General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Panorama days behimd on receiving logs

My panorama, based on the spyglass on the monitor tab, shows the logs from the palo altos to be received days after the palo alto recorded them. Cannot find a reason or a fix. Have tried restarting both but problem persists.

tazzvon by • L0 Member
  • 2023 Views
  • 1 replies
  • 0 Likes

Resolved! How much traffic log generate in one day?

Hello everybody,I'm new in Palo alto&Panorama and need your help. In our company, we have PA-3220 and I need to know that how much traffic generate in Paloalto in everyday, but I couldn't find it.I just found that i can see in Panorama - managed collectorr but i don't know that is a correct or not.Thank youMahsa

Mahsa.Eb by • L0 Member
  • 3593 Views
  • 1 replies
  • 0 Likes

Resolved! Is it possible to use wildcard certificate as forward trust certificate?

I have a wildcard certificate that already works for global protect portal and gateway.I would like to make this trusted certificate to be used for SSL decryption (forward-proxy mode) but I can't make any of those certificate to be Forward Trust Certificate because the checkbox is greyed out.So, is it possible to use wildcard certificate as forw...

cert-palo.png
Screenshot_45.jpg
nugroho by • L1 Bithead
  • 10269 Views
  • 6 replies
  • 0 Likes

RDP Freeze Fix - GlobalProtect

Hello, We struggled with the RDP freezing issue with GlobalProtect for a long time. The initial "fix" was to disable UDP for RDP in the registry. This fixed the issue for many users but also slowed down the RDP performance. We thought the issue was with GlobalProtect but after troubleshooting with Palo Alto we were able to see that at some po...

Certificate

Hi Team, I have four DC and each DC has HA PA firewall. I have generate CSR from one DC firewall. After i received a sign in certificate from the one i Generate CSR. will that certificate be used in different DC firewall. Its a GP certificate.

Resolved! Dynamically update Microsoft Office URLs and IPs

Does anyone have any suggestions to dynamically update Microsoft Office 365 (including Sharepoint and Teams) URLs and IPs? Having to update a list of IPs and URLs is impractical and time consuming. Microsoft keeps updating their backend infrastructure through various CDNs, and having to update this has been time-consuming and tedious. How are ot...

Benzito by • L1 Bithead
  • 15456 Views
  • 4 replies
  • 0 Likes

Resolved! Can only access DMZ server using private address, U-turn NAT not working

Configuring a new PA-850, new to this so go easy on me. I have three zones, internal, outside, DMZ. DMZ webserver Private IP = 192.168.2.16 Public IP = 212.12.34.56 I have created two NAT rules as follows: internal u-turn to DMZ source zone = internal dest zone = outside dest address = 212.12.34.56 dest translated address = 192.168.2.16 ...

WilliamD by • L1 Bithead
  • 4439 Views
  • 2 replies
  • 0 Likes

Ping request traffic blocked by app id ICMP type 8

All of sudden ping request traffic got blocked by application filter ID ICMP type 8. It was permitting by app ID "ping", suddenly the request is detected as "ICMP type 8" in the logs and blocked. This is for all the traffic which was permitting through "ping" APP ID. Was there any update in signature?

Best guides for new Firewall Deployment

I am deploying a new firewall for a PoC however I am having some issues. I have deployed and activated the server on Azure, I am using VM-Series. However despite on the Azure side there being no restrictions, there server is not able to connect to the internet for updates. I must be missing something basic in understand/setup so any pointers wou...

Nhussain by • L1 Bithead
  • 4648 Views
  • 5 replies
  • 1 Likes

Get a new firewall?

I presently use a UDMP, and while I'm kind of satisfied with it, I'd like to learn a lot more about networking and be able to use firewalls much more effectively. Hosting my controller won't be a problem because I have several servers. We utilise Palo Alto firewalls in our cyber security department, and they are, to put it mildly, fascinating. I...

Resolved! HIPs check for Client Side Certificate

Is it possible to use HIPs to verify the presence of a Client Side Certificate such as GlobalProtect cert for a computer and also check for cert on a mobile device? If the device has the cert then we would allow it through a firewall policy.

CZellars by • L1 Bithead
  • 9364 Views
  • 8 replies
  • 1 Likes

PA-VM 10.0.4 Trial, gets shutdown after a minute.

Hi All, I have received a download link from Palo Alto and downloaded the OVA eval file, after importing the device to the VmWare, it becomes online but after 1-2 minutes gets shutdown. Please let me know how can I resolve the issue. Thanks

pan-shutdown.PNG
verg61 by • L1 Bithead
  • 10230 Views
  • 6 replies
  • 1 Likes

when upgrade 5260 to 9.1 and further intefaces are marked "POWER DOWN"

We tried to upgrade our 5260 firewalls (in active active scenario) from 9.0.16-h2 to 9.1 and further the interface don't come up ethernet1/5 68 ukn/ukn/down(power-down) 00:86:9c:60:xx:xx ethernet1/6 69 ukn/ukn/down(power-down) 00:86:9c:60:xx:xx ethernet1/7 70 ukn/ukn/down(power-down) 00:86:9c:60:xx:xx ethernet1/8 71 ukn/ukn/down(power-down) 00:8...

  • 24459 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels