General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

PA-VM EVE || PA-HDF Mode issue

Hi Everyone, As I am running PA-VM on eve-ng, when start its stucked in PA-HDF mode & automatically rebooting after few seconds, previously it was working fine, your suggestion/solution will be appreciated Thanks.

Khalid by L0 Member
  • 2439 Views
  • 1 replies
  • 0 Likes

Resolved! license required for PAN-OS?

just purchased 2 PA-5410s and stumbled across eve-ng, do i have to have a license to be able to download the pan-os to run in eve-ng? thanks

branedge by L2 Linker
  • 2697 Views
  • 3 replies
  • 0 Likes

how to check traffic volume in IPSec tunnel

Is there any way to check the volume of traffic through an IPSec tunnel? We're being notified of spikes in volume through a tunnel but I'm not sure if there's a way to run a report or check metrics related to tunnel traffic.

Does anybody know how to install the cable management accessories that come with a PA-440 Rail kit?

I tried to get through to tech support with this, and I think I've faced easier quests trying to win money at a Casino! We have a PA-440 rail kit that we are installing 2 PA-440's on. The rail kit comes with a small baggy with cheap white zip ties, and some black plastic pieces that I think are supposed to be used to secure the power cord to th...

HA Clustering Info

Hi all,i have a question for all: i have two datacenter in two different city. The datacenters comunication in Layer 2 witn VRRP.In primary DataCenter (active) i have two FW in Active/Passive (Peer HA), i would configurate a new FW in secondary data center (in passive mode), same model FW, it's possbile? how to configuration this scenario? Than...

"Non-existent domain" error with split tunnel for "Both Network traffic and DNS"

Dear community! I have configured split tunnel for both Both Network traffic and DNS and it works fine. However while doing nslookups I get the "Non-existent domain" error According to the document down below, this can be fixed by setting "Resolve "All" FQDNs Using DNS Servers Assigned by the Tunnel (Windows Only)" option to NO. This optio...

Carracido by L4 Transporter
  • 3426 Views
  • 3 replies
  • 0 Likes

Resolved! Search security policies of network or related IPs

Hi, I need to migrate a vlan from a security zone to a new one. Which is the best way to search the related rules? Ae1.1200 10.100.15.0/24 I need to identify the rules of this network and the rules that use a specific ip like 10.100.15.20 and so one.

Resolved! 2 Public IP mapped to a Single Internal address

Hi All,I have a question about NAT'ng multiple public IPs in PAN to a single host. We plan to migrate the FTP server to the public IP below (2nd DNAT)(DNAT) - This is the current policy where we use it as an SSH server, does not have any specific portsSSH server 191.143.124.32 ---> Mapped to 172.30.50.108 (DNAT) - This should be a new policy ...

Resolved! Management Plane Cores in PA-400 Series

Hello, We would like to recommend that one of our clients move from PA-220 to PA-400 series firewalls. I had added multiple points regarding the improvement in Threat and Session information, however, one of the most important points for us to see the number of management plane cores on the new model PA-410 compared to the PA-220. I was unable t...

User868 by L1 Bithead
  • 5437 Views
  • 3 replies
  • 0 Likes

Enforcing Global Protect only on remote sessions

My company only allows company issued laptops (Windows only) to remotely connect to our network via VPN. Since these are company devices I feel they should always be restricted to company internet usage polices that only allow access to approved sites and categories. My users are all in office based but do need to remote in for those few work at...

dahoove by L1 Bithead
  • 3990 Views
  • 3 replies
  • 0 Likes

Clear Text and Tunnel traffic same physical interface QoS

Hi, I have a scenario in mind, for example: 1. We have physical interface for Internet link with a bandwidth of 50 Mbits/s, which is used to peer with our ISP and send internet-bound traffic through; 2. We have regular internet for users and VPN tunnel (to Prisma) using same link concurrently; 3. We have Subinterface configured on Physical ...

2023-02-24_16-08-20.png

site2site vpn. calling end is dynamic

I have a Palo gateway connecting via ipsec to a Palo gateway, the calling end has a dynamic IP and will need NAT-T. The called end has a static public IP. Whats the recommended method of using an identifier?

FTP (SCP) Error

Finished generating reports. Please press enter to continue...@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!Someone could be eavesdropping on you right now (man-in-the-mi...

NavidAlam by L3 Networker
  • 8944 Views
  • 6 replies
  • 0 Likes
  • 24443 Posts
  • 125 Subscriptions
Top Solution Authors
Labels