General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

PA Firewall Performance Chart

Spoiler
Looking at the comparison chart, if I was interested in the 3430 and I use SSL decryption, threat prevention\wildfire\URL filtering and IPSEC vpn does that mean I would get roughly 9/2 Gbps or 12.2 Gbps?
Looking at the comparison chart, if I wa
...

roma_0-1648500614096.png
roma by L2 Linker
  • 1385 Views
  • 1 replies
  • 0 Likes

WMI On server 2022 for USER-ID

Hi There,

 

Have a pair of PA-3220s. User-ID was working swimmingly. Recently upgraded our DCs to Windows Server 2022 and WMI is routinely failing and showing "Not connected" under server monitor.

 

Doing some reading on WMI and Server 2022, and it sound

...

kaumell by L0 Member
  • 3033 Views
  • 1 replies
  • 0 Likes

Resolved! SSL certificate for passive firewall

There is an active passive pair having SSL certificate (management only) with different CNAMES (its own management IP).

 

While the CSR generation and certificate import (signed by ECA) is successful on active peer, the CSR generated on passive peer is

...

Resolved! IPSEC VPN - app-id

Hello all,

We have a software ipsec connection that will be between an inside server and a server in the cloud. The PA will just be a pass through so to speak, (nating and security rule).

The ipsec requires UDP 500 and 4500 and the IP 50 protocol. Do y

...

roma by L2 Linker
  • 2989 Views
  • 2 replies
  • 0 Likes

Bulk way to search logs for many IPs?

I have a list of over a 100 IP addresses that I would like to search logs to see if there has been any activity. Is there a way to search the logs files by feeding the FW a file containing the IP addresses? Thank you.

ccfritz by L1 Bithead
  • 1667 Views
  • 1 replies
  • 0 Likes

Resolved! using Azure MFA with Global Protect

Hello,

 

To configure Global Protect to use our already Existing MS MFA server, I followed this KB: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClkkCAC 

 

I think I had to do one or two extra things as well, but in any case

...

Extending Eval license

Hi there,

 

My Eval Request is going to be expired soon, and I'd like to extend it for another 60 days but I don't know how?

 

Could someone please advise me how to extend my Palo Alto Eval license ? As I can't see any options in Palo Alto portal for lic

...

AK74 by L2 Linker
  • 1992 Views
  • 1 replies
  • 0 Likes

design help

 

Hi all ,

 

I have the above topology , Now the question where should iI keep the dmz zone 

on edge firewall or dc firewall 

 

Thanks 

 

pa dmz.JPG
simsim by L4 Transporter
  • 1373 Views
  • 1 replies
  • 0 Likes

FQDN resolution failures in Palo Alto

Hello

We are experiencing FQDN resolution failures in Palo Alto.

The Palo Alto has connection to the internal DNS; however, it does not resolve the FQDNs.

 

 



Please could you help us to verify this issue.

 

Regards

Alpalo_0-1648455350096.png
Alpalo by L4 Transporter
  • 1773 Views
  • 1 replies
  • 0 Likes

CPS average for DDos protection configuration

Hello Team,

 

I have a problem with the choice of CPS average value. When i made the command show session info which parameter I have to consider to calculate my CPS rate average ? Number of allocated sessions or packet rate or New connection establish

...

Mamoudou by L2 Linker
  • 2876 Views
  • 6 replies
  • 0 Likes

Palo Alto - dot1q tag Errors with Meraki switch

Hi,

 

First post on the Palo Alto side for me. Used to post a lot on the Cisco Support Community forums 

 

I thought I would ask around here if anyone had any ideas what might be causing this problem before I go ahead with some more troubleshooting myse

...

JouniF_0-1648114223727.png
JouniF by L0 Member
  • 2773 Views
  • 1 replies
  • 0 Likes
  • 24018 Posts
  • 102 Subscriptions
Labels