General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

URL Category in Match Criteria. Release 4.1

Hi, as I've readed in release notes of 4.1 there is a new feature to use URL category in Security policies, Qos and Captive Portal but I've updated to 4.1 my PA-500 and I don't see where to configure this in security policies. Anyone has tested this

...

ssancho by L2 Linker
  • 4708 Views
  • 4 replies
  • 0 Likes

Resolved! Importing Exported Logs

Once logs are exported to anFTP location, what is the procedure for importing them back into panorama?  I was unable to locate mention of this in the admin guide.

semtribe by Not applicable
  • 3183 Views
  • 3 replies
  • 0 Likes

Resolved! P-bit in type-7 LSA. OSPF NSSA.

Hi,

Is it possible to send OSPF LSA type-7 in a NSSA area with P-bit=1 ?

We are using PA as ASBR (just ASBR, no ABR) and redistributing some BGP route into OSPF. The prefix is send as expected as type-7 (NSSA Ext) :

admin@PA01(active)> show routing prot

...

How to Analyse threats

Hi all,

Can anybody suggest me how to analyse threats that's been alerted by Palo alto device.

What is the analysis approach?
Please advice.

Basic Question on Apps vs Service Relationships

I have attached a PDF that shows screenshots of the same rule, in four different variations.

I am trying to understand the relationships between using applications and traditional ports.

I have a server that has a static public IP NATed to the private

...

dns proxy - static entries

Hi

I have a dns proxy on one of my interfaces with some static entries, but nothing is resolved on the static ones - they should have a higher priority than the primary dns IP right?

Thanks

FlexyZ by L3 Networker
  • 3739 Views
  • 5 replies
  • 0 Likes

dns proxy - static entries

Hi

I have 8 static entries on one of my DNS-Proxy's but stopped working and when I show enties with

show dns-proxy static-entries all

It only shows one - GUI still shows them all

Thanks

FlexyZ by L3 Networker
  • 2445 Views
  • 2 replies
  • 0 Likes

PA-200 CPS vs Actual users

The specifications for the PA-200 show a CPS ( connections per second ) of 1000.

What number is generally agreed upon to calculate how many connections are actually used per user?

I've previously been told 50, which means all of 20 users being active a

...

KatanaNZ by L3 Networker
  • 3960 Views
  • 5 replies
  • 0 Likes

Traffic logging stopped in PA4020

Traffic loging in my P4020 stopped yesterday. No new traffic log events after that.  Command  >debug log-receiver statistics is showing rising amount of Logs discarded (queue full), while Traffic logs written is constant.

Logging statistics
-----------

...

tomkas by L0 Member
  • 2441 Views
  • 1 replies
  • 0 Likes

Panorama CLI questions

Had a couple of questions regarding some CLI commands for Panorama

Panorama version 4.1.0

Devices are a mix of 4.0.4, 4.0.7 and 4.1.0

Is there a way to update licensing information for the firewalls from the Panorama CLI

request batch license info  shows

...

jcostello by L4 Transporter
  • 2674 Views
  • 1 replies
  • 1 Likes

does session drop when changing VR?

I have an HA PAN scenario with single VR, after commiting a change to the default VR name then adding another VR to the system, I have noticed that some sessions droped.

Most of our sessions are opened one time and continue until service restart, if a

...

areda by L0 Member
  • 1729 Views
  • 1 replies
  • 0 Likes

Multiple ISP's for Global Protect Client?

I've been messing with the setup of using multiple ISP's in an office and maintaining the functionaility of an inbound VPN client for both - aka redundancy.

I guess my first question is, can a client have a Global Protect installation that is able to

...

cmaier by L1 Bithead
  • 1930 Views
  • 1 replies
  • 0 Likes

Policy complexity considerations

When creating policies, especially Security and QoS, how much consideration do I have to give to the number of policies?

If we want to get very granular with these policies, will we pay any significant penalty in performance (either in device administ

...

sspivey by L1 Bithead
  • 1793 Views
  • 1 replies
  • 0 Likes
  • 23554 Posts
  • 106 Subscriptions
Labels