General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4105 Views
  • 0 replies
  • 0 Likes

Exchange Load Balancing

Hello,Basically the scenario is that we have one exchange server behind the firewall, external users are accessing this server usning a host name mapped by a service provider to two different Public IP's using DNS round robin,Is it possible to configure two NATing rules for the same single host (the server). This way what ever IP the host name i...

rsaber by L1 Bithead
  • 3641 Views
  • 3 replies
  • 0 Likes

Very strange problem with connection

Very strange problemHi,have paloalto PA-500.I have three internet providers.I have many branch offices (40).my case4.1.0 softwarefrom all branch office we ping WAN1, WAN2, WAN3 is OKthe weekend I did upgrade the software to version 4.1.3from all branch office we ping WAN1 is OKfrom 30% of the branch office is ok ping WAN2from 70% of the branch o...

PAN and NetMotion

We run our NetMotion connections through the PAN for our mobile clients. The troubled moblle application receives dispatch information from our CAD application and since switching to the PAN from our previous firewall the delivery of this information has become unreliable.We suspect that not seeing any traffic across the link, the PAN shuts dow...

cdpadmin by Not applicable
  • 3378 Views
  • 2 replies
  • 0 Likes

Multiple Public IP's on External Interface

All,I apologize if this has been asked before but I couldn't find anything related to my specific question. I am a newbie when it comes to firewalls in general. We are going to be migrating from ISA to the PA firewall shortly and I have a question about public IP's assigned to the outside(untrust) interface. On the ISA we "attach" all the pub...

tohoken by Not applicable
  • 12412 Views
  • 5 replies
  • 0 Likes

SNMP TRAP Recommend

Hi AllI want to set snmp traps to my snmp-server , are there any recommend about that ?I have got the snmp mip from paloalto support site, but there are too many descrpitions about trap, so maybe someone can give me some recommends about system health of snmptrap.ThanksJoy

Incoming Traffic failed in Active Active HA

Hi,I setup active/active configuration and everything seems to be working. We test HA by powering off the other peer and vice versa. All outgoing traffic are working as expected. But, we notice that we're not receiving incoming traffic if one of the PAN fails. I configured NAT and assign the active/active HA binding to both. Please help.Thanks,Rex

Resolved! cannot unlock a vpn user

when i press unlock, comes the following error message:Unlock failed for the following: consalco-int.local christoph.ramboeck: request -> ssl-vpn -> unlock -> user 'consalco-int.localchristoph.ramboeck' can be at most 31 characterscan someone write me here to help or know what to do

USER - ID FOR EXCHANGE SERVER

Hi Guys ,I see on PAN OS 4.1 releases , We can discover user from Exchange Server.So where we have a document to understand more better how it works ?Where can i do download for this agent ?I need to install something on my exchange server ?Best Regards!

Thiago by L3 Networker
  • 4828 Views
  • 1 replies
  • 0 Likes

Resolved! Displaying detailed session info from the command line

Hi all,Does anybody know of a way to display detailed session information from the command line please?In addition to the basic info provided by "show session all" I would like to extract the "Start Time" and "Bytes" values for certain devices. I am able to filter sessions based on the "Bytes" value but that value is never displayed in the outp...

DavePalo by L4 Transporter
  • 2800 Views
  • 1 replies
  • 0 Likes

Brute Force Signatures

hi : In regard to Brute Force Vulnerability Signatures 40015 (ssh) and 40021 (rdp) :Why is there not a way to permanently block an IP number that exceeds the configured Number of Hits per time period? Is this possibly in the works fro a future release?

wlu by Not applicable
  • 15833 Views
  • 19 replies
  • 0 Likes

Site to site VPN phase one error.

Hi Team,For Site to Site VPN in System logs showing ( description contains 'IKE phase-1 SA is deleted SA: 10.10.10.1[500]-10.10.10.2[500] cookie:eb16a2088724d32c:0000000000000000.' )Thank you in advance,.

Gururaj by L4 Transporter
  • 3880 Views
  • 3 replies
  • 0 Likes

web browsing problem

hi,i installed pan5020 my customer..customer have 8 branch offices with metro ethernet..but some web page cannot open from branchoffices like www.yahoo.com, www.microsoft.com,etc.(i examine rule and logs everythigs looks normal, its interesting)when i switch to old firewall(cisco asa) everything running normal.i tried increase session time-out, ...

lildeniz by L3 Networker
  • 5791 Views
  • 7 replies
  • 0 Likes

Ipsec VPN to Cisco ASA

Hi Guys,right now we are trying to setuop a ipsec vpn between out palo alto 4.0.7 box and a cisco asa 8.2 box ..Cause we are running into troubles whithin the ike setup, i would like to know the following:1. How can i debug the vpn setup in the pa ? I'm used to ASA's but this is my first vpn setup on a PA. I want to check why the tunnel does not...

cfpa by L1 Bithead
  • 4207 Views
  • 3 replies
  • 0 Likes

iOS VPN and Identity Certificates

We are testing Certificate Based Auth + User Based Auth for iOS VPN. Is it best practice to export a unique Identity(Client) Certificate for each user/device? Or is it common to use the same Identity Certificate for everyone? Security wise, it would be better to use unique certificates, but managing them may be hassle. We are also looking into...

jambulo by L4 Transporter
  • 2251 Views
  • 1 replies
  • 0 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels