General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

IKEv2 IPv6 tunnel with dynamic endpoint from one IP

With IPv4 it is possible to build multiple IPSec tunnels from one interface IP with dynamic/unknown destinations and separate them based on the IKE peer IDs. That configuration is accepted by the firewall.As for IPv6, as soon as one source interface is used for multiple IPSec tunnel with dynamic peers, the following error is shown during commit:...

nikoo by L3 Networker
  • 2972 Views
  • 2 replies
  • 0 Likes

Release dates for PAN-OS

Hello all, Can anyone provide me the release dates for the following in regards to PAN-OS:10.0.410.0.510.0.610.0.710.0.810.0.910.0.1010.0.1110.0.12 Thank you

jsmoove by L0 Member
  • 1249 Views
  • 2 replies
  • 0 Likes

Reverse proxy for Exchange ActiveSync

We have a Palto Alto cluster and I want to use them as reverse proxy for our Exchange inbound trafic. We activated decryption for this trafic and we want to allow only ActiveSync trafic / application. It did not work with only allow ActiveSync application, we also had to create another rule to allow web-browsing to URL */microsoft-server-activ...

karsayor by L0 Member
  • 2539 Views
  • 2 replies
  • 0 Likes

Resolved! Monitor Logs - filtering with wildcard?

Are wildcards supported now when trying to filter logs in Monitor? I saw a post from 2015 asking about it and at the time the answer was "Wildcards are not supported in the traffic log filters." Was hoping that 9 years is enough time to implement that 🙂 https://live.paloaltonetworks.com/t5/general-topics/filtering-monitor-logs-wildcards/td-...

dlcrewse by L1 Bithead
  • 3386 Views
  • 2 replies
  • 0 Likes

Allow traffic mikrotik site to site.

Hi everyone. I just installed a firewall at an office. Office A is connected to office B via two site-to-site mikrotiks.Inside office A there is a server that records the presence of office B employees.After introducing the PA440 it stopped working..Currently the firewall is configured like this:Previously the router in office A was connected di...

AlessioS by L0 Member
  • 1136 Views
  • 1 replies
  • 0 Likes

Resolved! change default static route

Hi. ethernet 1/1 > DHCP ethernet 1/2 > Static i want to dst. 172.16.1.x next hop ethernet 1/1 ///// dst. 172.16..2.x next top ethernet 1/2 for change. not use pbf rule.

qmso475_0-1712801906455.png
qmso475 by L3 Networker
  • 1969 Views
  • 2 replies
  • 0 Likes

Query related to import export config

Hi Team, We are doing a migration of the firewall from the local VM firewall to another new firewall which managed by Panaroma. We have the below question for the import and export configuration. 1) Can we export a few configurations together, like only the security rule, NAT, and IPsec configurations, and import them to other firewalls? ...

Issue Reported in PANOS 10.2.7

the client has been dragging a problem since version 10.2.4 and still sees 10.2.7. Currently the client is on one of the affected versions, PANOS 10.2.7.This prevents users from being able to disconnect from Globalprotect via passcode or password, the client requires this functionality to be able to operate its remote users. by any chance that...

F.Pinar by L3 Networker
  • 3274 Views
  • 5 replies
  • 0 Likes

Alarm failed to start grpc connection with address urlcat.hawkeye.services-edge.paloaltonetworks.com:443

Hi, We are receiving this alarm: severity: high opaque: Failed to establish GRPC connection to UrlCat service: failed to start grpc connection with address urlcat.hawkeye.services-edge.paloaltonetworks.com:443, err context deadline exceeded We tried to disable the app id cloud engine following the next procedure but the alert is still show...

BigPalo by L4 Transporter
  • 5691 Views
  • 2 replies
  • 1 Likes

Application recognition "ms-teams-audio-video"

Hello, I run into behavior that I can't explain.We make teams available on the virtual desktops (web-based & desktop app)We only want to block the use of audio and video within the functionality of both teams options. Users are not allowed to use this (due to performance reasons) In our situation we have configured ssl/tls decryption.One...

Dual VPN failover confusion...

Hello everyone, Can someone offer some clarity on my questions regarding these two Palo Alto kbs? 1. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POO0CAO&lang=en_US In the screen shot, both primary and secondary tunnels are UP. Based on what this kb is built off of (https://knowledgebase.paloaltonetworks.com/...

VK9H13 by L2 Linker
  • 8446 Views
  • 9 replies
  • 0 Likes

Resolved! failed download GlobalProtect client

Good morning. I inherited an old PA-220. I would like to try to set up a VPN, but when I try to download any version of the GlobalProtec Client, the download fails "failed to download due to generic communication error". If I try to check for updates below, this attempt also fails "failed to check upgrade info due to generic communication error,...

gnesper by L2 Linker
  • 3060 Views
  • 2 replies
  • 1 Likes

Resolved! GlobalProtect Automatic Update screenshot?

I've looked and cannot find a screenshot of what is presented when the Global Protect portal presents a new updated GP to be downloaded. Would anyone have a screenshot? I can find none in the documentation. In other words, if GP Portal is set to update with prompt what shows up? I'd like to provide some documentation to our users and I can't...

source of user-id data

I'm troubleshooting what appears to be an issue with user-id. I want to confirm I'm identifying the correct Window Event Logs the User-ID Agent captures to populate the User-ID data. I'm reviewing the logs in Splunk, so the source is shows as WinEventLog:Security. It of course contains the source IP, username, and a message indcating a logon eve...

GlobalProtect disconnecting the RDP connection when trying to connect

Hello, So I work in education and our department is currently having an issue with the most recent GlobalProtect update (6.2.2-259) pushed onto us. Some of our staff members use GlobalProtect on their work-from-home laptops and connect to their office PCs through a RDP connection. We have a document imaging software that staff use which req...

armedina by L0 Member
  • 3135 Views
  • 1 replies
  • 0 Likes
  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels