General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Importing routes between VR

I know we can exchange routes between VR using BGP but is there any other built in method? Cisco and Juniper offer route leaking functions which let you import/export routes between VRF's without needing to establish a full routing protocol Thanks

GP Not Transitioning to Internal Network Correctly

Hello! I have a GP environment with one all in one NFGW (Portal/Ext GW/Int GW). It works great. Recently I added a second site with a similar setup for redundancy. The same DNS name points to both portals, the portals are setup to suggest both GWs equally, each has an internal GW; totally equal GP setups. The issue I now face is when a mobile cl...

MeCJay12 by L2 Linker
  • 1439 Views
  • 2 replies
  • 0 Likes

Interpretation of BPA Reports

I generated a BPA report on the AIOPS website using the tsf file from Strata, but I am a bit confused about the terms referenced in the report's interpretation. Among them, CSC controls 9.2, 12, etc., specifically refer to? Can anyone explain it. I went to download the file: CIS.Controls_v8_Critical_Security.Controls_2023:08.pdf The descript...

Felixcao_3-1710145673343.png
Felixcao_0-1710145051453.png
Felixcao_1-1710145293214.png
Felixcao_2-1710145309189.png
Felixcao by L3 Networker
  • 1138 Views
  • 1 replies
  • 0 Likes

Create a Palo Alto to Juniper SRX Route based VPN using OSPF

I created a new document from lab testing the Juniper SRX to Palo Alto VPN connections using OSPF on a route based VPN. But the only place I have permission to upload files is in DevCenter. So here is the link for anyone who needs the setup instructions for both sides.PanOS to Juniper SRX Route Based VPN with OSPF

pulukas by L7 Applicator
  • 5421 Views
  • 3 replies
  • 1 Likes

PPPoE disconnect randomly

Hello PaloAlto users! Recently I purchased a PaloAlto from ebay and I have installed it in my home. I have the WAN interface (ethernet1/1) as PPPoE with the information from my ISP (Digi Spain) . Everything is okay regarding the configuration (or so i think) with my ISP, i got my IP, can navigate perfectly etc. but in some cases i got disconne...

Jlsierra by L1 Bithead
  • 5086 Views
  • 5 replies
  • 0 Likes

emails stop working

hi all, i recently replace my palo alto 820 with new model 440, all is working fine however my emails from inside to outside stop working. my emails are on seperate zone on the dmz and i have barracuda. there is a nat policy. however when i set back the old one everything works properly. Does anyone have an idea about what is causing the issue

Resolved! fixing GP bug in newest 10.1.x versions

Hi, PA users Do you have any rumors about fixing this bug in the latest versions of 10.1.x. firmware? Note: GlobalProtect tunnel might disconnect shortly after being established when SSL is used as a transport protocol. Workaround: Disable Internet Protocol Version 6 (TCP/IPv6) on the PANGP Virtual Network Adapter. I have several hundred s...

Resolved! Minemeld Webui not coming up

Hello, 1st post here. Currently running Minemeld on Ubuntu 16.04 LTS I did see this link and tried what was suggested but no dice: Solved: LIVEcommunity - Re: Minemeld install errors on ubuntu server 16.04 LTS (amd64 bit) - LIVEcommunity - 253599 (paloaltonetworks.com) Minemeld-auto-update log shows the following errors and the webui is no...

kenrinc by L0 Member
  • 2424 Views
  • 3 replies
  • 0 Likes

PAN-PRISMA-ACCESS-PRIV-APPS-SC-QTY

Hello can someone explain what changed on SKU: PAN-PRISMA-ACCESS-PRIV-APPS-SC-QTY.A customer had previously that license with a qty. of 600 and the cost was per unit/user... now the price increased exponentially.

Resolved! Multiple tunnel to single destination over multiple WAN connections.

Hi, I am new to Palo Alto and require some help with design and configuration. Site A Palo Alto -- ISP A - P2P link ISP B - P2P link ISP C - MPLS link Azure Gateway I have to configure the tunnel from each of the ISP to the Azure and make sure each tunnel take precedence as it listed. What I understand, I can do the static ro...

gondolf by L1 Bithead
  • 2012 Views
  • 1 replies
  • 0 Likes

GlobalProtect MFA Radius 30sec Timeout

Hello, I want to setup MFA (radius) on palo alto for both the vpn and the admin page. For the admin page i have no problem. However for globalprotect i have a timeout problem. My configuration is : - radius timeout : 120 sec - globalprotect timeout: 120 sec - portal auth profile = ldap - gateway auth profile = radius The problem is that wh...

zakergfx by L1 Bithead
  • 1584 Views
  • 1 replies
  • 0 Likes

Resolved! FIPS-CC mode default user/password issue

We recently tried switching to FIPS-CC mode but the factory default user/password didn't work. The Admin guide showed the default user/password to be admin/admin even in FIPS-CC mode. We also found a Palo Alto documentation that for FIPS-CC it should be admin/paloalto but that didn't work as well. There was a mention of using the serial number a...

B.Vance by L1 Bithead
  • 11883 Views
  • 4 replies
  • 0 Likes
  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels