General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 3579 Views
  • 0 replies
  • 0 Likes

Resolved! DNS Security Filtering

DNS Security Filtering - baymanager.fullswingapps.com - has been classified as "phishing" and is currently being blocked by the DNS security filter on our PA firewall. This is a website for managing Full Swing Golf Pro simulator customer sessions on

...

IPSec Tunnel data flow

Hi All,

 

I recently established an IPSec tunnel between our Palo Alto firewall and a Fortigate device. The connection appears to be functioning properly, as indicated by a green status. However, I've noticed that instead of utilizing the IPSec tunne

...

BRaj23 by L0 Member
  • 794 Views
  • 1 replies
  • 0 Likes

Resolved! Palo Alto Proxy IDs Bidirectional?

Hi everyone,

I am a bit confused about proxy IDs when it comes to tunnel negotiation. Lets say I have a tunnel I am building with a vendor. My encryption domain will be 192.168.1.0/24 and my vendor will have 192.168.2.0/24. So lets also say the vendo

...

PAN-186584

Happy Friday, 

 

Have anyone experimented similar  behavior reported under PAN-186584 on VM-Series?

#PAN-186584

Pre go-live Health checks for auto deployed VMs in AWS

Not sure how to post in the automation section anymore as it now has been moved to read only.

 

Anyways.. need some insight please.

so we recently did a POC to use Terrarorm to autoscale / deploy VMs in AWS cloud. all good and working.

However we nee

...

PA_nts by L4 Transporter
  • 1236 Views
  • 2 replies
  • 0 Likes

Resolved! Why cant a URL be used directly in a policy?

Hi, 

I understand that to block an individual URL it has to be in a custom category before it can be used in a policy as a destination. For my own education and curiosity, my question is why must it be in a category? What is the processing logic in th

...

ABurger by L0 Member
  • 1596 Views
  • 2 replies
  • 0 Likes

HA mode with vwire

Not sure it this is the right location for this question but here we go ...
I'm trying to replace 2 transparent ASA's in ACT/STDBY with 2 Palo's in the same setup vwire ACT/PAS. Current setup is the asa's are connected to 2 vpn servers in ACT/PAS conf

...

Chromebook usernames in Palo Alto logs.

Hi,

I was wanting to know if it is now possible to have the Palo Alto firewall log url traffic with the username from chromebooks.  It shows the username for all windows users as it syncs with AD, but can't get the chromebook users to show up.  I set

...

dholmes by L0 Member
  • 2556 Views
  • 3 replies
  • 0 Likes

VPN event messages keep receiving

Hi,

I have two IPSec tunnel configured between Azure PA firewall and cisco router.

worried about continuously getting the informational event logs ikev2-nego-child-sart,  ikev2-nego-child-fail & ikev2-recv-p2-delete

Did the setting DH group to No PFS

...

VirupakshaRajapur_0-1691068863263.png

PA-5400, 3400 series DP memory check

Dear Team,

 

For existing firewall models, I can check the DP's memory through the 'tail follow yes dp-log dp-monitor.log' command.

 

However, new devices(PA-3400, PA-5400) do not have a dp-log path itself.

 

Is there a way to check dp memory on new

...

  • 24303 Posts
  • 122 Subscriptions
Top Liked Authors
Labels