General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4104 Views
  • 0 replies
  • 0 Likes

Enforcing Global Protect only on remote sessions

My company only allows company issued laptops (Windows only) to remotely connect to our network via VPN. Since these are company devices I feel they should always be restricted to company internet usage polices that only allow access to approved sites and categories. My users are all in office based but do need to remote in for those few work at...

dahoove by L1 Bithead
  • 3596 Views
  • 3 replies
  • 0 Likes

Clear Text and Tunnel traffic same physical interface QoS

Hi, I have a scenario in mind, for example: 1. We have physical interface for Internet link with a bandwidth of 50 Mbits/s, which is used to peer with our ISP and send internet-bound traffic through; 2. We have regular internet for users and VPN tunnel (to Prisma) using same link concurrently; 3. We have Subinterface configured on Physical ...

2023-02-24_16-08-20.png

site2site vpn. calling end is dynamic

I have a Palo gateway connecting via ipsec to a Palo gateway, the calling end has a dynamic IP and will need NAT-T. The called end has a static public IP. Whats the recommended method of using an identifier?

FTP (SCP) Error

Finished generating reports. Please press enter to continue...@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!Someone could be eavesdropping on you right now (man-in-the-mi...

NavidAlam by L3 Networker
  • 8312 Views
  • 6 replies
  • 0 Likes

Resolved! LSVPN not working when NAtted via Loopback

Hi Community, I got the following problem:We have a running LSVPN with primary and secondary tunnel, which are connected on the hub on two different VRs, which sync themselves via iBGP - everything fine so far. One of the satellite sites got two ISP lines, which should be used active/passive for redundancy.Binding the IPSec tunnel on the physica...

Chacko42 by L4 Transporter
  • 8850 Views
  • 9 replies
  • 0 Likes

The specific URL is not shown in the traffic log

PAN OS 9.1.7 The following traffic log shows the specific URL The other traffic log doesn't have the specific URL, and also this log cannot be seen in the url filtering log Is this a expected behaviors or something wrong with the customer's environment?

3.png
4.png
zji by L3 Networker
  • 2708 Views
  • 3 replies
  • 0 Likes

IP SLA

Hi,Could you please help me with a small query.Do we have any concept like IP SLA to monitor an ip and deactive route in a routing table.ThanksRaj

Adobe Creative Cloud -- Block Uploads

Hello has anyone had any success with blocking the ability to upload content via Adobe Creative Cloud using the Palo Firewall ? Is it as simple as creating a rule to block UDP\443 traffic for either QUIC, the domain, or both?

Pancast: Have an Idea for an Episode?

Hey Everyone! Have you listened to the PANCast podcast? PANCast is a Palo Alto Networks podcast that provides actionable insights from cybersecurity experts to customers, helping ensure each day is more secure than the one before it. Since launching last September, PANCast has produced and published 10 episodes — including titles like “Shou...

Screen Shot 2023-02-01 at 7.41.19 AM.png
Screen Shot 2023-02-01 at 7.45.27 AM.png
JayGolf by Community Team Member
  • 1459 Views
  • 0 replies
  • 0 Likes

Change HA setup A-A to A-P

Good Day. I am looking for pointers wrt changing the HA setup from A-A to A-P mode. The existing setup is for PA-5200s and they are in A-A mode with floating IP bind to active-primary (logically active-passive) and the HA setting is locally managed. Both the FWs are connected to panorama and they have unique interface IPs and dedicated templates...

krlinks by L0 Member
  • 1507 Views
  • 1 replies
  • 0 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels