General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 650 Views
  • 0 replies
  • 0 Likes

Resolved! Subnetted traffic issue

I am running my PA-2050 on layer 2. The system runs great except for one issue. My wireless zones are subnetted. The PA can see the subnetted traffic, allows it to go out, but the packets get lost on the return back. I know there is nothing wrong wit

...

Global Protect fail-over in a single PA with ISP failover

Hi everyone - I have a customer who is looking to have GlobalProtect fail-over along with ISP fail-over in a single PA cluster.

Currently I am using PBF and a single VR for theI SP failover  and it works fine EXCEPT  when it fails over there is no GP

...

dbrenipc by L3 Networker
  • 2444 Views
  • 1 replies
  • 0 Likes

Resolved! Moving from 4.0 to 4.1 (affect on NetConnect users)

I'm considering moving to the latest 4.1 release from 4.0.11, but I have a large number of SSL VPN users using the NetConnect client 1.3.2.  I believe they would have to use a Global Protect client once the OS is upgraded to 4.1.  What would be the b

...

iguarino by L0 Member
  • 3096 Views
  • 3 replies
  • 0 Likes

Resolved! Internet facing interface dhcp-client inbound NAT

So,

PAN 5.0.1

eth1/1 - Layer 3 / Internal network 10.0.0.1/24

eth1/2 - Layer 3 / External network - DHCP assigned IP adress from ISP.

Outbound NAT works. Inbound NAT i simply doesnt get to work..

Used the cli command test nat-policy-match from Untrust s

...

criiser by Not applicable
  • 3991 Views
  • 4 replies
  • 0 Likes

Building ISP's Network?

My ISP gave me 2 networks.

My 64 IP one (main-net) and then a 2 IP one (link-net)that connects back to the ISP Box.

I know I could make this with a simple router/ Layer3 switch.

I have just started testing with our PS-2050.

Is there a simple way to do th

...

Resolved! Allow traffic to specific URL - Best practices

Dears,

I have 2 PA2020 implemented working as webfilter only. (virtual wire feature)

I need to implement a rule which will permit any user to access the website www.adpweb.com.br anytime...

What I did:

Rule at first position

source: any user, any zone,

de

...

Resolved! HA Active/Passive Management Design

I am testing out and setting up two PA-2020 in a HA Active/Passive setup for eventual use in our production network.  I am testing this outside of our current network infrastructure to ensure I understand the complete setup processes. I had a couple

...

cmateam by L3 Networker
  • 5480 Views
  • 6 replies
  • 0 Likes

SSH interception and server rekey

PA200 running 5.0.1-h1, SSH traffic is being intercepted to block tunneling which is working fine so far.  The issue I'm seeing is the client (Putty) is dropping the session after 60 minutes with "Server's host key did not match the signature supplie

...

rob72 by L1 Bithead
  • 2254 Views
  • 1 replies
  • 0 Likes

Resolved! I need configuration help In vwire mode ,....

Hi All,..

Kindly refer the fallowing topology, in which VLANs (ex:10 VLANs) are created and any traffic to internet is routed to the core firewall. In between core switch and firewall i have connected PaloAlto firewall in VWire mode and also have defi

...

Gururaj by L4 Transporter
  • 2910 Views
  • 2 replies
  • 0 Likes

Resolved! Dropped Sessions

I've a strange problem. My PA (5.0.1) randomly kills all sessions. This is causing me problems as all internet traffic times out during these issues.

You can see from the show system statistics screen dump below that there is 0 packets and 0Kbps thro

...

djrodb by L3 Networker
  • 3303 Views
  • 1 replies
  • 0 Likes

Resolved! Different block pages based on policy

Is there no way to have different block pages appear per policy ? We have distint needs for a few different groups of users. We need one URL block page to come up when one policy is triggered and a different block page when another policy is triggere

...

jhickey by L3 Networker
  • 4438 Views
  • 3 replies
  • 0 Likes

User-Id Agent and "login id attribute name"

Hi

In one of my customers (Pan-OS v4.0.7) with eDirectory I use User-Id Agent (v3.1.2) to get user IP addresses. In that directory I used the "Login Id Attribute Name" to specify 'CN' as the attribute to use for user account because many users didn't

...

emaneiro by Not applicable
  • 3934 Views
  • 5 replies
  • 0 Likes

global protect ssl-vpn and accessing the internet - v4.1

I have built access via global protect for remote users and all is working fine except that they cannot access the internet.

1. DNS is assigned (internal)

2. All internal network resources are accessable

3. accessable routes includes 0.0.0.0/32

Any idea

...

Marcum by Not applicable
  • 3826 Views
  • 3 replies
  • 1 Likes
  • 23947 Posts
  • 113 Subscriptions
Top Liked Authors
Labels