General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ethernet link speeds

I am curious what the recommended link speed settings for the various ports. The external port has to be hard speedcoded to 100/full as that is required by the ISP. The internal connection is to a gig core switch at auto detect (1000/full).Should the internal connection be set to 100/full to match the external?Thanks,Bob

BobW by L4 Transporter
  • 7086 Views
  • 5 replies
  • 0 Likes

Site to site VPN terminating in DMZ possible?

Is it possible to setup a site to site VPN and have it terminate on the DMZ interface rather than the WAN interface? We have numerous remote locations that are running small sonicwall firewalls and connecting back to our corporate site. They currently terminate on a Sonicwall, but we are migrating over to a Palo Alto unit. The reason for termina...

High Availability across a Fibre connection

We are preparing to configure High Availability in Active Active mode on our PA-2020 firewalls in London. Our first firewall sits in our main site in central London with our DR site sitting outside central London connected together via a 1Gbp Fibre.Both sites have a 200Mpb Internet connection so it would be good to make use of both. What optio...

BBHLTD by Not applicable
  • 4319 Views
  • 2 replies
  • 0 Likes

Resolved! Outbound NAT pool question

For reasons I will not go into here, I want to take outbound traffic from secure to unsecure and convert it from a many to 1 NAT rule to a many to many NAT rule. I have 1024 public IP addresses. I want to take a section of my network and provide around 1000 devices with a NAT pool of around 254 addresses. Is this possible? I've tried this...

EdwinD by L3 Networker
  • 3070 Views
  • 2 replies
  • 0 Likes

Resolved! "Stupid" Custom URL Filtering Question

If I want to block all derivations of "acme.com" in URL filtering how should I format the domain in my blocklist/custom blocking category?If I add "acme.com" then that doesn't appear to match "www.acme.com", but if I add "*.acme.com" then it doesn't match "acme.com" (although it does it that redirects to another URL such as www.acme.com).Ultimat...

apackard by L4 Transporter
  • 4333 Views
  • 5 replies
  • 0 Likes

Resolved! GlobalProtect 1.1.7 Subject Alternative Name (SAN)

I'm reading the changes to default behavior with certicifcates in the new GlobalProtect 1.1.7 and I don't know what the Subject Alternative Name (SAN) point is referring to. I generate all the certicates from the PAN firewall for the GlobaProtect authentication setup. The Common Name is clear but where do I need to check the Subject Alternative ...

frypan by L0 Member
  • 3115 Views
  • 1 replies
  • 0 Likes

url field in cutom log format ?

Hi all,I'm trying to customize the log forward to my Syslog.In syslog server profile / custom log format / threat, I definitely not succeed in finding the right field where visited website urls are stored !If somebody have an idea ?Regards,Karl

Karl by L1 Bithead
  • 5009 Views
  • 6 replies
  • 0 Likes

Resolved! GlobalProtect, enabling ipsec from outside

Hi all,I am trying to enable Global Protect. So far I've been able to connect the client to the firewall successfully. However the remote VPN client cannot talk to inside hosts. But the inside hosts can ping the remote client.After troubleshooting, I found IPSec traffic is blocked at the outside interface (which blocks everything). When I enabl...

BTS_MS by L2 Linker
  • 5134 Views
  • 4 replies
  • 0 Likes

Resolved! Harddisk Diagnostic Run test

Hi All,Have you guys any experience to do harddisk diagnostic test on PA5020? if yes, how long i should wait? because i run the box almost 4 hours but till now no response from the box. there is no progress indicator so i dont know whether it still running or not.below is the last output. could i just stop it or must wait till finish?-------Rand...

el by Not applicable
  • 7793 Views
  • 5 replies
  • 0 Likes

False Positive Virus

We use Total Defense for an antivirus program. It appears that one of the executable (both the 32 bit and 64 bit versions) in the latest update is being flagged as a virus, Virus/Win32.WGeneric.bnrd, the other executable files are fine. When I look at the Data Filtering log for Wildfire I see it says that it was forwarded. But when I look at ...

rgreens by L2 Linker
  • 5407 Views
  • 3 replies
  • 0 Likes

Resolved! Problem with Captive Portal authenticated by User AD

Hi all,I got a problem when I use captive portal authenticated by user AD- First, I install Palo Alto User Agent on AD machine, this job worked fine. On the traffic log of PA, I saw User AD.- After that, I configure captive portal on PA and it works too, the user AD no need to login to Captive Portal (CP) and user not in AD must login via CP to ...

nguyenma by Not applicable
  • 5830 Views
  • 4 replies
  • 0 Likes

Resolved! Multiple DMZ setup question

Hello,I'm looking to create 2 dmz's on the PAN as separate networks. This is how I have it envisioned and would appreciate any feedback.1. configure two layer 3 interafaces with GW IP assigned2. assign security zone to each interface3. attach each interface to existing VR4. route internal dmz address networks to each interface in VR5. set secur...

iguarino by L0 Member
  • 5577 Views
  • 3 replies
  • 0 Likes

Resolved! PA 500 cluster synchronization failure

Hello,I've a problem with a cluster of PA500 running PANOS 4.1.8.Config File synchronization is not working between members.After a config change is done on the master, the following error message appears in the log file of the passive member:HA Group 1: Running configuration not synchronized after retriesThe only way to sync is to move on the C...

licenselu by L4 Transporter
  • 8456 Views
  • 11 replies
  • 0 Likes

Applications within SOCKS

Hi,When deploying a Palo Alto inline between a client and a SOCKS proxy that client uses, will it be able to recognize the applications accessed over the SOCKS Proxy? Or will you only see the SOCKS application being used by that client?ThanksS

dinges by L0 Member
  • 6175 Views
  • 2 replies
  • 0 Likes
  • 24432 Posts
  • 125 Subscriptions
Top Solution Authors
Labels