General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

VPN Bandwidth Load Balancing

Hi Team,

 

I have three VPN connection for three isp network. We need to load balance the VPN connection when it reaches to a particular threshold for example 75% or 80% then the traffic need to shift to other tunnels.

 

For example if one tunnels is bei

...

Resolved! How to reduce downtime when migrate to an AE interface

Hi All,

 

Am going to bundle an existing layer3 interface (e1/1)with extra one (e1/2 ) to an ae1 interface. And then move the ip address from e1/1 to ae1. 

This is in a HA A/P configure, question is how to reduce the downtime to roughly 0?

If it will imp

...

AllanGao by L1 Bithead
  • 2334 Views
  • 3 replies
  • 0 Likes

Resolved! U-Turn NAT question

When setup U-turn NAT, can see SNAT part using an internal interface for DIPP. But in the scenario A/P FW has two downstream switches, ie. two internal interfaces, if need to setup 2 U-turn NAT policies . So that when the primary link down, can use t

...

AllanGao by L1 Bithead
  • 2870 Views
  • 4 replies
  • 0 Likes

Resolved! Security Policy "Last Hit" metric

Hello,

How is the "Last Hit" metric for a security policy on the firewall generated? Would the timestamp be based on the session start time or the received time of the log? Intuitively I would think the former, but I am starting to think its the latte

...

Pc does not join into Domain

Hi,

I can not join into a domain when the computer pass through PA.

This is my scennario:

PC - PaloAlto - Switch - DomainController

The PC and Domain controller are in the same Zone (trust) and I have a security rule: from zone trust, to zone trust, perm

...

PA without license

Hello.

 

I hope you can help me. I currently have a customer who wants to leave one of their old APs unlicensed as a VPN concentrator. My question is the following:

 

What functions would be active in the PA?

 

For GP I checked this KB: https://knowledgeba

...

Policy Optimizer Reports

Hello Community,

Has anyone here found a decent way to have a report generated automatically on a periodic basis for the Policy Optimizer suggestions? I.e. A PDF generated every Monday morning with a list of Unused policies in the past 30 days, etc.?

 

...

Global Protect stuck in "Connecting", "Still Working"

Hi there guys, I have a Macbook Pro with Catalina v10.15.4 and I am here because I am out of moves on how to make this software to work. 

 

Troubleshooting I've tried so far:

1) Tried going to privacy and security in the settings to allow the software t

...

Packet Buffer Congestion error

Hello
We have a couple of FW 5220 in active-passive. last 07/15 we upgraded to version 9.1.10 and we have detected that "Packet Buffer Congestion" is growing linearly.

could it be a bug in this version?

thanks so much

packetbuffer.png
BigPalo by L4 Transporter
  • 5476 Views
  • 3 replies
  • 0 Likes

Captive Portal HTTPS SSL decrypt

Captive Portal HTTPS decrypt

 

Dear all:

 

Very good afternoon, I have the following doubts and concerns:

-Is it mandatory to configure SSL Decrypt ( I understand that yes, please confirm, it is for the point that when they enter a HTTPS site, it displays

...

Metgatz by L4 Transporter
  • 2503 Views
  • 2 replies
  • 0 Likes

server hello message dropped at firewall

We are facing currently this issue with a DC firewall. The following is the environment

EnduserPC-> DC Firewall (PAN) -> f5 Load Balancer-> Web Servers

 

All these days the users were able to login to the web services without any hassles. For the last 2

...

file saving issue through global protect

I'm facing issue at the time MS-Office files saving when global protect is connected.

Logs showing temp file (.rels ) .When we excluded temp file file blocking profile, after that its start to saving file.

But for long time we cant exclude temp file fr

...

SurajN by L2 Linker
  • 1904 Views
  • 1 replies
  • 0 Likes
  • 24204 Posts
  • 100 Subscriptions
Top Liked Authors
Labels