General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 2071 Views
  • 0 replies
  • 0 Likes

Resolved! Internet and internal network sepration via virtual router

Hello,

 

I am new to Palo Alto. I have basic question. 

 

Traditional setup I worked on my last project was as below,

 

 

VRF on cisco router for 

- Internet -0 bgp

- Production - bgp

- DMZ  - bgp

 

FW connects to all 3 VRF. Route between VRF is via

...

gondolf by L1 Bithead
  • 3213 Views
  • 4 replies
  • 0 Likes

cluster PA-5020 migrating to PA-1410

Hi Experts,

We are migrating from Cluster PA-5020 to PA-1410, I have some queries below if you guys can help me out please.

1. For platform migration(PA-5020 to PA-1410), we can just upload configuration files on the new PA-1410, just recheck physica

...

SNMP response on two interfaces? Possible?

I'm configuring NetFlow on our PA-5200. I'm collecting the data in What's Up Gold.  WUG has a limitations (it appears) that the NetFlow IP that I use for the IP address also has to be respond via SNMP on the same address.  However, the PA-5200 cannot

...

LIVEcommunity System Update - Delayed

UPDATE 11/8/23 11:43 a.m. EST:

LIVEcommunity’s System Update will be delayed. This means your use of LIVEcommunity will not be impacted this week (11/8-9), and you can proceed with business as usual.

 

Thank you again for your patience and stay tuned

...

jforsythe by Community Team Member
  • 986 Views
  • 0 replies
  • 0 Likes

Resolved! rx-bytes, tx-bytes mean

Hello everyone,

 

I wonder if the meaning of rx-bytes and tx-bytes in the "show system state browser" command represents bps or byte.

 

'rx-bytes':xxxxxxL, xxxx/s

'tx-bytes':xxxxxxL, xxxx/s

 

Thank you in advance.

 

 

Resolved! cannot find matching phase-2 tunnel for received proxy ID

Hello,

 

We have a site to site VPN setup between our PALO ALTO and a firewall of our customer that was allowing one IP. On the ipsec tunnel sec proxy-id allow local (172.18.23.61/32) and remote (172.21.88.191/32) . When we made this the VPN is enabl

...

a.mboukam by L1 Bithead
  • 10354 Views
  • 13 replies
  • 0 Likes

Resolved! GlobalProtect Gateway Behind Nginx Issue

Hello everyone! My environment only has one public IPv4 so I'm trying to make the most of it. We already run a number of web services on port 80/443 behind an Nginx reverse proxy. I'm trying to add GlobalProtect to the mix. I have my portal and gatew

...

MeCJay12 by L2 Linker
  • 3258 Views
  • 3 replies
  • 0 Likes

DHCP options and PXE boot

Hi,

 

we have just recently made a change in where we moved clients from one segment to a new one. We are using WDS for PXE boot and the WDS server (MDT 2013) is on a different segment than the clients. The Palo is our DHCP server for clients and we ha

...

tlea by L2 Linker
  • 41397 Views
  • 40 replies
  • 0 Likes

Global Protect

I have defined a closed VLAN that has no internet access, and it can only communicate over the LAN. In the same LAN, there is a Global Protect portal configured. The clients can ping and access the portal's web page, but the Global Protect applicatio

...

ODUBIDB by L0 Member
  • 1721 Views
  • 2 replies
  • 0 Likes

static routes for 2 wan links with DHCP dynamic IPs

Hi everyone,

 

I would like to ask for some assistance in my configuration, the palo alto firewall has been so far a pretty frustrating experience, I guess due to my lack of knowledge of Pas

 

i have 2 wan dhcp dynamic ips links

 

I would like to imp

...

nevolex by L3 Networker
  • 2781 Views
  • 2 replies
  • 0 Likes

Site to Site VPN issue

Hi,

 

We have 3 sites with Palo Alto PA-415 devices.  Site A is the headquarters, and Site B and C need to connect with a site to site VPN to Site A.  We have Site A and B connected, but site A and C won't connect.  We setup the VPN connection the sa

...

  • 24232 Posts
  • 117 Subscriptions
Top Solution Authors
Top Liked Authors
Labels