General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4117 Views
  • 0 replies
  • 0 Likes

Resolved! How do we config a basic setup for guest wifi app blocking

We are relatively new to Palo Alto detailed configs, although we have used url filtering, av filtering, etc for some time. We want to start doing a better job blocking at the application level on our guest wifi, especially in the areas of peer-to-peer, etc. Are there some basic guidelines or configuration guides on how to get started. Baselin...

high latency after HA failover

Hello team, I have an HA active/passive with a couple of PA-3250. After failover from active to passive there are a high latency for all the connections and some Http/https sessions cannot be established. I see in the traffic logs many aged out sessions and tcp-rst-from-server and also tcp-rst-from-client. After one minute aprox. the system gets...

Carracido by L4 Transporter
  • 3692 Views
  • 4 replies
  • 0 Likes

No Logs for matched rule

Hello everyone, We are facing a strange problem with one of our PA-220. I created a rule to allow all traffic between 2 different zones with our default log settings. The problem is that I only see a hand full hits and nothing in the traffic log. Yes there is traffic because I see it when I start the paket capture. There is traffic in booth di...

Website Access Issue from one of branch office

Hello All, We have PA-850 implemented across the sites (4 sites), there is a URL www.crunchydata.com is not accessible from one of Branch Office in US, while there is no issue accessing same URL from other branches. However - i have checked and confirmed via detail packet inspection where i am getting hello client and server response back to cli...

ECMP Single Interface

I have an HA pair of firewalls in my data center. I have a single ISP that provides two routers for internet access. I use HSRP on those routers, which obviously share the same subnet on the inside interface that connects to the outside interface of the Palo Alto firewalls. I have two instances of HSRP setup to where some of my other perimeter d...

create a new Vsys queries.

Wish to configure new VSYS, will it cause any issue while configuring? Do we need to reboot after enabling Multi-vsys opention? Will it will cause network disruption over default VSYS1? · Will it will affect the functionality of Access Control Policy on the default VSYS1? · Will it will affect the entire functionality of default VSYS1? · Could...

Global Protect have issue after firewall upgrade to 10.2.6

Hi, Yesterday we upgrade Pan-OS version from 9.1.13 to 10.2.6. GP version on 5.2.12. Now we have issue with GP as we have difficulties to connect the Gateway with error Cookie expired/Authentication failed We can confirm the Radius server is reachable we can ping it from the firewall. There were no changes made on the firewall except upgrad...

IPSEC VPN tunnel

We have a site to site VPN tunnel that fails when the vendor side tries to Re-Key. We are seeing no U-Turn policy blocking them. We can ReKey from outside without issue. 1. Has anyone seen this issue previously and been able to fix it? 2. Does anyone have a script that can be run that will logon our firewall and allow me to run 2 commands to ...

Palo Alto Application ms-office365-base not working

Hello Everybody, i thought i try the community for a change with my problem. One of our departments recently asked for a policy change, so their server could access a ressource in the internet. The rule is as simple as it gets. Source is their Server, Destination is a FQDN, Application SSL. (we don't decrypt). We already had a policy which all...

Log forwarding profile for Correlated Events?

Hello all, It appears that we have had at least a single correlated event in the past seven days, but did not recieve any alert related (via any configured log forwarding profile). It appears the each match that was correlated did perform a log action, but the actual correlated event did not. How do I attach a log forwarding action for Correlate...

  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels