General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! HOW TO CONFIGURE .1q - VLAN TRUNK

Hi guys ,I have a lots of doubts about how to configure .1q vlan TAG / TRUNK on PALO ALTO FIREWALL.It`s possible to work with layer 3 interface ?I don`t found any documents here.Does anyone have something to help me.Nbest RegardsTHiago LIma.

Thiago by L3 Networker
  • 3978 Views
  • 2 replies
  • 0 Likes

Resolved! Disable weak cipher suites for SSL/TLS and SSH

Hi Team, I want to Disable weak cipher suites for SSL/TLS and SSH my question is, are the below commands correct ? Do I need to run below commands on Active and Passive firewalls separately ? I am using data port as management ( I do have dedicated management port with IP but not using it) so below commands are still valid. Also, I am on PAN OS...

shafi021 by L2 Linker
  • 48732 Views
  • 8 replies
  • 0 Likes

Correct way to setup UserID redistribution

Hi there, I'm looking for the correct way to build our UserID redistribution topology based on our enterprise needs. We have 1 Panorama appliance, 4 PA3020 hosting a GP Gateway component and 50 PA3020 for remote offices. Our only source for UserID is the GP Gateways. I've set up Panorama to retrieve UserID information from our 4 GP Gateway and o...

Resolved! Country code blocks with IP address exception - is there a way to do this?

I have a block rule for some of the more egregious regions of the internet. Unfortunately, the regions use the source address within the rule on the Palo so I see no way to negate an IP address in a region being blocked. Is there a way I'm not aware of to do this? It would be nice if you could group a rule with another and skip the next rule ...

user-ID non-domain windows systems not being logged

Hello PAN community,I have setup user-ID with Active Directory and the hostnames and user names for domain joined systems are being logged in the firewall's monitor.Some systems have their hostnames resolved, but others are just showing IP addresses. Does anyone know why?Second, I'm also trying to see if user-ID can pick up source names and host...

Resolved! PA -5060 Version: 8.1.24 , All the interfaces flapped simlutanesouly

Hi Team, We have observed a situation where all the connected interfaces were flapped on the Firewall with the below logs, there is no much conclusive evidence in the tech-support logs, not sure if i am missing the log file which has the reason for this cause. LACP interface ethernet1/2 moved into AE-group ae3. LACP interface ethernet1/...

Resolved! Dumb question: Are there cases where a configuration change will take effect prior to committing?

I would like to reconfigure our PA-3260 FW to use its 40G interfaces instead of the 1G interfaces being used in production now. I plan to create one new aggregate ethernet interface made up of subinterfaces that correspond to each of the individual 1G AEs now in production. In the process, I will need to remove the IP addresses in each of those ...

rpastor by L0 Member
  • 3566 Views
  • 3 replies
  • 0 Likes

Resolved! Cortex XDR Firewall configuration query.

We have configured the Check Point firewall version (R81.10), but it is not supported for native log ingestion. However, we have checked the official Palo Alto documentation for this link: https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Ingest-Logs.... -It states that log ingestion and data require a Co...

Resolved! Logging In PAN OS

Hi Team, >In general, the PA Firewalls are manged by Panorama will log directly to Panorama or do we need any configuration to be made to push the logs to Panorama? >What is the best way to configure logging for the firewalls managed via Panorama? For the firewalls in cluster as well the firewalls which are standalone? >Based on what i ...

Firmware download

I have device registred and lisenced also I can ping from the device updates.paloaltonetworks.com however I cannot run any: request support checkrequest license fetchrequest license inforequest content upgrade check Server error : Failed to check support info due to generic communication error. Please check network connectivity and try again.

Resolved! Issues with DHCPv6 Client with Prefix Delegation

Hi there, Playing around at home with DHCPv6 Client with Prefix Delegation. Been following this guide: https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/networking-features/dhcpv6-client-with-prefix-delegation The configuration for the outside interface is working ok, and I get a prefix from my ISP. What fails is when I try to ...

erikda by L2 Linker
  • 2314 Views
  • 1 replies
  • 0 Likes
  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels