General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4132 Views
  • 0 replies
  • 0 Likes

Can I verify a config before doing a commit?

I was writing a rule to allow ciscovpn to only certain addresses, so I added a destination and the application I chose was ciscovpn. I added it to the policy and then did a commit. it came back with messages saying that ciscovpn needed ike to function and it was denied in the default deny. so I added ike and did a commit, and got a message ...

dabels by Not applicable
  • 2186 Views
  • 2 replies
  • 0 Likes

Resolved! AntiSpyware Response Page

Did the AntiSpyware Response page option go away in version 4.1.4? Seems like I tested with it and saw an option for an AntiSpyware page in eariler versions of 4.x, but I'm not seeing it listed as an option on the firewalls or in Panorama in 4.1.4.

robertb by L0 Member
  • 2326 Views
  • 1 replies
  • 0 Likes

Resolved! Layer 3 Interface Trunk Configuration

Hi,I am a new Palo Alto firewall user, however I have been working with firewalls for some time. I have a couple of quick questions;1) Does the Palo Alto PAN-OS firewall have equivalent of the "shut" or "no shut" command to turn an interface on or off?2) I have an 802.1q trunk link coming into my firewall; this trunk link has multiple VLANs ta...

dsulli99 by Not applicable
  • 11449 Views
  • 2 replies
  • 0 Likes

how to browse for adding specific AD group in LDAP authentication.

Hi..Customer would like to use SSL VPN with Active-Directory.So, I have configured SSL VPN with LDAP Authentication.There was no problem to connect SSL VPN with LDAP Authentication. after verify SSL VPN connection, I was going to add some specific group to LDAP authentication in Authentication profile.But I cannot browse Active-Directory group...

willstech by L3 Networker
  • 2404 Views
  • 1 replies
  • 0 Likes

Adding multiple IPs to external interface

I am interested in adding all of the IPs from a range like x.y.z.40/28 to the external interface of the PAN.The verbiage on the GUI makes it sound as if I need to add each IP individually.Can I add a range as listed above by entering it as x.y.z.40/28 and if so, can I then NAT inbound by individual IPs in the range by referencing the individual...

BobW by L4 Transporter
  • 3721 Views
  • 1 replies
  • 0 Likes

Resolved! URL logging without URL Filtering license

We are trying to log all URLs without having a URL Filtering licenseFor that we created a custom URL category containing*.**.*.*Seemed to work but when we compared the amount of log entries to the proxy logs we discovered that we only see less than half of the proxy URL logs in the PA URL log.Looking around we noticed that the option "Log Contai...

AndreasB by L2 Linker
  • 3621 Views
  • 1 replies
  • 0 Likes

CLI cmd to show system log

I'm trying to use the CLI to get a list of SSLVPN logins, but keep getting either "sytnax error at end of input" or "syntax error at AND" errors. what i've attempted so far is variation on:show log system subtype equal sslvpn object equal "Test SSL-VPN"I suspect it's something to do with the object name which has a space it in. I've tried single...

u11756 by Not applicable
  • 27705 Views
  • 1 replies
  • 0 Likes

ThreatLog forwarding doesnt work

Hi All,I have configured the PaloAlto to email me threatn logs for medium , high and critical alerts, but it seems to email me only medium threat alerts, how do i fix this 😞Please find attached my log forwarding profile.My email profile is configured fine, as i can receive system alert emails etc, but only with threat alerts, all i get is medi...

Combining NAT rules?

Whil my NAT rules are working fine I get the feeling I am missing something with net rules. I have an external ip which needs three ports forward to separate internal server: port 7000 goes to port 3389 on 192.168.1.1, port 7001 goes to port 389 on 192.168.1.2, port 7002 goes to 3389 on 192.168.1.3.I have these working with individual NAT rule...

BobW by L4 Transporter
  • 1867 Views
  • 1 replies
  • 0 Likes

Asymmetric routing

Does anyone else have a multi-site network with asymmetric routing? I'm having some issues getting from site to site.Here's what's going on:We have two datacenters -- one for the eastern US, the other for the western US. Each datacenter has a PA-2020. Our satellite offices use PA-500s, ASA 5505s, and ASA 5520s. There is an IPSec tunnel from ...

nwallette by Not applicable
  • 10389 Views
  • 5 replies
  • 0 Likes

PA500 Configuring a Static Routing Question?

Hello all.I have a fairly easy deployment - a set of PA500s with internal trusted and external trusted zones. On the inside, they are currently connected to a router hsrp pair and on the outside pointing to another brand FW. I have only a handful of networks inside, so I have static routes pointing to the inside/outside configured in the VR area...

dudesdad by Not applicable
  • 3083 Views
  • 2 replies
  • 0 Likes

Source NAT confusion

I am trying to provide for some 1-to-1 NAT on our PAN, which I thought we be an easy task. However, my configuration insist on using the interface IP address for outbound connections. Here is my setup.Untrusted Network Interface IP: x.x.x.10/29Trusted Network Interface IP: y.y.y.4/16Mail Server Public IP: x.x.x.12/32Mail Server Private IP: y.y...

cdpadmin by Not applicable
  • 4464 Views
  • 5 replies
  • 0 Likes
  • 24337 Posts
  • 124 Subscriptions
Labels