General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4144 Views
  • 0 replies
  • 0 Likes

NAT Configuration: Need information

Hello everyone,I need confirmation on configuration.I attach a picture to this discussion.Can you confirm that the 2 first menstrual sufficient for the proper functioning of an email server in the DMZ (not to mention filtering rules)?Also, the first two rules can replace the last?Thank you in advance for your help.

URL Filtering - Error: Failed to get response from device server. Please try again later.

Yesterday our PAN started running very slowly i.e. lots of sites taking forever to start loading.I noticed on Dynamic Updates, for URL filtering I have this error listed:Error: Failed to get response from device server. Please try again later.If I disable URL filtering on my policies everything is working perfectly.Nothing has changed on the P...

Resolved! change application time out

Hisomeone did make modification on the time out defined in a application definitionis it the only thing to do, to modified the time out.or you have to create an application override to force this modification.thank's

Gregoux by L4 Transporter
  • 2123 Views
  • 1 replies
  • 0 Likes

Applipedia not up to date?

I've noticed the applipedia online does not contain the latest applications since the 376 update?Currently only seeing 1674 applications. Any ideas?

rds by L2 Linker
  • 2500 Views
  • 1 replies
  • 0 Likes

no wildfire log entry

Hello allI have been creating a antivirus profile with alert action for all decoder for antivirus action and wildfire action.but I tried to obtain some logs in wildfire log entrie. May be I didn't request the good file on the web? How could I proceed to populate the wildfire log entrie.thank you very much

Gregoux by L4 Transporter
  • 7580 Views
  • 15 replies
  • 0 Likes

Firewall Seems to Be resetting SSH Connections

HI,I have a problem with my Palo Alto firewall deployment were the firewall seems to be resetting all connections using port TCP 22 (SSH, SCP, SFTP). I have done packet captures on the ingress interface of the firewall and it shows as if the connection is being reset on the server side. However, packet captures on the egress interface show as if...

Resolved! Throughput

Hi,Is there a way to get system statistics session output with API ?or just throughput value ?

Resolved! Basic fundamentals

Hi,Just have some queries on Palo Alto firewalls posting some questions. Help on these is much appreciated.pi1) How to initiate a ping from GUI2) As per my knowledge Vwire Sub-interfaces must be acquiring the properties from parent interface, and we need not configure the Vwire Object for Vwire Subinterfaces. But in PAN-OS 5.0.4 even for interf...

Captive portal doesn't show with Firefox

Is anyone out there having issues getting captive portal to show when using Firefox. All I get is a blank screen, the URL does not change to the redirect address and it appears to be stuck doing something. The environment is the following:* Firefox 16 with both Windows and Mac* Captive portal using redirect mode to IP address* PAN OS 4.1.7I ap...

victormg by Not applicable
  • 3472 Views
  • 2 replies
  • 0 Likes

Resolved! Push dynamic update through Panorama

Hi all,Does anyboby know if it's possible to either push dynamic (scheduled of course, don't want to do that manually every day) update from panorama to managed palo or configure palo for requesting their dynamic update to panorama ?of course palo don't have access to the Internet but panorama has.Think the second way should be the best solution...

VinceM by L5 Sessionator
  • 4417 Views
  • 5 replies
  • 0 Likes

Just skype

Hi,An environment like LAN - PAN - Proxy - Router - Internetis there a way to block everything but allow just skype.No web browsing, nothing allowed except skype.I tried some rules but skype couldn't connect.Thanks.

Palo Alto blocking Symantec Antivirus

My URL filter on my PA2050 is blocking https://143.127.102.40/mrclean as malware-sites. This is Symantec SEP talking to the Symantec cloud. A discussion of the URIs used by Symantec is located here: Clients connecting to an IP. | Symantec Connect Community This specific IP is one of these URIs.I've checked with Brightcloud, and they have t...

EdwinD by L3 Networker
  • 2983 Views
  • 1 replies
  • 0 Likes

cluster question

Hi,Device1 ActiveDevice2 PassiveWhen a failover happens...it takes about 7-8 timeouts(45 second) : device1 passive device2 activeWhen a failover happens again it takes about 1 timeout(good time): device1 active device2 passiveAny ideas ?Thanks.

SYSTEM ALERT: Version 5.0.5

Hi All,After upgrading to version 5.0.5 i have a strange thing....---severity: highopaque: HA Group 1: Peer version of 5.0.5 not compatible with the HA2 keep-alive setting; disabling HA2 keep-alive---severity: criticalopaque: HA Group 1: All HA1 connections down----Am I missing something?Regards,Alex

Oleksandr by L3 Networker
  • 4329 Views
  • 9 replies
  • 0 Likes

Resolved! M-100 Panorama Mode Collectors in HA

Probably an obvious question but the documentation doesn't seem to reference this directly...If I have 2 x M-100s in HA, by default they are in a state where the primary is listed within the "Managed Collectors". From what I understand the logs are not sync'd between the primary and secondary - only the configuration aspect of Panorama. With t...

dmeier2 by Not applicable
  • 3376 Views
  • 2 replies
  • 0 Likes
  • 24340 Posts
  • 124 Subscriptions
Top Liked Authors
Labels