General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

UDP Packet size

Does anyone know if the maximum permitted UDP packet size follow the MTU setting? or is there a specific setting for this?I need to understand if the PA automatically allows UDP packet sizes over 512 bytesThanksRod

djrodb by L3 Networker
  • 11617 Views
  • 5 replies
  • 0 Likes

Resolved! GlobalProtect portal corrupt.

Running an 2050 Active Passive HA pair.Yesterday I noticed that I couldn't login with the Globalprotect client. After some investigation I noticed that I could log in on the Globalprotect Portal web page, but after the login the page which offers the client downloads would not show up and the connection was reset after a timeout of ~30 seconds.I...

OSPF

Hi,Can anyone please help me with ospf issue iam facing.I have attached the OSPF config of Palo Alto and downstream SRX 100 devices.Iam unable to get the OSPF routes in Palo alto device. ThanksRaju

Resolved! How to generate a CSR from a Self Generated Palo Certificate

Hi There,I am struggling to generate the CSR for a self generated certificate on a Palo firewall (this is the first time I am doing it). I did look into all the documents in the knowledge base and they seemed to be very confusing. I have generated two certificates (one for captive portal and the second for SSL-VPN) using the Palo's Generate op...

Resolved! ICMP Source-Quench?

Hi,In Cisco ACLs, they have the option of adding rules like "access-list OUTSIDE extended permit icmp any any source-quench". Does Palo Alto have a way of distinquishing ICMP message types? I've tried looking in the application library, and ICMP shows up as an App (just like ping does) not nothing about Source-Quench, Time-Exceeded, Unreachable,...

Abs by L3 Networker
  • 2685 Views
  • 1 replies
  • 0 Likes

Resolved! Panorama and Threat Map

Hello togheter,few days ago we started to forwarding our logs from our PAs (located world wide) to Panorama.I really like the Threat Map under the App Scope Monitor tab.Do you know, if its possible to configuried it so, to have an overview of all PAs ww? Because actually i see the Panorama device only....THX

Hithead by L4 Transporter
  • 4307 Views
  • 4 replies
  • 0 Likes

Panorama Templates

What is the benefit of Panorama templates?It seems like when creating a template and pushing it out to a device, it doesn't warn you when you are overwriting device configuration. For example, I have a layer 3 interface 1/10 and my template has interface 1/10 for tap. When pushing the template out, it overwrites the layer 3 interface without a w...

das by Not applicable
  • 4096 Views
  • 3 replies
  • 1 Likes

Resolved! using vpnc with Palo Alto 4.1 IPSEC/Xauth

It seems like the freely and widely available vpnc client should work just fine with the palo alto ipsec/xauth setup, however I must be missing something. I have it working with IPAD with the shared secret + XAUTH with group/password, but with vpnc on linux I get this in the system log:IKE phase-1 negotiation is failed. Couldn't find configurati...

Resolved! Panorama. howto retrive old logs ?

Hi,I have panoram installed and configured. I have my PA FW that is now sending traffic logs and system logs, and threat logs to the Panorama.1. How can I configure PA FW to send URL logs to the Panorama ?? as I do not see any url logs in the panoram from the PA FW ?2. Panoram is now reading the current logs, how can I export the existing 1 mont...

ta185020 by Not applicable
  • 16406 Views
  • 8 replies
  • 0 Likes

Discover what is initiating a site-to-site VPN?

Hi folks.I have a situation with site-to-site VPN's on my Palo Alto's which I could use some help diagnosing.I have a number of remote teleworkers who have a company-provided Cisco 887 router, which is used to run a site-to-site, IPSEC VPN to link into our internal network.This works fine in 99% of cases, but there's always one with an issue.One...

darren_g by L4 Transporter
  • 11068 Views
  • 3 replies
  • 0 Likes

Resolved! QoS

Hi.Iam Raju.. Iam a beginner to palo alto networks...I have a small issue working with QoS... Can someone please help me...I have attached the configuration of my Device..Please have a look at it... the issue is device is not showing the QoS Statistics...ThanksRaju

Resolved! What is the reason for packet capture?

Hello all,We recently flattened our lab firewall and configured it as a tap firewall. It currently has only one security policy which is an allow all policy. The firewall currently has one zone and the only other non-standard default config is a handful of custom applications and application overrides.What I did was set a filter in the traffic l...

  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels