General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Selective cut-paste of the config

Hi,I have to deploy 9 PA boxes. I would like to create all objects on one box and copy that section to all the boxes. How do I achieve that? The config seems to be in XML format and section cut-paste is not working on command line. So far only way I could see it working is export the config from GUI to xml format, edit whole file in notepad and ...

smunzani by Not applicable
  • 7455 Views
  • 5 replies
  • 0 Likes

Number of supported Global Protect clients per box ?

In all the specifications sheets there is a different number listed for the concurrent SSLVPN and IPSECVPN supported clients. eg. on a 5020 2,000 IPSec VPN tunnels/tunnel interfaces5,000 SSL VPN UsersI find these number very confusing :Globalprotect uses both IPSEC and SSL ( IPSEC is preferred I was told).So my question, how many globalprotect c...

Resolved! Threat Prevention Throughput

Hi,Just want to know if there is a way to see how much threat prevention throughput is consuming? The command I use to check for the current throughput is show systems statistics sessions but I believe this is for the firewall throughput. Please correct me if I'm wrong.Thanks,MBS

Blocking jar and class files. What about *.pack.gz?

To mitigate the threat of the non stop java exploits Ive started to block jar file and class files. Now in the data filter logs i spot *.jar.pack.gz files. Im wondering about a few thingsIs blocking jar and class files a good mitigation against browser based desktop java exploits (drive by's)? As far as I can tell from my research the answer is ...

choff123 by L3 Networker
  • 5362 Views
  • 3 replies
  • 0 Likes

Resolved! flow_inter_cpu_nat_mismatch

Hi All, Noticed this Global Counter incrementing on our 5060 platforms ( running 4.1.x code ). When messing with the command "set session processing-cpu" and pointing all new sessions to a single CPU the counter stop incrementing (makes sense, no inter CPU communication requred ). Is this something we should be worried about ? No issues to re...

dpenhall by L2 Linker
  • 2367 Views
  • 1 replies
  • 0 Likes

Shared Application Groups in Panorama Version 5

In Panorama Version 5 it can be configured that address and service objects are only applied to firewalls which actually need these objects because they are used in the policy. Unused objects are not pushed to the firewall. However we found out this only applies to address and service objects (as the setting "Share Unused Address and Service Obj...

Anon1 by L4 Transporter
  • 2103 Views
  • 1 replies
  • 0 Likes

GlobalProtect Vsys issue

HelloI want to configure GlobalProtect Remote Access to limit the connection to a Vsys from external administration users to just the ones that uses VPN.I have tried on a PA-200 and works but There's an error when I configure the same settings on PA-5050 with Vsys.The error message I get is:Invalid configuration. Schema verification failed.netwo...

Resolved! Routing Daemon

Hi All. Could you please let me know the routing daemon used in Palo Alto firewalls.Thanks in advance.Hari.R

Resolved! DHCP - Getting info on allocated IPs

We have our PA-500 setup on our company's public network. This network is used by employee's personal machines and clients machines when they come into our office.We have run into a few situations that we can see someone is most likely infected as the machine has been profiled by the PA-500 as transmitting threat traffic. The problem is we onl...

smithp by L0 Member
  • 2568 Views
  • 1 replies
  • 0 Likes

Need another BGP instance on Virtual Router

So I need another BGP instance on a virtual router of mine... but ive read that its not possibleAdmin GuideThe firewall provides a complete BGP implementation that includes the following features:Specification of one BGP routing instance per virtual router.Im trying to keep the cfg on my router neat and tidy. Is there an elegant way to handle th...

choff123 by L3 Networker
  • 4171 Views
  • 2 replies
  • 0 Likes

Resolved! IPSEC-Tunnel Monitoring "tunnel-status-down"

I`ve created some IPSEC-Tunnel .Now I try to monitor the connection using "Tunnel Monitor" option.During the commit off the configration to the applince I'll see in System - LOG: example: 10/10 11:26:52 vpn; informational; tunnel-status-up; VPN_TEST:t_test; Tunnel VPN_Test:t_test is up some seconds later 10/10/11:27:03 vpn; low; tunn...

Resolved! PanOS 5.0 on-device User-ID agent

Hi,I have installed a PA200 with PanOS 5.0.2 and on-device User-ID agent. I have connected my device on a network with a DC Windows 2008R2 and I have configured User Mapping and Group Mapping Settings as explained in the Getting_Started_Guide_PanOS 5.0 document, but in the Server monitoring tab the status stays on "Not connected". The MGT interf...

lauro7 by L0 Member
  • 3127 Views
  • 2 replies
  • 0 Likes

Resolved! Problem with interzone U turn NAT

Hello,I followed the instructions in the paloalto "understanding NAT-4.1RevC" pdf for implementing U turn NAT.It works when I try to access a server in the DMZ from the trusted zone via it's public untrusted IP.I have now a web server which somehow tries to do a http connect to it's own URL, which describes Case 5 in this document "server in the...

Resolved! Physical connectivity validation on passive device

Hello,We use vsys on our PaloAlto cluster. During a new vsys deployment, I would like to validate that the passive device's physical connectivity to a switch is working. But I don't wish to launch a failover just for this, because it could impact the whole cluster.Is there any way to test physical or logical interfaces connectivity without any f...

Duplem by L2 Linker
  • 4513 Views
  • 2 replies
  • 0 Likes

Resolved! GP agent takes 30 seconds to connect

HelloWe are currently testing the GlobalProtect VPN client. One issue that bothers us is that the GP agent takes more than 30 seconds to connect to the gateway. Is that really the time it takes to establish a tunnel? Our earlier PPTP solution took 1-2 seconds to connect...Our setup looks quite simple. We followed the setup in the official docume...

oschuler by L4 Transporter
  • 5022 Views
  • 4 replies
  • 0 Likes
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels