General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Static route path monitoring doesn't recover

Configured the path monitor on my primary ISP route per this guide, https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/static-routes/static-route-removal-based-on-path-monitoring.html# It worked great when I unplug the cable from the primary ISP CPE. The default route went to the back up ISP. Problem is the primary default rout...

Resolved! Log Forwarding

Hey, I'm using PaloAlto PA440 and I'd like to forward logs to syslog, but I don't use dedicated management (MGMT) port for administration. I configured log forwarding, but it does not work. Do I need to use dedicated management port to send logs? Is it possible to configure log forwarding on any port? Thank You!

yonkerro by L0 Member
  • 2327 Views
  • 1 replies
  • 0 Likes

Log collectors Incoming logs per second capacity

In a log collector group, we have two log collectors and redundancy enabled option is turned on. This results in the incoming logs per second capacity reduced to half. However, wanted to confirm that in order to use the incoming logs capacity of both the log collectors optimally- should we change the preference list on the managed devices so th...

Global protect client to access IPSEC peer networks.

Hello - my query is that "Is it possible for Global protect client users of HO to access the resources located at branch office over IPSEC tunnel? We have 3 branch locations configured Site to site IPSEC tunnels. Since I created a access rule in HO for the same but no success. Please suggest

amar by L1 Bithead
  • 2886 Views
  • 4 replies
  • 0 Likes

Amazon Video Not Playing

I'm running PanOS 9.0 on a PA220 and noticed a couple days ago that Amazon Prime Video wasn't playing on any of my wireless devices. However, it would play on a desktop or laptop through Firefox. After a few troubleshooting steps and Google, it seemed to me the difference was in the actual player itself. I enabled "Allow HTTP partial response...

JacobAn by L2 Linker
  • 8029 Views
  • 5 replies
  • 2 Likes

VM Home LAB issues

Hey All looking for some help on a VM Palo that lives on a dedicated ESX box See attached diagram sorry if its confusing ISP modem(192.168.10.1) --Palo WAN port ether1/1 using sub interface ether 1/1.10 (192.168.10.3) Switch (VLAN1 192.168.10.2) --> Palo LAN Port on eth1/2 using sub interface eth 1/2.10 (192.168.10.4) A machine on 192.1...

Slowness Issues After applying Zone Protection to Inside Security Zone

I recently discovered that my configured Zone Protection Profile applied to my Inside Security Zone was the root cause of my very slow https download speeds. I came to this conclusion after I had noticed that with the Zone Protection profile applied to the INSIDE security zone, it would take a 3.5 gbps file 6 hours to download; however, after re...

Palo Alto with MDM DNS Filtering

Hi, I need to have our Palo Alto firewall v 10.1.6 working with our MDM DNS filtering. When the MDM filtering is enabled users are not able to get outside to the internet. Thanks for any assistance Marc

Solarwinds Query

Hi All, We have a problem with the report data on Solarwinds. We are running a multi-vsys Palo Alto 5220 with bgp connectivity to a router and need to run bandwidth reports on all vsys. All Vsys have at least 2 BGP Peering for inside and outside on 2 AE's, each assigned a particular Vlanif. All reports seemed to look good but one person is sayi...

a.jones by L3 Networker
  • 3711 Views
  • 4 replies
  • 0 Likes

How paloalto security roles work

Hello Everyone I want to know about Paloalto security roles. I mention the problem I have In our system, there are many roles for internet access. All roles are assigned with active directory groups.A user can have one or more internet roles.For example: One user can have both "low internet" and "social internet". And the url filter of each one ...

Fagani by L2 Linker
  • 2680 Views
  • 3 replies
  • 0 Likes

Global Protect VPN - Mac OS Ventura

Hi Trying to install the VPN product GlobalProtect-6.1.0.pkg onto a M2 Laptop running Ventura. I get the Installation failed message and to contact the software manufacturer for assistance. Any ideas why it wont install? have admin rights as well.

Threat alert emails

I see threat alerts as critical but no words of block. Are these still getting thru even if flagged as an alert? How do I verify or change to alert and block?

MMurphy1 by L1 Bithead
  • 1473 Views
  • 1 replies
  • 0 Likes
  • 24431 Posts
  • 125 Subscriptions
Top Solution Authors
Labels