General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Zone to zone interaction PBF

Hi All,

i have some doubts ....

1.i have three zone TRUST,DMZ,UNTRUST. 

2.there is a nat policy from TRUST zone, DMZ zone to untrust 

3.all interface is under same VR .and there i haven't add any static route yet. instead i create a PBF rule from bot

...

VRF lite two different set

I want to use two Virtual Router

VRF router-28 and VRF router-128

WRF-Router-28 for wan, inside DMz 

Second-Router-128 WAN, INSIDE and DMZ

Separation port connection for two set of DMZ, WAN and inside

this all allow for PA-440?  

I'm trying to use as

...

Resolved! CLI Arp table result

Hey, 
I wonder if the "Show arp all" command doenst show the IP - MAC pairs if they are not matching the IP range of the VLAN (which is defined by subinterface) ?

Like on the ethernet1/2.50 (which range is 10.66.50.1/24) i wont see the 10.66.51.X IP? 

Resolved! Failed to update content package

Good Evening,

I'm having problem installa dynamic updates (PA3020 sw ver 9.1.18) Application and Threats. Everytime I tried to install manually or authomatically I receive this error in system log

Failed to upgrade Content package to version <unknown

...

unibg_it by L1 Bithead
  • 1929 Views
  • 5 replies
  • 0 Likes

Error 503: Service Unavailable

Hello!

I am configuring  an ha cluster Fw 440.Firmware 10.1.3

 

When i push "commit" i lost gui access.

I can ping andaccessvia ssh to fw.

I recover the gui access via cli:request restart system.

 

I have updatefirmware to 10.1.11-h5 but i happen the

...

Cannot Create Account on CSP

Hi, we've received our PA-445 but cannot create a Customer Support Portal account for it.  After entering the serial number and sales order number I receive the following error:

 

Unable to create user account, request matches multiple Support Accoun

...

ewgnickp by L0 Member
  • 564 Views
  • 2 replies
  • 1 Likes

Right way of moving cable

Please find the exsisting set-up:

Juniper switch---ospf--->Palo-Alto firewall------------tunnel-----> External 3rd party Cisco Router

 

We are planning to change the Juniper switch to Cisco switch and make the configuration as below:

Cisco switch---o

...

Sujanya by L3 Networker
  • 653 Views
  • 2 replies
  • 1 Likes

PA410 Version: 10.2.7-h3 does not send logs to Panorama

Hi team, 

 

I got a question , after upgrading Panorama to 10.2.7-h3 the logs stopped to be reflected on. (PA-410 to Panorama) ( from PA-3250 to Panorma is working properly). So , I proceed doing the following :

 

1. We proceeded with the workaround

...

F.Pinar by L2 Linker
  • 571 Views
  • 1 replies
  • 0 Likes

Bug Search Tool

Hi all,

 

I've created a tool, that you might find helpful.

 

It can be tedious to search for specific bugs, or when a bug have been addressed. This tool gathers all known and addressed issues from all (not EoL) releases and makes it easier to filter

...

Threat name is Blank on Email report PDF attachment

Hi everyone,

 

Good day and greetings!

 

I have an unusual encounter with an email report pdf attachment. The threat names are blank but I can identify them by looking at the "Count" Like below snapshot.

 

Were this ever a bug or was intended to be

...

renzanjo11_0-1710747378203.png

Matching HIP in Decryption Policy

Anyone doing this? It is configurable in the policy itself but isn't referenced in any documentation. The firewalls seem to ignore the HIP profile configured in the decryption rule when matching/not matching traffic. 

 

When I configure the rule to mat

...

ccscott by L2 Linker
  • 4872 Views
  • 12 replies
  • 0 Likes

Applications not being identified correctly

I am running into a  number of situations where the applications are not being identified correctly and thus not working.  I can see that the applications is using the correct port, but the PA shows it is "web browsing", unknown, etc.  Examples:

KaKao

...

BobW by L4 Transporter
  • 2510 Views
  • 4 replies
  • 0 Likes

EDU-110/220 Still Available

I'm looking for the Self Paced version of the EDU-220 which used to be the EDU-110. Has this been removed. I don't have the time currently to go to an Instructor lead course and studying for my PCNSE.

 

Thanks

Griffin by L0 Member
  • 360 Views
  • 1 replies
  • 1 Likes
  • 24106 Posts
  • 102 Subscriptions
This widget could not be displayed.
Top Solution Authors
Top Liked Authors
Labels