General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 591 Views
  • 0 replies
  • 0 Likes

Resolved! URL Filtering - Max URL Entries

Is there a limit to the number of URL entries allowed or is it only limited by hardware resources?  

 

We are a school district, so the number of whitelisted/blacklisted URLs is substantial - probably near 1000.

 

We are currently running PANOS 10.2

...

Resolved! about Password complexity configuration

Hello,

 

I configured required password change period and post login count in password complexity on my firewall.

 

If admin login in post login count stage after required password change period expire

 

How can admin recognize expiration of his account pa

...

hbshin by L2 Linker
  • 3143 Views
  • 2 replies
  • 0 Likes

SSL Connect Error on SMTPS Settings

We have problem with SMTPS configuration on Palo alto Firewall

so we have the SMTPS Certificate and already inject to the firewall

Our users says that the certificate is the certificate CA and when we test the email connection, the firewall shows err

...

Resolved! PA-3410 : STP Block cannot be created

Hello all, 

We have a PA-3050 configured with V-wire and are operating as STP Block on the uplink of Backbone_B.
 
We are going to replace PA-3050 with a new construction firewall, PA-3410.
 
STP block is not generated in the in-house LAB before deploymen

...

스크린샷 2022-09-26 오전 10.20.49.png

Related to Paloalto VM instance type change

Dear Team,

 

I have a question while testing.

 

If I'm wrong, anyone please feel free to leave a comment.

 

1. Check if an issue occurs in the service traffic processing part when changing the instance type
> Since there is no change in the settings,

...

Resolved! PA-3410 Spanning tree cannot be generated

Hello all,

We have a PA-3050 configured with V-wire and are operating as STP Block on the uplink of Backbone_B.
 
We are going to replace PA-3050 with new construction equipment, PA-3410.
 
STP blocks are not generated in the in-house LAB before deploymen

...

스크린샷 2022-09-26 오후 1.17.26.png

WSL and SSL decryption

Hi guys. We have a number of developers that use Windows Subsystem for Linux (WSL) on their Windows clients, and there are a lot of URLs and services that will not work when we decrypt the traffic. Managing a decryption exclude list for them would be

...

MD-OTL by L0 Member
  • 2509 Views
  • 2 replies
  • 0 Likes

PA-5250 Migration to Virtual Appliance and EoL Status

Hello

 

I'm interested in the Palo Alto virtual or VM-series appliance that would be broadly equivalent to the PA-5250. I realise the product selection is best made based on requirements such as sessions security rules, dynamic ip addresses, security

...

Redman by L1 Bithead
  • 2367 Views
  • 2 replies
  • 0 Likes

DNS proxy errors

We are using PANOS 9.1 and latest DNS security. Any thoughts on these errors from proxy log? 172.16.1.1 and 172.16.1.3 are Microsoft AD DNS servers.Can these be effecting performance of traffic?

 

2020-02-17 08:30:23.583 +1100 Error:  pan_dnsproxy_recv

...

Resolved! Pan-OS database

Hi guys, greetings.

On of my customers asked me a simple question about palo alto database. How does it work internally? Is there any SQL database internal on PAN-OS? Should it be accessed by any external factor like APIs os something like that?

IPSEC tunnel not working post HA failover

Hello Friends,

 

We have Palo Alto firewalls (various models like 3050, 5220 and 3220) which are in HA (active-passive mode).  IPSEC tunnels are working fine when traffic is on active gateway. The issue is, when we failover traffic on passive gateway,

...

HA Interfaces failover triggers

Hi All,

 

We currently have a pair of PA-5250 firewalls configured in active/passive. We have 4 port channel groups configured with the condition set to 'all'.

 

The question i have is we are using eth1/1 & eth1/2 as HA interfaces if one of these goe

...

ElliotM by L2 Linker
  • 4185 Views
  • 4 replies
  • 0 Likes

Resolved! GlobalProtect Local LAN Printing

I have GlobalProtect running for machines when they are off the network.  Is there anything that I need to setup that would allow them to be able to print to their local LANs even though the agent is connected back to the FW?  I am currently testing

...

ccaruso by Not applicable
  • 10034 Views
  • 2 replies
  • 0 Likes
  • 23927 Posts
  • 113 Subscriptions
Top Liked Authors
Labels