General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1819 Views
  • 0 replies
  • 0 Likes

HA Active/Active,..

Hi Team,..

Attached is the scenario for HA Active/Active,..Is it possible to configure IPSec and SSL VPN in this Scenario?

The external interfaces of each PA firewall is directly connected to ISP routers and have configured defferent public IP's on bot

...

Astik by L0 Member
  • 3052 Views
  • 2 replies
  • 0 Likes

Shared Gateway and VSYS

Hi,

I've a basic setup with TWO vsys with separate vrouters on each vsys (Maketing and Sales ) and a shared Gateway. Some vpn Tunnels terminating on my shared gateway.

I need to implement some static NAT rules for my VPN tunnels, so far so good.

Routing

...

slh by Not applicable
  • 2861 Views
  • 1 replies
  • 0 Likes

Resolved! PPPoA

Hi All,

hoping you can help with something I'm now too sure about.  I haven't found anything in help or knowledgepoint so far.  I've pre-configure a couple of PA-200's in PPPoE mode (ISP modems in bridge mode) to send to a remote site OS.  I've just h

...

Brightcloud tagging Yahoo sites as Phishing and Fraud

Greetings!

Today I received several helpdesk calls concerning yahoo! mail not working. Logs show that the 'yming.com' site that yahoo! uses is being flagged as a 'Phishing and Fraud' site.

I know I can report it (24-48 hour fix) and can manually unbloc

...

cloughr by L2 Linker
  • 4954 Views
  • 6 replies
  • 0 Likes

Allow download of file types that show as ZIP

Hello,

I have had a few instances where I've needed to allow certain files types through the data filter.  One annoying case was native Office 2007/2010 documents that end in x.  What I did was add it to my file blocking profile with the action of ALE

...

gsvarney by L1 Bithead
  • 8363 Views
  • 6 replies
  • 0 Likes

4.0.9 to 4.1.6 - Issues to be aware of?

Are there any known issues to be aware of if I wanted to go from 4.0.9 to 4.1.6?

We had an issue when we went from 4.0.9 to 4.0.11 where the dataplane on our PA-500 randomly rebooted several times and support's initial suggestion was to do a factory r

...

Dual/HA IPsec tunnels with 2 ISPs ?

Hello,

I have 2 PaloAltos, one is running on robust and redundant Corp internet ISP, another one on a remote location with 2 public  ADSL (and miserable quality ofc !). My goal is to have a redundant IPsec link between the two PaloAltos :

How would you

...

essnet by L4 Transporter
  • 2314 Views
  • 1 replies
  • 1 Likes

Resolved! Hotmail Categorization Weirdness

Hey folks,

User reported MSN mail being blocked as phishing-and-other-frauds, but my Hotmail and her other MSN email accounts work fine.  I investigated and found that the server:

sn123w.snt123.mail.live.com

Is being categorized by the PAN device as phi

...

Negative lookahead regular expression not working

Hi

Bit of an advanced regex feature, but I would like to set up a custom vulnerability signature to detect browsers (user-agent) that are not Internet Explorer. True, one could detect Firefox specifically, but there are so many different browsers in t

...

SSL decryption and Http redirection

Hi,

I am testing SSL decryption and it seems to work fine  except when Http redirection is involved. E.g. when you try to connect to Https://gmail.com , google redirects you to https://www.google.com and it gives me a certificate error because of the

...

SLOW INTERNET

Hi GUys ,

I`m deploying a PAN.

Everything is OK , COnfiguration , URL Alerts , AV , AS everything on ALERT MODE.

But my problem , after COnfigure a L3 INterface to receive IP via dhcp client from my ISP router , my connection with internet becomes very

...

Thiago by L3 Networker
  • 5499 Views
  • 4 replies
  • 0 Likes

Antivirus Update Frequency

Is this specified anywhere?

I can't seem to find where the antivirus update schedule is stated explictly.

Or is it just part of the weekly content updates?

KGC by L3 Networker
  • 8111 Views
  • 7 replies
  • 0 Likes

HA Active/Active

Hi,

Can anyone tell me if HA Active/Active on a PA-500 requires three links in total? As there are limited ports on the PA-500 this may cause an issue.

Also, if this the case - is there any option on having an IPSEC VPN terminating on the passive firew

...

singersit by Not applicable
  • 4094 Views
  • 4 replies
  • 0 Likes

Blocking traffic from another country

Hello,

We have an Extranet server which sits on our DMZ... http and https are allowed through the firewall so that outside users can access the web app on that server.  My server admin asked me if I can block all inbound traffic from China and Taiwan

...

dwoolley by L1 Bithead
  • 4891 Views
  • 5 replies
  • 0 Likes
  • 24244 Posts
  • 117 Subscriptions
Top Solution Authors
Top Liked Authors
Labels