General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4133 Views
  • 0 replies
  • 0 Likes

Global Protect Architecture

Guys ,Need some guidance here . One of our client with an MPLS network wants to build a GP network . They are looking at buying a portal for a PA 5050 and have GP gateway licenses for each local box . The issue is the local boxes wre on different networks . All the users will hit the portal and the portal will now send them to their local gatewa...

usvi by L3 Networker
  • 2934 Views
  • 3 replies
  • 0 Likes

Resolved! Debug Flow Basic in PAN-OS 5.0.4 (PA 2050)

I have been having problems with running Debug Flow Basic since upgrading from PAN-OS version 4.1.6 to 5.0.4.I am using the following commands to setup my debug:debug dataplane packet-diag set log feature flow basicdebug dataplane packet-diag set capture on(I have not applied a capture filter as this is our test PA so very little traffic being p...

debsPal0 by Not applicable
  • 3734 Views
  • 2 replies
  • 0 Likes

Resolved! I don't know how to set zone protection

Hi~I have a question,,We know that,,,Paloalto appliance is not primary dos soultionso one support some dos feature (TCP Flood, UDP Flood, ICMP 0 Packet someting like that etc,,)I had poc from customer siteI set zone protection between Tap Zone and Tap zonecustomer asked me;;why is palaalto do not represent about source ip and dst ip,,,also I don...

Resolved! DHCPv6 relay - "interface is not on"?

Hi.I'm trying to configure DHCPv6 relay for a few interfaces. One of the interfaces works perfectly, but three others doesn't work at all.On the interface where the relay is working I can see the traffic flow in the traffic log, but on the interfaces where it doesn't work I see nothing at all in the log. I log all dropped packages.I ran a packet...

flic by L0 Member
  • 3310 Views
  • 2 replies
  • 0 Likes

Huge data transfers between remote DC and PAN Agent

Hi Team, We have had issue with huge data transfers between PAN agent and remote DC's We have observed lot of data activity between the PAN Agent and other Domain Controller servers on the WAN. For instance, in the last one hour our Router accounting, and WAN Graphs, has shown 830 Mb of file access from one of ourremote DC, which is connected vi...

ta185020 by Not applicable
  • 9345 Views
  • 9 replies
  • 1 Likes

Interface L2

Hi guys i have a doubt about L2 Interface!Palo Alto check triple hand shake when interfaces are on L2 ?Because i have some troubles with asymetric environment and i`m planning deploy on L2.Regards!

Thiago by L3 Networker
  • 2445 Views
  • 1 replies
  • 0 Likes

REST API and HA

If I use the REST API to pass user ID mappings from my RADIUS servers into the firewalls, what should I do when they are in an HA pair?Because I don't necessarily know which with be the active one, should I just write to one and if that fails, swap to the other (will work if they pass user info between them) or do I have to write all updates to ...

djr by L4 Transporter
  • 4063 Views
  • 2 replies
  • 0 Likes

How to add a PA5050 to OPManager?

Hello..I have a PA5050, and i'd like to add a PA-5050(PNAOS Ver. 4.1.9) to an OPManager. It only shows a health status after completed to add a PA5050 on an OPManager. That mean is not showing a CPU, memory and other information on the OPManager. (MIB Version is 4.1)Dose a MIB of PA-5050 not support a CPU, a memory monitor throughout the OPMana...

willstech by L3 Networker
  • 3863 Views
  • 2 replies
  • 0 Likes

GlobalProtect Gateway authentication

HelloI've noticed that the username used witch GlobalProtect Client is truncated when it has a prefix that ends with "\"It thought it could be removing the domain as I started checking witch domain\usernameBut it tried other stirngs and it happens the same:lalakers\usernameharrypotter\usernameskywalkers\usernameIs it by design? Is it possible t...

Secondary VPN peer / IPsec gateway?

I would like to configure one of our VPN tunnels to use a secondary peer IP to failover to in the event the primary goes down. So far I haven't been able to figure out how to do this by poking around in my tunnel configuration, and I can't find any documentation online or in the admin guide. I know you can do it on other firewall platforms, but ...

Resolved! PA HA Licensing

Hi,Is it possible to have two PA configured in an Active-Passive scenario with different set of licenses.1st appliance:Threat PreventionURL Filtering2nd appliance:Threat Prevention.Also, is there a different pricing criteria if the license is for the passive box?Thanks

rsaber by L1 Bithead
  • 5055 Views
  • 2 replies
  • 0 Likes

Resolved! Intermediate certs for SSL-VPN portal

Hi!I am using a DigiCert certificate for the SSL VPN portal and the management interface, and it all works well with most browsers. However the certification chain requires an intermediate CA to be trusted/sent as well, and I haven't managed to get that to work on the PAN-box.It's not a big issue as most browsers seem to be able to resolve the c...

  • 24337 Posts
  • 124 Subscriptions
Labels