General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Strict IP Address Check after 9.1.12

Customer upgraded to 9.1.12 and after that it was noticed that for some of the zones, traffic was dropped. During debug,it was concluded that reason is Strict IP Address Check in the Zone Protection Profile:

"flow_dos_pf_strictip 1 0 drop flow dos Pac

...

nikoo by L3 Networker
  • 5176 Views
  • 8 replies
  • 1 Likes

Why Did Strict IP Address Check Break this VPN?

We have been working with TAC to find the cause of this issue where FTP client could no longer upload to external companies FTP server over the VPN tunnel.  After many days, we started a packet filter on the Public Internet (WAN) interface, which is

...

ms.jzam by L2 Linker
  • 14520 Views
  • 30 replies
  • 0 Likes

Resolved! refresh external dynamic list real time with cli

Hi,

I need to update in real time the external dynamic list IP. 

Looking for this doc https://docs.paloaltonetworks.com/pan-os/9-0/cli-reference/pan-os-9-0-configure-cli-command-hierarchy.html and cli command "find command keyword",didn't see any comma

...

Resolved! FIPS Failure upon boot

One of devices was not properly shut down due to a power outage in a building.  When the device started back up, it appears that it entered maintenance mode.  The reason is FIPS failure.  I have attempted to reboot the device from maintenance mode an

...

BryanSG by L0 Member
  • 5731 Views
  • 2 replies
  • 0 Likes

Globalprotect 5.2 Cookie Issue

Hello 
We just upgraded our GP from 5.1.7 to 5.2.10

We have a gateway with SAML authentication
We have some connections issue with a message "already logged in" from the Identity Provider

I think this is due to the new feature "Default System Browser for

...

QoS max egress, no effect

Hi there,

 

I'm playing with QoS in our lab. I have a simple setup with two queue, first for SMB traffic, second for RDP traffic.

The max egress value is set, but when I transfer data, then both queues get bandwith values.

 

What I am doing wrong here?

 

 

 

...

PA QoS Monitor.png
PA QoS Profile.png
PA QoS Policies.png
Netzer by L2 Linker
  • 1643 Views
  • 2 replies
  • 0 Likes

site to site VPN on TP-link --- PALO ALTO ---- AWS

 

As of now STORE router/POS1 able to reach the head office(PALO ALTO) via site to site VPN and HeadOffice(PAN) to AWS also working via site to site VPN. But our main goal is that POS1/Store able to reach the AWS network. As of the momment POS1 not ab

...

IPSEC S2S store to HO to AWSrev1 .jpg

global protect connectivity issue (version 5.2.10)

Hi Team,

 

We have facing the connectivity issue on GP Agent 5.2.10.

 

After turning off the windows firewall, it's connecting.

 

Please let us know how we can achieve this without disabling the windows firewall. Because in earlier versions of GP client we

...

VishnuPS by L3 Networker
  • 2049 Views
  • 2 replies
  • 1 Likes

User-ID Agent not mapping users

Hello,

 

Im trying to configure User-ID Agent.

 

Dedicated users is created, with details acroding to: Create a Dedicated Service Account for the User-ID Agent (paloaltonetworks.com)

Agent version: 10.0.4-23

Agent is installed on Windows Server 2019.

DC's a

...

mgwozdz_1-1644489742592.png
mgwozdz_2-1644489787346.png
mgwozdz by L1 Bithead
  • 1808 Views
  • 1 replies
  • 0 Likes
  • 24197 Posts
  • 100 Subscriptions
Top Liked Authors
Labels