General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! cortex xdr agent connection problem

hi everybody,

 

we've installed cortex xdr agent on a terminal-master server which gets cloned for distribution

 

xdr-agent on master has active connection to cortex-cloud

 

but cloned servers can't connect...

 

 

xdr-log:

 

2022/05/18T14:32:44.590+02:00 <Info>...

Resolved! Management IP in Active/passive setup

Hi 

 

I am quite new to Palo Alto firewalls, but have worked with different vendors before. 

 

When running a HA in Active/passive a central VIP for mgmt is usually setup, so you dont connect to the passive FW.

From what i see there is no VIP for mgmt in

...

Url problem

Hello everybody.

I allow a url. I also allowed categories for that url, but the site still doesn't work properly. There is a problem connecting to a server on that site and it is deny

 

Thanks in advance

Fagani by L2 Linker
  • 3397 Views
  • 7 replies
  • 0 Likes

Resolved! Panorama 10.0.5 - Scheduled Config Export - ssh custom port

Hi,

we try the export of the config of Panorama and our bothe Firewalls 3260 thru the "Scheduled Config Export".

It runs well with FTP and SCP port 22.

 

With a custom port ssh, the "Test SCP server connection" failed.

 

I found no future infos on https://

...

bovay by L1 Bithead
  • 2918 Views
  • 4 replies
  • 0 Likes

Resolved! Palo Alto PA-3220 replace Bluecoat Proxy

Hi Guys,

 

Does anyone tried to use PA-3220 model as proxy server? Currently the internet traffic of my company is using bluecoat proxy with pac file (config in windows proxy setting), and the proxy also inline with sourcefire for doing SSL interceptio

...

Fast DNS Resolution Issues

Hello Community,

I checking to see what everyone is doing for their allow lists for some thing like an S3 bucket. 

 

Scenario: Lets say my server has no internet access due to policies denying the traffic. I then create an object, FQDN,  xyz-s3.amazo

...

Reference guide to configuration xpath and entry?

Is there any PA published document for the node paths and entries in the configuration file? And how do you tell if something is a path or an entry in the config? It seems extremely painful to try and figure out an xpath to pull the data you want. Se

...

Resolved! Prisma SD-WAN application SLA setup?

Where can I know how to setup the application SLA condition?

 

I read some Prisma SD-WAN Administrator’s Guide, I seen there are lot of function to enable Path selection and monitoring based on the Link Quality, SLA.

 

But how can I set the SLA of the ap

...

JoeKwok by L2 Linker
  • 2772 Views
  • 3 replies
  • 0 Likes

Antivirus Security Profile

Hi everybody,

 

i've enabled and configured an antivirus security profile and attached to a security policy for web-traffic

 

as i see web-traffic can be antivirus-scanned, but my problem is: traffic is identified as ultrasurf with port 8080

 

so antivirus

...

Resolved! Can't advertise static route over ebgp

Hi all,

 

i'm not having much joy getting this working.

I have created a static route for a subnet which I am trying to advertise to an eBGP peer.

I then created a redistribution profile with only static enabled

I then added that profile under bgp Redist

...

Mushussu by L0 Member
  • 3794 Views
  • 3 replies
  • 0 Likes

Resolved! Static Route Question

I just have a question about static routing on the palo alto and how it deals with traffic.

 

We one VR and a default network route to send traffic for 10.20.0.0/16 out via ethernet 1/5 , zone core.   There is another interface 1/6 configured with 10.2

...

MistryJa by L1 Bithead
  • 1935 Views
  • 3 replies
  • 0 Likes

compatibility

Dear Gents.

Kindly, i have a Cisco catalyst 9500 switch, my question, what is the last product of Palo alto firewall compatible with my cisco 9500 switch?

 

thanks. 

 

SDWAN - DIA anypath -Scenario?

Im still trying to get a grasp of the concept of SDWAN - DIA anypath.  The components and configuration are pretty straight forward but the "why/when" is not making sense.  The main scenario that's proposed is "when you want to fail over to using the

...

smarcyes by L1 Bithead
  • 3091 Views
  • 6 replies
  • 0 Likes
  • 24034 Posts
  • 102 Subscriptions
Top Liked Authors
Labels