General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Active-passive HA with BGP to 2 ISPs, BFD + graceful restart

Hi, Anyone ever configured BGP + BFD + Graceful restart, trying to do this setup but not sure if there is any timers to ensure below. Can't find anywhere on any knowledge base. 1. when ISP link go down - BFD ensure seconds failover, ISP gateways are on same subnets attached through switches to Palo 2. when firewall failover - the BGP sessions s...

PetGoh1 by L1 Bithead
  • 9904 Views
  • 3 replies
  • 0 Likes

PA firewalls and HA across different GEO locations

Hi Support, We have Client in Cork want to know about the FW HA across Different Location. What are requirements for having fw cluster spread across different GEO locations (latency, delay, etc)?Is this recommended at all by PA? If yes, what kind of link is required for HA connectivity (L3, L2)? We have some ideas of spreading current firewall c...

NavidAlam by L3 Networker
  • 11351 Views
  • 5 replies
  • 0 Likes

Resolved! Panorama connectivity check failed for xxxx. Reason: TCP channel setup failed, reverting configuration

- We ran into an issue where the commits from Panorama were failing with error: • . Performing panorama connectivity check (attempt 1 of 1)• . Panorama connectivity check failed for xxxx. Reason: TCP channel setup failed, reverting configuration• . Configuration reverted successfully - We checked No validation errors while the commit failed- run...

Firewall integration to Panorama with initial/default device Post-Rules

Hello, firstly, apologies for the long winded background info to explain my requirements !! I've a large project with hundreds of Firewalls to deploy. All initial base-configuration and Panorama-integration will be completed via the use of various specific templates, template-stacks and parent/child/grand-child device groups, achieved via auto...

GlobalProtect on Mac 13.4.1 ("msgtype = hip" rather than "msgtype = portal")

I'm looking over the log files of a Mac (v13.4.1) that cannot connect using GlobalProtect (v6.1.1-5). I'm comparing it to another Mac running the same OS which works, and in the PanGPS.log files I'm seeing this difference: Working: Line 53: P10741-T259 07/19/2023 15:37:40:147 Debug( 759): CPanMSService::Init connect timeout 5, received timeout...

Management Interface down

Hello, i have the problem that I have two PA-445 as HA clusters where the management interface does not have an uplink.I've already tried several cables and switches, but unfortunately I can't get an uplink on the interface.There is no spanning tree on the switches, all ports are active.Type: 1000T, Mode Auto, Flow disabled.Switch port: VLAN 1...

Resolved! Negate Deny Rule

Hi All, I have a negate rule on the firewall Souce Address - 10.1.1.1(Negate) Destination Address- Any Service- https Action- Deny Does it mean that it will allow 10.1.1.1 and deny everything or does it mean that it will deny everything and then I need to create an accept rule to allow 10.1.1.1. Will 10.1.1.1 be allowed through this negate...

Ujbal89 by L0 Member
  • 1708 Views
  • 1 replies
  • 0 Likes

Resolved! Secure Renegotiation in PANOS 9x?

I'm seeing some posts stating that Secure Renegotiation is not supported on the Palo Alto platform. Is this still true for the latest release, v9.x? If so, how is it enabled?

Personal VPN Services thwarting Company Policies

Downstream of our PAN's, we have our Citrix environment. This environment includes some Netscalers that have a nice feature in that they provide in their SYSLOG, two fields named "ClientIP" and "NATIP". This proves quite useful in that while the ClientIP field geolocates to a local Boston IP address, the NATIP address shows they are coming in...

Jaragorn by L1 Bithead
  • 7440 Views
  • 16 replies
  • 0 Likes

Resolved! EDL problem

Hi,I find this error: EDL(my list) Entry not referenced by a rule.What does it mean? How can I resolve it?

s_quasar by L3 Networker
  • 27904 Views
  • 18 replies
  • 0 Likes
  • 24428 Posts
  • 125 Subscriptions
Top Solution Authors
Labels