding the latest 0day exploit for java 1.7u10 (and possible java 1.6u38) as descibed in:

Malware don't need Coffee: 0 day 1.7u10 s

...

mikand by L6 Presenter
  • 6329 Views
  • 14 replies
  • 2 Likes

Resolved! Upgrade Palo Alto version

Hi,

I have 2 problems:

1) I refresh the Software in my Palo Alto and i cant see the new versions 5.x. The last version that i can dowload is 4.1.11. Why i can refresh the new releases????? I attached a screenshot with the error and the succesfull conne

...

Resolved! Problem LDAP

Hi I have a problem with my firewall palo alto. I hope you can help me

I had configured an LDAP server (Active Directory) in my Palo Alto. Also I had created two Atuhentication profile. One for VPN access and another for the administration of Palo Alt

...

  • 23631 Posts
  • 107 Subscriptions
Top Liked Authors
Labels