General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Linux VPN clients

Does anyone have suggestions for Linux based VPN client software to users into a Palo Alto Managed environment. The dynamics (frequent upgrades of various distributions) is causing issues with our current 3rd party commercial VPN solution. Any suggestions would be greatly appreciated. Clients are Ubuntu based laptops.Phil

HITSSEC by L4 Transporter
  • 4656 Views
  • 5 replies
  • 0 Likes

Resolved! GP - second gateway creation problem

HiI have PA200 with 5.0.5 with ateway and portal licence.On untrust interface I have /26 networkTo set up another gateway I added second IP to my untrust interface. X.X.X.141 with /32 mas - is it correct?after commit I add new gateway profile and try to add client configuration.But I cant pick a checkbuttonwhat I do wrong?I need second getway be...

_slv_ by L4 Transporter
  • 4208 Views
  • 5 replies
  • 0 Likes

Resolved! Forward DNS requests

Hi,We are looking for a way to forward All dns requests to internal DNS ip.Either client changes its ip address to public dns addresses it should be forwarded to internal.Can we do that ?We don't want to write a deny rule for public Dns requests.We don't want to enforce client's dns.

Palo Alto blocking Wii game

Hi All -Just got my Palo Alto installed last week! So far so good. Hope this is the right place to be posting...I just got a message from a student that since the firewall install, a game on his Wii U, Monster Hunter, has stopped working. He claims this game works via P2P -- I haven't not looked in to this yet. We do not block P2P, but we u...

Resolved! GP with Host detetion and auto-connect

Hi,PA 500 in 5.0.4 and GP client 1.2.3Would like to be sure, I need GP auto connexion from outside of my network and no GP in my network.Then configure my external gateway, my internal host detection. It works well.But short question do I need the GP license for that ? Normally no, just one gateway, no HIP then no license ....During my test, it ...

VinceM by L5 Sessionator
  • 6123 Views
  • 5 replies
  • 0 Likes

Loopback addresses and ARP

I'd like to terminate VPN's on lookback addresses from my public range.If my public interface is 1.1.1.1/24 and I want to terminate VPN's on .2 and .3 I create two loopback interfaces (place them in the Internet Zone) with the IP addresses of 1.1.1.2 and 1.1.1.3.Should their subnets be /24 or /32? (I've see examples here that show it configured ...

Resolved! Can firewall act as VPN client?

Wondering if we can configure a lab PA-200 to connect to a VPN concentrator on the internet using IPsec, as though it were a VPN client not a site-to-site tunnel. Not connecting to the firewall using GP, but using the firewall itself as the VPN client...and then use routing or tunnel interface to receive interesting traffic sent to firewall tha...

Nick1 by Not applicable
  • 5364 Views
  • 6 replies
  • 0 Likes

How to QOS Cisco Phones?

Architecture:Hub and Spoke, Site to Site Ipsec VPN tunnelHQ Site:ASA5520Call ManagerCisco IP PhonesRemote:PA5020No Call ManagerCisco IP PhonesRemote users connect to HQ via VPN tunnel between ASA and PAQOS Policysrc.zone Inside dst.zone Inside to match traffic over the tunnelappsrtcp, rtp and sccpThis is working pretty well. Any further advice ...

PANoJAM by Not applicable
  • 4292 Views
  • 3 replies
  • 0 Likes

Resolved! Limiting the "admin" logging sessions

Hello everyone; some of you know if there is a way to limit the admin logging sessions. This is, if I logging in the firewall with the "admin" account from the PC A; and I try to logging to the firewall with the "admin" account from the PC B too; I should be unable to do it.Thank you for your help.Best regards.

Smartekh by L1 Bithead
  • 3320 Views
  • 3 replies
  • 0 Likes

User ID agents showing as red

I have 3 separate domains on my network and they are not trusted together. On my main domain where the firewall is installed the agent shows green, however when I install the agent under the remote domains (on different subnets across the country) the icon is red. The settings match my 2 main domain controllers that are working. When I look a...

nthen by L3 Networker
  • 13581 Views
  • 22 replies
  • 0 Likes

NetConnect and GlobalProtect VPN Dual Setup in 4.0

We are still on 4.0. Is it possible to setup the GlobalProtect configuration while still in 4.0 and allowing Netconnect to continue working? This will allow us to create documentation for end users and distribute it and publish it before migrating. Thank you

parkerbc by Not applicable
  • 3844 Views
  • 3 replies
  • 0 Likes

Routing through virtual systems

Hello,I have such situation that I need to make routing through virtual system. I added a network diagram below.Maybe you guys can help me in this situation.I want that traffic from Vsys2 can access GW_default as it can Vsys1. Also I want to control traffic between zone_1 and zones_2, zones_3 .What solutions there can be ? I now that there is sh...

aaputis by L0 Member
  • 2703 Views
  • 1 replies
  • 0 Likes

Resolved! Connecting two L2 segments via PAN?

I am trying to connect two separate Layer2 segments using the same VLAN ID 569 and same IP subnet 10.10.69.0/24.The firewall has:ae1 (mode layer2) with members ethernet1/1 and ethernet1/2ae2 (mode layer2) with members ethernet1/5 and ethernet1/6VLAN 569 configured with name UC_Servers> show vlan "Unified Communications Net 569"total vlan show...

efellows by L1 Bithead
  • 4104 Views
  • 3 replies
  • 0 Likes

GlobalProtect algorithms

Hi,Does anyone know what kind of algorithms being used with GlobalProtect and how much a administrator can control this?/kristian

kristian by L3 Networker
  • 3498 Views
  • 4 replies
  • 0 Likes

Resolved! What are the available variables for response pages?

What are the available substitution keywords for the response pages? Do they differ by page?I am trying to incorporate an email with all the pertinent information to be sent to our internal systems. Unfortunately, the keywords that I have found for substitution are insuffficient. For example:<h1>Virus Download Blocked</h1><p&gt...

kpatten by Not applicable
  • 11050 Views
  • 7 replies
  • 0 Likes
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels