General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! IPv6 over PPPoE

(apologies if this has been answered before, I'm new to this community but I didn't find any answers to this.)So basically my question is if it's possible to get IPv6 to work with PPPoE?I just installed PA200 in my home, and before the PA200 I had two PPPoE connections, one for IPv4 and one for IPv6 (different service-providers, since my main on...

Natti by L1 Bithead
  • 9067 Views
  • 7 replies
  • 1 Likes

nslookup on the management port ?

I would like to check a few DNS issues I'm seeing on the management port.I had hoped to find nslookup in the CLI, but it isn't there.Is there something equivalent ?Thanks.

DSTR by L0 Member
  • 41569 Views
  • 4 replies
  • 1 Likes

Looking for AI/ML tools for DoS/DDoS protections and traffic analysis

Hi all,Large organization - looking for recommendations of AI/ML tools that we could use to augment our traffic analysis and provide DoS/DDoS protections. I know there are many different ways this could be done but I'm just looking for some 1st-hand-experience on some solutions you guys implemented successfully:- I am not familiar w/ Palo's AI/M...

GlobalProtect reports a "Client Certificate Error" but still connects

Hello-I'm running a PA-500 on with GlobalProtect for VPN access. Just recently our users started experiencing an issue wherein they try to connect and receive a "Client Certificate Error" error dialog. However, after they click OK to close the dialog, the agent connects anyway. I investigated the issue myself and found what follows below. No...

The Mysterious "stun" application

Does anyone have a understandable explaination of this application called "stun" from what I can gather its used for things like skype and facetime, but it generates a lot of traffic in my network. While yes we are lync/skype in house and there are the occosional calls out to the internet, I see this application going out to google public IPs on...

GRE Tunnel to Zscalar

Hi All, I have setup the GRE tunnel to Zscalar. I am not able to ping the peer(Zsclar) from the tunnel interface created for GRE Tunnel. I see the GRE tunnel interface is down, cant see any ARP as well from the peer as it is down. Is there anything that i need to get it working? Interface itself is showing down so what should be done for this ...

Resolved! Botnet report : Dates Missing in calendar

Hello Community, I am facing an issue with Monitor>Botnet> Dates The dates are missing in the calendar where it is only showing reports until 22 December 2023, since it is 03-01-2024. I am running on PA-850 with 10.2.3-h9. Hope someone provides the solution for it. Thanks in advance.

Resolved! Paloalto VPN Traffic Inspection.

I have a question regarding Paloalto VPN Traffic Inspection.Is there a way to inspect traffic that users inside use commercial VPN (free VPN program) on the outside Internet?

Logging and Change Management in Prisma Cloud

Summary: There is currently a size limit of 128kb in compute console history logs. It's likely to hit this limit and then only an error will display in the changes section: "diff size exceeded limit (128KB)". This makes the history log useless for auditing a specific endpoint, as experienced by multiple users. Are there ways to overcome th...

Strange behavior

Hi, facing issue where directed interfaces traffic is not working (from DMZ zone to Servers zone) , while from Inside ZONE to SERVERS is working fine despite inside users SVI is core switch then static route from core switch to paloalto while for users inside DMZ zone their gateway is FW itself (also DHCP ) and no routing is needed to reach SE...

mhmameen by L1 Bithead
  • 1331 Views
  • 1 replies
  • 0 Likes

Resolved! Virtual Router Best Practice - Guest Network

Hi, We don't have dual ISP but we do have STS VPN that connects our offices to our Cloud Infrastructure. At the moment all the interfaces share the same virtual router. So assuming the traffic from source to destination was allowed in a security policy then it will be able to route to the remote subnets via the STS VPN interface. We have ...

jbusby by L1 Bithead
  • 2800 Views
  • 1 replies
  • 0 Likes

WinRM-HTTP fails with the error 401

Hello, I'd like to request some advice on trying to shift away from WMI to WinRM-HTTP/S based User-ID. I followed the set-up guide by Palo and User-ID server monitoring is able to connect to the domain controller over WinRM-HTTP, but only every hour. If I set session monitoring to something less than 3600 seconds, each attempt by the user-id se...

Megrretz by L1 Bithead
  • 31158 Views
  • 9 replies
  • 0 Likes
  • 24427 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels