General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

URL Filter Inline Categorization SLOW/DELAY - troubleshooting?

Since updating to PAN-OS 10.2.8 (and subsequently 10.2.9-h1), we've had numerous complaints of slow website access. Outside of the firewall it works fine. I've since narrowed it down to a problem or issue with the URL Filtering Inline Categorization engine. Is there a way to troubleshoot what the hang-up is? Logs seem to tell me very little...

Resolved! Upgrading from 850s to 1410s.

Hello All! I am upgrading from 850s managed by Panorama to 1410s, managed by the same Panorama. No new interface configs, just a simple cable swap. Is there a procedure for this? Is it as simple as plugging in the new 1410s, attaching to panorama, pushing the same policy and config out to the 1410s, then swapping cables over to the new 141...

RonClark by L0 Member
  • 2392 Views
  • 1 replies
  • 0 Likes

Resolved! Scheduled Policy not terminating existing session

Hello everybody, I have a PA-220 and setup a rule that my children cannot access the internet after 8pm. This is working but only for new sessions. Existing sessions like TeamSpeak or BattleNet started before 8pm are still open. Can I somehow kill also existing sessions? Thank you

Dispaying object name in traffic monitoring

Hi, I would like to know if it's possible to display object name associated to each address in traffic logs. I cant find it in any columns but i'm wondering if there is another way to do it. In fact, we want to organise the logs to have a better visibility. Thank you

thkarim by L1 Bithead
  • 7153 Views
  • 9 replies
  • 0 Likes

setting up multiple internet connections

Translator Translator Hi everyone. I have a PA-220 firewall. It is currently connected via interface 1/8 to an internet connection that I will soon have to discontinue, and which I will call GW1 here.At the same time I activated a new internet connection that I will call GW2, connected to interface 1/7 of the firewall...

gnesper by L2 Linker
  • 5979 Views
  • 14 replies
  • 0 Likes

No logs in the monitor > traffic tab?

Hello All,1.) I have just installed Palo Alto 7.1 in Eve-NG, and made two interfaces as Vwire with zone Trust and Untrust.2.) I am able to access access everthing (e.g. internet, ping, etc.) hence policies are working fine as I have created a policy to allow everything from Trust to Untrust. However I am not able to see any Traffic logs in the...

no logs.png

Update Panorama

Did not found any email to write Palo alto PAN-OS developers that hence writing here on feedback on palo alto Panorama update. After finishing update panorama then against the version we update it gives option of "Re-Install" by clicking on that it starts reinstalling and subsequently firewall reboots. Suggestion and request - please put con...

Resolved! Port forwarding through ipsec tunnel

Hello, I have two Pa-440's. One 440 has a public static ip and the other is just dhcp as of right now. I do a site to site to site vpn working between them. I setup an original port forward on the public static ip device to a local host and it worked great. Now, I moved that host to a subnet on the public dhcp firewall. I tried s...

IPSec IKEv2 multiple events per second

Hello everyone, I see many events per second for a site-to-site IPSec tunnel and am unsure if it's normal. The below events have a severity level of informational but go over and over in a second. My question is, is it normal? if not, where should I look to fix it? What can be wrong? ikev2-nego-child-startikev2-nego-ike-startipsec-key-delete...

BGP Advertising prefix to same AS it was learned from.

I'm working on a VRF-centric DC model that utilizes a PA as the firewall platform between VRFs. One of the snags I'm hitting is that if a route is learned from R1 on an AS (say 65001), and is advertised via eBGP to the PA (AS 65002), the PA won't even attempt to advertise it to R2 (Really R1, in VRF AF - AS 65001). I can work around this by spoo...

Tyler_C by L1 Bithead
  • 23307 Views
  • 15 replies
  • 0 Likes

Unnown-TCP application "commvault"

Hi Guys, I hope you guys can help with classifying unknown traffic. I have read many forums for this topic none of which answer my specific question. I understand that should create a custom app if your application bespoke and it is unlikely that an APP-ID would be created. However, I am expereincing an issue with an application called "commv...

Resolved! How to use Seprate IPs on WAN interface of 2 Paloalto Firewall.

Im new in PaloAlto and configuring HA Active/Passive Mode with seprate IPs on WAN Interface in both Firewall, every thing is working fine but when Active Firewall 1 Syncronized with Firewall 2 its change the Firewall 2 WAN IP with Firewall 1 WAN IPs in that case my all routing to oustside is Block in Firewall 2 because it has different route out...

aamirns_0-1653313000551.png
aamirns by L1 Bithead
  • 7294 Views
  • 8 replies
  • 0 Likes

Deny any any ruleset

So if you accidentally put the any any and deny ruleset at the top of the panorama firewall and it wont let you in through the web interface. How would we be able to get into the panorama to change it back to the previous configurations??

User id integration cisco ISE

hi i did User id integration cisco ISE using syslog field identifier as article http://k12itdir.blogspot.com/2016/02/paloalto-user-id-from-cisco-ise-nodes.html?m=1 and its working fine . Problem its just send user name without domain and since i have another integration with Active Directory i got domain\username . My request how to have user fr...

mhmameen by L1 Bithead
  • 2857 Views
  • 2 replies
  • 1 Likes
  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels