General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Two Virtual Routers and NATing

Hello,We currently utilize dual ISP's as part of our business continuity plan and it looks like we have most of our PBR's setup appropriately. I am trying to figure out a way to create a static NAT entry on ISP2 via VRF that will go to the Core NetworkISP1 (L3-Outside) ISP2 (L3-Outside2) | ...

jschelert by Not applicable
  • 3248 Views
  • 2 replies
  • 0 Likes

Exchange 2010 - Applications Required?

We have a Palo Alto in front of an Exchange 2010 CAS server.The Palo Alto is in a back-to-back config with a "dumb" firewall in front of it that only allows port 443 inbound.The Palo Alto has the SSL cert from the Exchange box on it, so does SSL inspection on all the inbound traffic.My questions is, can anyone who has Exchange 2010 behind a Palo...

HA interfaces link fail questions

According to manual, active-standby cluster..• If one HA interface fails, synchronization continues over the remaining interface. If the state synchronization connection is lost, then no state synchronization occurs. If the configuration synchronization is lost, heartbeats are lost. Both devices determine that the other is down, and both become ...

raymondl by Not applicable
  • 3210 Views
  • 2 replies
  • 0 Likes

traffic between management IP addresses in HA ???

hello guys,i have a silly question for today. am testing HA in my lab ....... i have noticed on PAN dashboards that it shows the management IP address of it's HA partner!! is there any traffic concerning '' HA '' that moves between the managements interfaces ??? for me it should not be the case .... if you checkout attached screenshot PAN mana...

Passive Logging

Hi - we are running 2x PA4050 in version 4.0.4. We are sending all logs to Panorama. We have them in active-passive mode. I see logs for both the policy and alarms (eg an etherchannel leg is lost - I get port & HA events etc) from the active. However, I can't get any logs (though it is logging locally) from the passive to Panorama. If I pul...

fmd by L3 Networker
  • 3122 Views
  • 2 replies
  • 0 Likes

Resolved! vwire with "zoned" vlans

I have a design type question I received from a customer today that I couldn't quite answer. They would like to position the PAN inline on a trunked interface in a vwire type configuration. But based on the traffic tagging they would like to create seperate zones. So basically VLAN100-IN and VLAN100-OUT, VLAN200-IN VLAN200-OUT ect ect, all on th...

Resolved! Trying to block only certain websites using 3.1.6

I need some help. I am very new to using firewalls and am not scheduled to go to class for Palo Alto until the first week of September. In the mean time I am trying to block a group of users from accessing the internet other than about 10 sites. I have tried everything I know how to do and even stuff I am just trying to figure out to do and I ge...

JeffTQT by L2 Linker
  • 5345 Views
  • 6 replies
  • 0 Likes

Bitrix

I am unable to find an app for 'Bitrix'. Does anyone know if this PAN app exists?URL: http://www.bitrixsoft.com/

bbsoc by L2 Linker
  • 2277 Views
  • 1 replies
  • 0 Likes

Impact of large address group

What is the performance impact of having many addresses to match against? If I have an address group that has hundreds of individual addresses in it (some FQDN), others ip netmask, will it have a noticible impact on performance? We are using a 2050 primarily for URL filtering.

Dropping of SNMP polling when committing changes

I have a pair of PAN-500 in HA on 3.1.9 and our NMS system polls the PAN using SNMP.Everytime I commit a rulechange, i noticed that it stops answering SNMP requests for about 2 minutes.The PAN still passess traffic but I've seen this with ruleset commits and software or definition updates.Is this by design?

  • 24429 Posts
  • 125 Subscriptions
Top Solution Authors
Labels