General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

ECMP Single Interface

I have an HA pair of firewalls in my data center. I have a single ISP that provides two routers for internet access. I use HSRP on those routers, which obviously share the same subnet on the inside interface that connects to the outside interface of the Palo Alto firewalls. I have two instances of HSRP setup to where some of my other perimeter d...

create a new Vsys queries.

Wish to configure new VSYS, will it cause any issue while configuring? Do we need to reboot after enabling Multi-vsys opention? Will it will cause network disruption over default VSYS1? · Will it will affect the functionality of Access Control Policy on the default VSYS1? · Will it will affect the entire functionality of default VSYS1? · Could...

Global Protect have issue after firewall upgrade to 10.2.6

Hi, Yesterday we upgrade Pan-OS version from 9.1.13 to 10.2.6. GP version on 5.2.12. Now we have issue with GP as we have difficulties to connect the Gateway with error Cookie expired/Authentication failed We can confirm the Radius server is reachable we can ping it from the firewall. There were no changes made on the firewall except upgrad...

IPSEC VPN tunnel

We have a site to site VPN tunnel that fails when the vendor side tries to Re-Key. We are seeing no U-Turn policy blocking them. We can ReKey from outside without issue. 1. Has anyone seen this issue previously and been able to fix it? 2. Does anyone have a script that can be run that will logon our firewall and allow me to run 2 commands to ...

Palo Alto Application ms-office365-base not working

Hello Everybody, i thought i try the community for a change with my problem. One of our departments recently asked for a policy change, so their server could access a ressource in the internet. The rule is as simple as it gets. Source is their Server, Destination is a FQDN, Application SSL. (we don't decrypt). We already had a policy which all...

Log forwarding profile for Correlated Events?

Hello all, It appears that we have had at least a single correlated event in the past seven days, but did not recieve any alert related (via any configured log forwarding profile). It appears the each match that was correlated did perform a log action, but the actual correlated event did not. How do I attach a log forwarding action for Correlate...

GlobalProtect: Port 4501 UDP

Hi all, I understand that GlobalProtect uses TCP 443 and UDP 4501... But what is there any more information available about GlobalProtects usage of port 4501? All I could find is the following: TCP/443 for the SSL communication UDP/4501 for tunnel communication to the GlobalProtect Gateway It doesn't really include much about it.. any ins...

mmclimans by L3 Networker
  • 50592 Views
  • 3 replies
  • 0 Likes

Resolved! Clarification on Web-browsing App

I just need to clarify whether if allowing Web-browsing on a policy would be enough to allow both http(80) and https(443) traffic, ( i.e I don't need to allow both web-browsing and ssl) as it has port 443 as secure port. Thanks

Web-browsing app.PNG
SDon by L0 Member
  • 6013 Views
  • 2 replies
  • 0 Likes

Unable to download new firmware for Lab PA-220

Hello, We are using a PA-220 on version 9.0, its unlicensed, had a real issue getting a new license because the PA-220 was previously purchased off Ebay so we use it now for basic configs now. How do i get the newest firmware for this? I went under devices and then software and hot check now but its not getting me a newer version, I'm stil...

OID of throughput value of each interface

I've seen several posts that asking the same question, but none of them have provided substantial suggestion. Many replies just suggest to use existing templates of Cacti or Zabbix. What if I'm not using those 2 monitoring tools?PA has published an OID list on https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClaSCASHowev...

jeremylo by L3 Networker
  • 8700 Views
  • 5 replies
  • 0 Likes

SNMP OID for session throughput

Hello does anyone know if there is an OID for the session throughput (show session info > throughput)?I would like to monitor that on my firewalls without offloading to get an idea of their load with respect to the max throughput from the tech specs Best regards

  • 24428 Posts
  • 125 Subscriptions
Top Solution Authors
Labels