General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1804 Views
  • 0 replies
  • 0 Likes

Antivirus DB not showing up on inactive HA node

Hi,

I have a pair of PA-500 in an active/passive cluster. The Dashboard says that all content is matching between the nodes. However, if I go into Device->Dynamic Update on the secondary node, there is no Antivirus in there. I can only see it on the p

...

Resolved! Policy Based Forwarding - Enforce Symmetric Return

Hi,

I am planning a firewall migration right now and trying to solve the problem that traffic comes in through two different interfaces during the migration (Internet through old firewall, Internet through new firewall). I was looking at policy based

...

Port Forwarding Without NAT

So, I have a very interesting network.  I have a media server that is on a separate VLAN.  There is no way for me to statically configure the client(s) with a static IP (they just search for the server).  It uses tcp/32400.  Basically, my host will s

...

Resolved! NAT exclude

Hi,

is it possible to make exceptions/exclusions for a NAT rule? Think of this scenario:

  • small PA-200 setup
  • only one external/public IP address
  • that IP address is used for a lot of incoming NAT
  • the NAT rule basically forwards everything from the external
...

Best practice for demo PAN in Tap mode

Hi,

I have to demo PAN in 3 Legs firewall compose Internet, DMZ and Internal zones. so I have some question regarding to this.

1. What mode on mirror I should config on the firewall, TX or RX or TX and RX ?

2. Should I configure virtual system for each

...

Report creating Question

Hi,

I'm quite new to PAN firewalls, and I find the ACC page to be very informative and can usually find all the info I need from there.

However, I've just had the IT manager request (and omg hes not a happy camper at me) a report of the usage of our in

...

Resolved! User-ID Management Setting

In the device management settings there is now a "User-ID" checkbox.  I have looked at the administrators guide but it doesn't mention it, presumably because it is fairly new.

What does this actually control, because the user-id agent on the box works

...

djr by L4 Transporter
  • 3865 Views
  • 5 replies
  • 0 Likes

Global Protect Architecture

Guys ,

Need some guidance here . One of our client with an MPLS network wants to build a GP network . They are looking at buying a portal for a PA 5050 and have GP gateway licenses for each local box . The issue is the local boxes wre on different net

...

usvi by L3 Networker
  • 2657 Views
  • 3 replies
  • 0 Likes

Resolved! Debug Flow Basic in PAN-OS 5.0.4 (PA 2050)

I have been having problems with running Debug Flow Basic since upgrading from PAN-OS version 4.1.6 to 5.0.4.

I am using the following commands to setup my debug:

debug dataplane packet-diag set log feature flow basic

debug dataplane packet-diag set cap

...

debsPal0 by Not applicable
  • 3415 Views
  • 2 replies
  • 0 Likes

Resolved! I don't know how to set zone protection

Hi~

I have a question,,

We know that,,,

Paloalto appliance is not primary dos soultion

so one support some dos feature (TCP Flood, UDP Flood, ICMP 0 Packet someting like that etc,,)

I had poc from customer site

I set zone protection between Tap Zone and Ta

...

Resolved! DHCPv6 relay - "interface is not on"?

Hi.

I'm trying to configure DHCPv6 relay for a few interfaces. One of the interfaces works perfectly, but three others doesn't work at all.

On the interface where the relay is working I can see the traffic flow in the traffic log, but on the interfaces

...

flic by L0 Member
  • 3050 Views
  • 2 replies
  • 0 Likes

Huge data transfers between remote DC and PAN Agent

Hi Team,

We have had issue with huge data transfers between PAN agent and remote DC's

We have observed lot of data activity between the PAN Agent and other Domain Controller servers on the WAN.

For instance, in the last one hour our Router accounting

...

ta185020 by Not applicable
  • 8467 Views
  • 9 replies
  • 1 Likes

Interface L2

Hi guys i have a doubt about L2 Interface!

Palo Alto check triple hand shake when interfaces are on L2 ?

Because i have some troubles with asymetric environment and i`m planning deploy on L2.

Regards!

Thiago by L3 Networker
  • 2238 Views
  • 1 replies
  • 0 Likes
  • 24241 Posts
  • 117 Subscriptions
Top Solution Authors
Top Liked Authors
Labels