General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

VM Home LAB issues

Hey All looking for some help on a VM Palo that lives on a dedicated ESX box See attached diagram sorry if its confusing ISP modem(192.168.10.1) --Palo WAN port ether1/1 using sub interface ether 1/1.10 (192.168.10.3) Switch (VLAN1 192.168.10.2) --> Palo LAN Port on eth1/2 using sub interface eth 1/2.10 (192.168.10.4) A machine on 192.1...

Slowness Issues After applying Zone Protection to Inside Security Zone

I recently discovered that my configured Zone Protection Profile applied to my Inside Security Zone was the root cause of my very slow https download speeds. I came to this conclusion after I had noticed that with the Zone Protection profile applied to the INSIDE security zone, it would take a 3.5 gbps file 6 hours to download; however, after re...

Palo Alto with MDM DNS Filtering

Hi, I need to have our Palo Alto firewall v 10.1.6 working with our MDM DNS filtering. When the MDM filtering is enabled users are not able to get outside to the internet. Thanks for any assistance Marc

Solarwinds Query

Hi All, We have a problem with the report data on Solarwinds. We are running a multi-vsys Palo Alto 5220 with bgp connectivity to a router and need to run bandwidth reports on all vsys. All Vsys have at least 2 BGP Peering for inside and outside on 2 AE's, each assigned a particular Vlanif. All reports seemed to look good but one person is sayi...

a.jones by L3 Networker
  • 3688 Views
  • 4 replies
  • 0 Likes

How paloalto security roles work

Hello Everyone I want to know about Paloalto security roles. I mention the problem I have In our system, there are many roles for internet access. All roles are assigned with active directory groups.A user can have one or more internet roles.For example: One user can have both "low internet" and "social internet". And the url filter of each one ...

Fagani by L2 Linker
  • 2647 Views
  • 3 replies
  • 0 Likes

Global Protect VPN - Mac OS Ventura

Hi Trying to install the VPN product GlobalProtect-6.1.0.pkg onto a M2 Laptop running Ventura. I get the Installation failed message and to contact the software manufacturer for assistance. Any ideas why it wont install? have admin rights as well.

Threat alert emails

I see threat alerts as critical but no words of block. Are these still getting thru even if flagged as an alert? How do I verify or change to alert and block?

MMurphy1 by L1 Bithead
  • 1456 Views
  • 1 replies
  • 0 Likes

Flow group IDs

In PAN OS show running resource-monitor ingress-backlogs assigns a group-ID to each session consuming more than 2% of packet buffer. I am looking for way to identify what these group-IDs map to on PAN OS e.g grp-id 2 refers to flow_slowpath. Is there way to list all such mappings ? Thanks Karan

Resolved! How to add address from .json file

Hi I need to whitelist some ip address and the Service provider has provided me dest. address in .json file IP addresses for the firewall allowlist - Genesys Cloud Resource Center (mypurecloud.com) How can i add these address from .json files to my object>Address? I have created 2 EDL(for AWS and Goolge). and created policy suing the EDL. i...

Resolved! Delete VSYS configuration

I have a VSYS on my PA-5050 which is no more required and needs to be deleted.What steps needs to be taken for this?Is it unassigning all the interfaces in that , deleting all policies etc or do we have a proper step by step thing for this?Thanks all in advanceRegardsVaibhav

Vaibhav by Not applicable
  • 14423 Views
  • 6 replies
  • 0 Likes

VRRP with Cisco router LAN interface

My default branch configuration, the WAN router is the default route for the client devices on the LAN. Lets say 10.10.1.1/24My firewall is the default route of the WAN router, lets say 10.10.1.254/24.Cheap layer 2 switfh on the LAN, so no L3 routing option there.In the above setting, clients send all packets to WAN router, Internet traffic is ...

Move/clone/copy from FW Local Policies to existing Device Groups

Clone or move FW Local Policies to Device Groups Hello good afternoon, as always, thanks for the collaboration, time and good vibes. I have the following question. Due to bad practices some admins have made changes and added local policies. The Firewall in HA has its device-groups where there are a large number of policies, ie most, almo...

Metgatz by L4 Transporter
  • 5018 Views
  • 3 replies
  • 1 Likes

SAML for direct login on many firewalls

I got SAML working fine with Okta for Panorama. Very nice. Next, I have "many" firewalls which are managed by Panorama, and I find myself directly logging in to them frequently enough that it would be nice to have SAML for that too. (Context switching from Panorama to firewall would good enough to make me not care about direct login SAML but ...

  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels