General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4445 Views
  • 0 replies
  • 0 Likes

SNMP response on two interfaces? Possible?

I'm configuring NetFlow on our PA-5200. I'm collecting the data in What's Up Gold. WUG has a limitations (it appears) that the NetFlow IP that I use for the IP address also has to be respond via SNMP on the same address. However, the PA-5200 cannot send NetFlow traffic out its MGMT interface so I'm using our inside trusted interface to send Ne...

Resolved! rx-bytes, tx-bytes mean

Hello everyone, I wonder if the meaning of rx-bytes and tx-bytes in the "show system state browser" command represents bps or byte. 'rx-bytes':xxxxxxL, xxxx/s 'tx-bytes':xxxxxxL, xxxx/s Thank you in advance.

Resolved! cannot find matching phase-2 tunnel for received proxy ID

Hello, We have a site to site VPN setup between our PALO ALTO and a firewall of our customer that was allowing one IP. On the ipsec tunnel sec proxy-id allow local (172.18.23.61/32) and remote (172.21.88.191/32) . When we made this the VPN is enabled, but we are seeing the following error from the external site trying to access these IP's. Err...

a.mboukam by L1 Bithead
  • 13813 Views
  • 13 replies
  • 0 Likes

Resolved! GlobalProtect Gateway Behind Nginx Issue

Hello everyone! My environment only has one public IPv4 so I'm trying to make the most of it. We already run a number of web services on port 80/443 behind an Nginx reverse proxy. I'm trying to add GlobalProtect to the mix. I have my portal and gateway running on the same IP. When I forward the ports (80, 443, 4501) the portal seems to work corr...

MeCJay12 by L2 Linker
  • 4020 Views
  • 3 replies
  • 0 Likes

DHCP options and PXE boot

Hi, we have just recently made a change in where we moved clients from one segment to a new one. We are using WDS for PXE boot and the WDS server (MDT 2013) is on a different segment than the clients. The Palo is our DHCP server for clients and we have defined some options in our DHCP scope (option 66 pointing to the WDS server and option 67 poi...

tlea by L2 Linker
  • 46563 Views
  • 40 replies
  • 0 Likes

Global Protect

I have defined a closed VLAN that has no internet access, and it can only communicate over the LAN. In the same LAN, there is a Global Protect portal configured. The clients can ping and access the portal's web page, but the Global Protect application is very slow in connecting to the configured portal and performing user authentication. However...

ODUBIDB by L0 Member
  • 1997 Views
  • 2 replies
  • 0 Likes

static routes for 2 wan links with DHCP dynamic IPs

Hi everyone, I would like to ask for some assistance in my configuration, the palo alto firewall has been so far a pretty frustrating experience, I guess due to my lack of knowledge of Pas i have 2 wan dhcp dynamic ips links I would like to implement some redundancy if 1 link goes down - the second link activates and when the primary goes ...

nevolex by L3 Networker
  • 3393 Views
  • 2 replies
  • 0 Likes

Resolved! What privileges required by service account used by palo alto firewall in LDAP server profile to fetch group information from LDAP server

What privileges required by service account used by palo alto firewall in LDAP server profile to fetch group information from LDAP server for group mapping?Do we need admin privilege ? oris it enough that we need service account only to be a member of the following groupsEvent Log Reader Distributed COM Users Server Operators

perumalj by L2 Linker
  • 12884 Views
  • 3 replies
  • 1 Likes

Site to Site VPN issue

Hi, We have 3 sites with Palo Alto PA-415 devices. Site A is the headquarters, and Site B and C need to connect with a site to site VPN to Site A. We have Site A and B connected, but site A and C won't connect. We setup the VPN connection the same way. How can we troubleshoot this? We have a ton of experience with Sophos firewalls, but th...

PAN VM Security Policies -

I have setup my VM on a single desktop with 4 NICS to connect to different subnets and security zones and to have different interface setups for the VM. Two other desktops have NICS with different subnet scopes. I have created a rule to test ping traffic from zone 'A' to zone 'B' as an example. You can ping from a client in zone 'A' to a client...

Source user information is intermittently not visible in the traffic log.

he agent is installed on the ad server and user information is mapped and confirmed. However, source user information is not visible intermittently in the traffic log. This occurs even when it is the same application and the same external address. I would like to know why this may occur. The timeout is 45 minutes, and the symptoms are the same e...

How API to work with PA

Hi We like to set up API for palo alto and review related documents. I found there are a lot documents on API. but I am not familar with API in PA and do not know which documents is good for beginner to kick off. Anyone can share some documents link for understanding how to use API and explain how ACI to work with PA? Thank you very much!

kevinospf by L3 Networker
  • 1583 Views
  • 2 replies
  • 0 Likes

Checking NAT Pool Usage from the GUI

Hello community,I'm wondering if there is a way to check the usage of IP addresses in a NAT pool from the GUI and/or from Panorama. I'm interested in seeing which original IP addresses have been translated and what is the translated address. The CLI command equivalent for this is show running nat-rule-ippool <rule_name>I have checked the d...

WhatNot by L0 Member
  • 4600 Views
  • 2 replies
  • 0 Likes
  • 24375 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels