General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Question about NAT

How can you use dynamic source translation with dynamic source address.

 

This is my scenario. 

 

Site one Public NAT 1.1.1.1 source address 192.168.2.1

Site two Public NAT 2.2.2.2 source address 192.168.3.1 

 

If I want to combine this rule into one Nat ru

...

hpatel11 by L2 Linker
  • 1547 Views
  • 1 replies
  • 0 Likes

GRE Tunnel Policies

Hi,

I'm creating tunnels from my Palo Alto Firewall to Zscaler and have been trying to ping Zscaler's Global IP. What sort of policies are needed to allow traffic to pass into GRE Tunnels? (and/or NAT, Policy based forwarding)

Thanks!

smshafek by L1 Bithead
  • 1265 Views
  • 0 replies
  • 0 Likes

No data in Custom reports

Hello,

 

I'm using verson 8.1.7 (upgradede last week) in Panorama and firewalls 7050.

I have defined custom reports added to report groups nad this report groups defined in Email scheduler to send it every Monday.

If I do "Run now" in the custom report a

...

Captura.PNG
bprietoc by L1 Bithead
  • 7375 Views
  • 8 replies
  • 2 Likes

Resolved! After OS upgrade, CPU keeps high value

Hello all,

Our customer is using PA-3060, and we upgraded the OS on June 19. (8.1.x -> 9.1.x)

 

Although the CPU may go up due to OS upgrades, according to them, device that used to use cpu at 40-50% but it is maintained at 60-70% and sometimes cpu usag

...

how does two or more snmp communities?

Two snmp community values need to be set, but only one community value is included.

Can I put only one community in the SNMP Community String?

If anyone knows, please share the contents.

qmso475 by L3 Networker
  • 2447 Views
  • 3 replies
  • 0 Likes

Traffic logging issue from firewall to Panorama

Log-collector status show as active and connected. Checked the logging status and based on the time stamp, observed that log creating and log forwarding are stopped. So panorama is not showing a logs for pair of PA-850 firewalls.

 

We have tried restar

...

Global protect gateway disconnect

hello Everyone, 

 

I am having client who is trying to connect the laptop from office system. VPN is on the laptop, and he can see the file and stuff , but when he is accessing through remote desktop connection to laptop. when it login , Screen lock it

...

loki4722 by L0 Member
  • 1514 Views
  • 1 replies
  • 0 Likes

Honey pot recommendation for DNS sink holing

Dear all,

 

we are seeing many DNS alerts for spyware, but we don't have any DNS logs.

Also, internal hosts can't resolve external FQDNs, so probably most of the requests are coming from the proxy.

So we are thinking about setting up DNS sink holing with

...

BGP on two virtual routers on same firewall?

Hi all,

 

We have two HA pairs of Palo's BGP across two diverse datacentres BGP peering with 3rd parties using our private AS numbers. We now have a new 3rd party who require us to use a registered AS number. I am told that Palo doesn't have the abilit

...

StuartS by L1 Bithead
  • 5999 Views
  • 6 replies
  • 0 Likes

Help infinite loop in 10.1.5

Hi, we are using VM series and I just updated it to 10.1.5. When I want to use "help" (question mark) it loads up new tab in web browser and it goes into infinite loop of redirects. Page never loads up.
It happens on any question mark in any menu (as

...

Resolved! Too many IKE log in System log

Hi guys,

 

I've received call from my customer, and they said too many IKE log in System log.

until this time, there is no critical issue by this problem. (just little bit high DP CPU, maintain 40 %)

but I want to know why this problem occur.

 

anybody kno

...

카테노이드 IPSec.png

Resolved! Site to Site VPN between Cisco Meraki and PA3250

Hi all,

 

I am having trouble establishing a tunnel between our PA and a Meraki MX with the dynamic IP.

 

By trial and error, I was able to establish phase 1 by specifying Meraki's FQDN as "Peer Address" and Peer ID as it's local IP (can be found under t

...

  • 23579 Posts
  • 103 Subscriptions
Top Liked Authors
Labels