General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Bytes sent by Firewall is too high, seems abnormal.

Hi everyone! Greetings to all. I was just curious since I've been seeing traffic logs packets which are Gb's and Tb's in size. I am not sure if this is a wrong display but I am pretty sure there was no such traffic in my network. I am currently running PANOS 10.1.8 Is this a bug? Regards, Renz

Resolved! URL Categorization suddenly failing as not-resolved for Google search URLs

Is anyone else seeing sudden failures in URL categorization for Google searches? Starting within the last hour or so we are seeing intermittent blocks as not-resolved for search URLs, but not for the Google homepage or any other websites (that I have been able to find so far). Initial error seem to be a HTTP2 compression error to the Google serv...

2023-09-06_135545.png

Resolved! Automatically blocking IP's after a certain number of Global Protect pre-login failures?

I've just recently started getting blasted with Global Protect portal pre-login failures, coming from a bunch of illegitimate IP's. They all fail because I use certificate authentication and the client cert is not present on the attacker's device. I have have the NGF set up to email me every time this happens and I'm getting just blasted with e...

Advanced Routing - NAT for overlapping networks between 2 logical routers

Hi, We have a Palo VM with advanced routing enabled. We have 2 customers with overlapping networks (172.16.0.0/24). Those networks must be accessible by the same servers (in connected network 10.1.1.0/24).Customer1 network is routed via a static route to another router, Customer2 network is behind a IPSec VPN configured on the Palo VM. We ca...

palo.jpg

Windows User-ID agent not collecting mapping

I'm working on getting a Windows User-ID agent set up for a customer and it's not collecting logs. Checked all permisssions and service account user is in Event Log Readers and has permissions to both the install folder and registry entries. Just as a test, I had the customer add the service account to the domain admins group and the user mapp...

Route-Based VPN between PaloAlto & Strongswan

Hi! If anyone have some experience about this topic? I need a vpn between our PaloAlto and a virtual machine with strong swan installed. To route some traffic from our local network to this vpn tunnel. How to make this possible?

Monitor Power Supply of PA-400 by SNMP

Is there a way to monitor power supply redundancy by SNMP? I found this, but these values are not a SNMP object. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbfCAC similar to this; these values don't exit on my PA-440. https://live.paloaltonetworks.com/t5/general-topics/snmp-monitoring-on-pa3250-psu/td-p/417040 ...

Resolved! VPN Phase 1 Not Synchronized between HA pair

Hello guys, Sorry if this topic has been already discussed before but I could not find an answer. I would like to know why phase 1 is not synchronized between HA pair. Is there a particular reason ? Thanks

seag by • L1 Bithead
  • 3745 Views
  • 3 replies
  • 1 Likes

Resolved! Palo Alto SNMP Item meaning

Hello, i'm doing snmp polling to firewalls and need to know the throughput for the interfaces. Am i right to think that Interface out counters (ifOutOctets.n, 1.3.6.1.2.1.2.2.1.16.n) and Interface In Counters (IfInOctets.n, 1.3.6.1.2.2.2.2.1.10.n) are the items that i'm looking for? Or there is any other that i might have overlooked? I also need...

DanielVe by • L1 Bithead
  • 5839 Views
  • 7 replies
  • 0 Likes

Firewall can't be added to VM-PANORAMA-25: Device limit reached

We have a new Panorama VM-25 but we can't add any devices to it. We get 'maximum device limit reached' when we try to add the first FW. We have valid licenses so not sure what the problem is. I have tried deleting that device management license and fetching new ones but it just brings back the exact same one. Does anyone know what the pro...

drewdown_0-1705938343133.png
drewdown_1-1705938431257.png
drewdown by • L4 Transporter
  • 1808 Views
  • 2 replies
  • 0 Likes

Logging - 5450

Any tips/places to look into when not seeing logs locally on the firewall? new install, PAN OS 10.2.7

clewis1 by • L3 Networker
  • 3118 Views
  • 6 replies
  • 0 Likes

PA200 Android IKEv2/IPSEC PSK

Hi everyone, I received an old Palo Alto PA200 firewall from a friend who works in networking, and I decided to set it up in my home lab to explore its interface and features. If I like how it performs, especially the monitoring capabilities, I might suggest purchasing it for the company where I work. Currently, I'm trying to establish an IPsec ...

Kublach by • L0 Member
  • 2333 Views
  • 1 replies
  • 0 Likes

Resolved! How to view administrative distance?

Hi everyone, How would I see administrative distance of the routes in the routing table? they seem to not be visible in the gui (more runtime stats) or via cli (show routing routes). is there a special command or special area via gui I can see this information??

VK9H13 by • L2 Linker
  • 6497 Views
  • 5 replies
  • 0 Likes
  • 24460 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels