General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4108 Views
  • 0 replies
  • 0 Likes

how to clear TCP options using Palo Alto firewalls?

At the moment we are replacing our Cisco ASA firewalls with Palo Alto firewalls and one thing we cannot still figure out is how to make the Palo Alto firewalls to clear the TCP options on TCP sessions. This can be done, in Cisco ASA firewalls, using the commands:tcp-options clear range <lower number> <higher number> clearIs there any...

netexgb by L1 Bithead
  • 6135 Views
  • 8 replies
  • 0 Likes

Resolved! L2 "switch" ports?

Hi All,Am I right in saying if I configure a selection of interfaces (in this case on a 3020) as L2, and then assign them to a VLAN with a L3 VLAN interface all those ports will sort-of act like a switch (or more likely a hub)?A bit like the handful of ports you get on some Small office firewalls (thinking Juniper SSG, sonicwall, and some fortig...

Dpeters1 by L2 Linker
  • 3636 Views
  • 2 replies
  • 0 Likes

Resolved! minimum PanOS version for UserID version

PanOS release notes call out the minimum User ID agent version supported. UserID agent release notes do not call out a minimum PanOS version. Is there any issue in getting ahead on the UserID agent version? For example, we have several devices running PanOS 5.0.4, but one cluster stuck back on 4.1.0. Can we upgrade the UserID agent to 5.0.4 with...

gmparis by Not applicable
  • 3053 Views
  • 1 replies
  • 0 Likes

Resolved! All sites registering as "unknown"

Came in today with users screaming that they were getting blocked on all websites. Finally extracted enough information from them that the category was coming up as “unknown” for all sites…even Google. Decided it had to be an issue in the URL filtering…updated to latest Brightcloud…no change.Thought URL cache or dynamic URL cache might be the ...

mmartin by L1 Bithead
  • 19939 Views
  • 34 replies
  • 1 Likes

PBF rule

Hi,Could you please help me with the below query.What exactly it happens when I enable "Disable this rule if nexthop/monitor ip is unreachable" in the PBF rule - > Forwarding Tab - > Monitor Check Box.Suppose , if the Monitored IP is not reachable , It ll fall back to routing-table. What happens if the monitored IP is reachable after some ...

Upgrade to 5.x - the good, the bad, the ugly?

OK, one for you guys who have upgraded to the 5.x stream.Ignoring the steady furore over the UserID agent and CPU issues, what are the advantages/disadvantages of upgrading from 4.1.x to 5.0.x?I have a single HA pair, no Panorama, no Wildfire subscription, using both IPSec and SSL/Global protect VPN's.Anyone willing to comment?Cheers

darren_g by L4 Transporter
  • 4267 Views
  • 5 replies
  • 0 Likes

PA 2000 platforms rebooting in our network

We have deployed around 10 pairs of PA 2000 platforms in different networks within our environment.These networks almost generate the same type of traffic. What we experience is that, these firewalls which ever is active, goes in for an automatic reboot. The traffic is not interrupted bcs of the passive device taking over.We see this in all the ...

User-ID on-box Best Practice

Hi,Can anyone clarify for me what the best practice recommendations are for the User-ID agent? Prior to V5 it was clear that they should ideally run on the domain controllers or servers close to them. However with the option of running on-box, is this now the preferred option, are there any limitations or side-effects of doing so?Thanks

djr by L4 Transporter
  • 9524 Views
  • 6 replies
  • 0 Likes

Shrew Soft VPN (XAuth) connected but no traffic

I can connect successfuly thru the Shrew Soft VPN but I cannot get access to the internet.I tried both "Obtain Topology Automatically or Tunnel All" and setting manually Remote Network Resource 0.0.0.0/0 but neither one worked.Any ideas?

nkavoulis by Not applicable
  • 3038 Views
  • 2 replies
  • 0 Likes

Resolved! multiple interfaces in a Zone

AllI only setup Vwire and Zone, Each zone has one interface. we have a few (5)zones. For examplezone1=interface1zone2=interface2, etcso user started ftp session, it will pass two zones Z1-Z2--->Z3-Z4---->ftp.sample.com, so we see two sessions for same connections. Two sessions will be contributed to connection tables. PA will inspect twic...

Resolved! Management CPU is 100%

Hi Guys,We are having an issue with the Palo Alto 2050 running OS 5.0.2. Earlier it happens when we do a commit or generating some reports. Then we cleared the all logs and update to 5.0.2 and now the Management CPU is always 100% even though we didn't do anything. Is this is a bug in 5.0.2 and does the next version 5.0.3 will fix this. Please h...

ajay by Not applicable
  • 18083 Views
  • 19 replies
  • 0 Likes

tunnel interface in PBF rule

Hi,Can anyone please help to resolve a small issues.1) Can we use tunnel interface in PBF rule if yes please provide a sample configuration.2) I have 2 ISP's terminated on my PA firewall, i require a failover to 2nd ISP if my Primary ISP is down by monitoring the Gateway of 1st ISP, how can i achieve it.ThanksRaj

Is there a way to search on the network monitor window for a particular subnet ?

Is there a way to search on a particular subnet range in the monitor / network monitor view ? This would be a great feature for us as we (Data Center) monitor the URL usage globally and would like to drill down to a single subnet (location) to view what problems there may be. We are a 24x7 shop and could use this a a tool to resolve issues on...

CJ by L0 Member
  • 3102 Views
  • 3 replies
  • 0 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels