General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4141 Views
  • 0 replies
  • 0 Likes

dns proxy - static entries

HiI have a dns proxy on one of my interfaces with some static entries, but nothing is resolved on the static ones - they should have a higher priority than the primary dns IP right?Thanks

FlexyZ by L3 Networker
  • 5848 Views
  • 5 replies
  • 0 Likes

dns proxy - static entries

HiI have 8 static entries on one of my DNS-Proxy's but stopped working and when I show enties withshow dns-proxy static-entries allIt only shows one - GUI still shows them allThanks

FlexyZ by L3 Networker
  • 3550 Views
  • 2 replies
  • 0 Likes

PA-200 CPS vs Actual users

The specifications for the PA-200 show a CPS ( connections per second ) of 1000.What number is generally agreed upon to calculate how many connections are actually used per user?I've previously been told 50, which means all of 20 users being active at any one time?Would this calculation be correct, or has real world use come up with a different ...

KatanaNZ by L3 Networker
  • 5810 Views
  • 5 replies
  • 0 Likes

Traffic logging stopped in PA4020

Traffic loging in my P4020 stopped yesterday. No new traffic log events after that. Command >debug log-receiver statistics is showing rising amount of Logs discarded (queue full), while Traffic logs written is constant.Logging statistics------------------------------ -----------Log incoming rate: 0/secLog written rate: ...

tomkas by L0 Member
  • 3004 Views
  • 1 replies
  • 0 Likes

Panorama CLI questions

Had a couple of questions regarding some CLI commands for PanoramaPanorama version 4.1.0Devices are a mix of 4.0.4, 4.0.7 and 4.1.0Is there a way to update licensing information for the firewalls from the Panorama CLIrequest batch license info shows the existing licenses associated to the Panorama managed devices but does not update for the new...

jcostello by L4 Transporter
  • 3437 Views
  • 1 replies
  • 1 Likes

does session drop when changing VR?

I have an HA PAN scenario with single VR, after commiting a change to the default VR name then adding another VR to the system, I have noticed that some sessions droped.Most of our sessions are opened one time and continue until service restart, if a session is to be dropped, the service must be restarted in order to initiate a new session.So do...

areda by L0 Member
  • 2227 Views
  • 1 replies
  • 0 Likes

Multiple ISP's for Global Protect Client?

I've been messing with the setup of using multiple ISP's in an office and maintaining the functionaility of an inbound VPN client for both - aka redundancy.I guess my first question is, can a client have a Global Protect installation that is able to connect to multiple gateways? I haven't seen anything to indicate it's possible yet - maybe I ju...

cmaier by L1 Bithead
  • 2380 Views
  • 1 replies
  • 0 Likes

Policy complexity considerations

When creating policies, especially Security and QoS, how much consideration do I have to give to the number of policies?If we want to get very granular with these policies, will we pay any significant penalty in performance (either in device administration or performance)?(Specifically we have PA2050 that will route through 220Mbps max to intern...

sspivey by L1 Bithead
  • 2227 Views
  • 1 replies
  • 0 Likes

Pan OS 4.1, Destination Nat Problems

Hallo,I installed a PA500 wit Pan OS 4.1 at customer side and most thing working fine.I configured the WAN interface as DHCP-Client with default route to this interface. In NAT-Rules i want to publish a internal server to give external sources acces to this internal source (simple portforwarding). My problem is, if I configure a destination tran...

Show unused rules option

The show unused rules is very helpful but as I work at cleaning up rules after migration it would be really handy if I could clear that flag to see if the new rulesets created are handling all of the traffic before disabling the old rulesets. Is there a quick way to clear that flag so that it starts from fresh?Thanks in advanceJohn MitchellHydro...

Resolved! Is there anyway to have the URL Filtering response page to display category in the local language of the firewall Region.

Hello,I was wondering if there is any feature or ability of the firewall Response Page to display URL Filtering Category in the local language of the site it is inspecting.For example, if a user is from the Netherlands and speaks Dutch, can the Firewall located in region be set up to post the category of blocked site being surfed in Dutch?Pleas...

Eone by Not applicable
  • 3852 Views
  • 3 replies
  • 0 Likes

PA-500 WAN connect directly to ISP

Hello,We are using an PA-500. We would like to connect the WAN port directly to our ISP. Normally the ISP requires a Cisco router with the following requirements.Connectivity requirements:Ethernet / IEEE 802.3-2005WAN side 1000Base-T full duplex100mbit througputPPoE/PPPRFC 2516 PPPoERFC 1661 PPPRFC 1332 PPP Internet Protocol Control Protocol ( B...

check to check "deny" packages

HiI have some rules that will allow IPSEC between two Windows Domain Controllers, but it only works when I allow "any" underapplication - unless I ping from both ends.So how can I see what port I am missing in my custom application group?Thanks

FlexyZ by L3 Networker
  • 1857 Views
  • 1 replies
  • 0 Likes
  • 24340 Posts
  • 124 Subscriptions
Top Liked Authors
Labels