General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4124 Views
  • 0 replies
  • 0 Likes

Resolved! 5060s SFP ports

Hello,I have one 5060s and I would like to know what types of fibre can support. Unfortunately I couldn't find any info in the hardware doc. Can support LX or SX fibres?Many thnaks,Thomas

BOOMMAX by Not applicable
  • 3801 Views
  • 2 replies
  • 0 Likes

Resolved! GlobalProtect 3G issue on Windows 8 pro tablet

Hi,we installed GP 1.2.1 on a Windows 8 32 bit pro tablet (thinkpad 2). With WiFi it works perfectly but when we use 3G, we can't even open the Portal website in the Internet Explorer and the GP client can't connect. I thought it could be a problem with the certificate but then it would not work with WiFi?

sboelter by L1 Bithead
  • 5736 Views
  • 5 replies
  • 0 Likes

Virtual Routers

Hi,I have the WAN it's vlan 9 with the IP x.x.9.1 and I have to give access to vlan 6 which is the part of users, the Palo Alto must make the routing, vlan 6 has the IP's: x.x.6.0/24, x.x.109.0/24, which should go out x.x.6.254.How can I do routing with the virtual routers?Thanks.Regards.

Angel by Not applicable
  • 2097 Views
  • 1 replies
  • 0 Likes

Resolved! Dynamic Updates using an Interface with dynamic IP address

Hi,I would like to know how to configure the Palo Alto Updates in Service Route Configuration using an interface with dynamic ip address?When I´m using dynamic ip the interface doesn´t appear in Device -> Setup -> Services -> Service Route Configuration.Thank you and regards,

rrunge by Not applicable
  • 3609 Views
  • 1 replies
  • 2 Likes

Resolved! AD group for administratoin using authentication through LDAP

I'm trying to authenticate an AD group for administrative access for our PA. I'm missing the last step to implement it and I may have some of the steps messed up. could someone fill in the blanks for me?Create an LDAP profileCreate an authentication profile???Sorry if this question has been covered before.Thanks

What am I doing wrong? This policy to block unknown traffic to countries outside the US.

Hi all!I have a new policy that I pushed yesterday that was a total failure and any help you can offer would be appreciated.We have a policy that looks like this:Source <Internal IP addresses>Destination <Negate Region US>Application <unknown-tcp, unknown-udp>DENYHowever, it is catching and DENYing all unknown-tcp and unknown-u...

Resolved! Problem with Panorama

Hi all,I am using Panorama 5.0.4. I have two device groups and let's say two administrators.Is it possible to grant Admin A RW permissions to Device Group A and RO to device Group B, using the same login?How can this be achieved?Any help would be appreciated.

polbank by Not applicable
  • 2149 Views
  • 1 replies
  • 0 Likes

Resolved! PA-2050 and Juniper SRX reth config

There some problems with connection user to Juniper SRX through PA-2050.The exercise is to make L2 connection between Wifi user to Juniper SRX through Palo Alto.Please give some advice to make this configuration in Palo Alto.I have no many experience this PA.Thanks in advance.

Ulugbekyu by Not applicable
  • 3116 Views
  • 2 replies
  • 0 Likes

Resolved! Could IPsecVPN use PBF instead of routing?

Hello guys.I have a question about IPSEC VPN tunnel and is IPSEC VPN can use PBF instead of routing or not.I think that tunnel interface could have ip-address (for tunnel monitoring) so I guess IPSEC VPN tunnel could use PBF instead of routing?!So I tested about that but its faild. so I wonder about it caused my missed configuration or PAN could...

ttongfly by L3 Networker
  • 4695 Views
  • 4 replies
  • 0 Likes

Layer 7 protection with custom service (port)?

I'm having a discussion with my firewall engineer about rules in the PA5020. If I define an application to be used, say SSL, and I want to run that on a random port, say 8443. When I define that port (service) 8443 and choose the Application 'ssl', does that rule say that I can run SSL over port 8443 OR does that rule say I can run any applica...

Resolved! Migrating OSPF to the Palo Alto

Hello. I am working on the initial configuration of our new palo alto's. These are not in production yet. These new firewalls will be taking over our vlan's (will be the gateway) and will be running OSPF. I will stop the ospf instance on the local router and migrate to the firewalls. I am following the "How to configure OSPF" pdf that I found he...

ldavie by L2 Linker
  • 5474 Views
  • 3 replies
  • 0 Likes

Resolved! Adding domain to username for user identification

Hello We are using RSA for user authentication with Global Protect.We need to identify the LDAP group (Windows Active Directory) the user belongs to, but It doesn't work.The reason is that the user we use for authentication doesn't include the domain and the LDAP query doen't match the right user:cscworks@pa-intx.cajamar.int(active)> show us...

iOS device "network errors" when SSL Decryption is turned on

Regarding SSL Decryption:I originally put the whole category of "social-networking" under a Decrypt rule (mainly to decrypt Facebook to block Facebook games). However, when I tested on my iPhone after that, LinkedIn, Twitter and Facebook all had "network errors" and basically wouldn't connect and pull down information. I then removed the "soci...

uscit by Not applicable
  • 3461 Views
  • 2 replies
  • 0 Likes
  • 24336 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels