General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4131 Views
  • 0 replies
  • 0 Likes

Resolved! Graph Realtime bandwidth consumed by each application

Hello,Is it possible to have a graph with the Realtime bandwidth consumed by each application in VWIRE mode ?I saw these: http://www.paloaltonetworks.com/products/QoS.htmlbut for applications, there is only a chart...Maybe is there a way to make it with the splunk tools?Regards,

Inbound NAT - Please advise

Hi,Consider the following:All traffic (0.0.0.0/0) is NAT'd as 1.1.1.1 (public)The exchange server has an inbound NAT of 1.1.1.2 (public) > 192.168.1.1 (private).Now when the exchange server makes a connection to the outside world will it be seen as 1.1.1.1 or 1.1.1.2?If it is 1.1.1.1, then I must make a reverse NAT rule for all my inbound VIP...

Resolved! Maximum Rows In Policy Editor

I am currently working within Panorama and for one device group there are over 533 rules and editing them is terribly slow. I found this document and one of the fixes mentioned was limiting the row count in the policy editor to only 100. I would love to do that but I can't seem to find where in the interface I specify this.Any help would be v...

External IPs with two ISPs

Dear all,We have a special setup on our external firewall interfaces. There are two different Internet lines from two different ISPs:The yellow line (ISP b) indiaces the main Internet line. The green one is currently only used for outgoing e-mails using the "main" IP address 212.x.x.6. Now we would like to activate an additional IP range assigne...

oschuler by L4 Transporter
  • 3016 Views
  • 2 replies
  • 0 Likes

Resolved! expanding, an expanded panorama storage

Hi,I will do follow the procedure "Expending Panorama Storage Using a Virtual Disk", admin 4.1 doc, page 270, to have a 500GB disk for log. But a question popup!! (again)Here my question : can we expend, a second time, a expanded panorama storage? And if we do this, we will still have the logs? And how?just to be more clear :- let say toda...

export all logs from PA to Panorama

Hi,I have config PA-2050 to send logs to panorama, using this doc:https://live.paloaltonetworks.com/docs/DOC-1267àBut i have old logs in PA that stay there. Just the new logs are send to panorama.There is a way to export all logs to panorama? i need to keep those log in the panorama engin for investigation purpose.thanks!

Resolved! where URL Filtering log is save?

Hi,I have transfered all logs in panorama. Im working on understanding how logs work with disk space/partition, and some questions popup in my head! :smileygrin:I know where Threat and Traffic Logs are save (in a specific partition: threat and traffic) :admin@XYZ-PAN> show system logdb-quotaQuotas: traffic: 25.00%, 2.722 GB ...

PBF on 2 internet links on same ISP

Hi,I would like use PBF to secure and share 2 internet links (same ISP)When I configure public IP on the PA interfaces I have an error due to LAN overlap.the primary link eth4 x.y.z.99/24the secondeth3 x.y.z.185/24the ISP gateway is x.y.z.254 same for both links.my lan interface eth2 192.168.2.82/19my VR : 0.0.0.0/0 eth4 next hop IP x.y.z.254Ho...

kyr-jha by L0 Member
  • 2765 Views
  • 3 replies
  • 0 Likes

Sample Configs

Are there any links or references to a complete sample config for the PA firewall? I would like to see complete NAT examples and security policies for both inbound and outbound traffic. The Understanding NAT guide covers the inbound policy but not the outbound and does not cover all security policies. Also, I am looking for examples of securi...

pko by L1 Bithead
  • 3060 Views
  • 3 replies
  • 0 Likes

Resolved! What happens if I change mgt IP?

Hi folks -Just starting to deploy over here and I'm going through some mental exercises regarding pre-staging of firewalls. I have about a dozen PAN's in my possession that I need to configure and then will ship out to branch offices... I'd like to add these firewalls to Panorama now, so will obviously need to give the firewalls a management ...

djfwsup by Not applicable
  • 3638 Views
  • 2 replies
  • 0 Likes

Globalprotect client download froze

I have encounted an issue with GlobalProtect. When I click any of the 3 download links of GlobalProtect Agent from the portal page. The download started, but after a few minutes it froze. I tried on 2 machines with different OS (windows 7 and windows server 2008 R2) with different Internet circuits. Does anyone have idea about such issue?Thanks ...

yq by L0 Member
  • 2629 Views
  • 2 replies
  • 0 Likes

Network address Translation (NAT) support for IPSec ESP

I have an IPSEC tunnel with a third party and they require that all traffic coming from me to be NATted as they will only accept data traffic coming from the IP of the NAT within the IPSEC tunnel.I have been unsuccesfull in trying to figure out how exactly this NAT within an IPSEC tunnel can be applied on a Palo Alto 5020 and would appreciate an...

jrhine by Not applicable
  • 5464 Views
  • 1 replies
  • 0 Likes
  • 24337 Posts
  • 124 Subscriptions
Labels