General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 388 Views
  • 0 replies
  • 0 Likes

GlobalProtect multiple gateways

Hi All,

 

Similar to a Cisco ASA tunnel-group configuration where we can have different VPN configurations using the same public IP, I wonder if similar configuration can be achived on Palo Alto. My objective would be to configure different gateways us

...

ipsec question

Hello,

Do I need a tunnel interface for site to site vpn ? 

If yes How can I do that and what is the benefit 

Thanks 

 

 

 

tifotano by L0 Member
  • 1517 Views
  • 1 replies
  • 0 Likes

destination port in PBF

Is there an option to define destination port in PBF. Now if a service is selected, PA applies PBF if source or destination has that port.

I am looking for a PBF which should match only if destination port is 80.

ceapen01 by L2 Linker
  • 2013 Views
  • 3 replies
  • 0 Likes

Resolved! Always on Global Protect

Hello All,

Looking to get advice on this topic. The idea is to have the users connect via a VPN tunnel regardless of their location, internal LAN or working from home, etc. I need to make it easy on the users so its to a burden, e.g. having to authen

...

exclude a network from static route

Is it possible to exclude a network from static route.

 

For eg  I have static route 10.20.0.0/16 to the core-switch.

unfortunately my management network (including PA) is 10.20.200.0/24

I dont want traffic to 10.20.200.0/24 going to core switch.

 

just ex

...

ceapen01 by L2 Linker
  • 3209 Views
  • 3 replies
  • 0 Likes

LDAP-S Authentification failed (LDAP-S with TLS1 ?)

Hi,

 

while using LDAP-S (port 636) on a PAN Firewall for a connection to an active directory on a Windows Server 2019 I have the problem that the Firewall just can't connect.

 

If I try the "test" command for testing the authentication profile I get thi

...

maximum length of TACACS User ID

We use TACACS+ server for admin authentication.

 

Is there a limit on the length of an ID?  I have one that is 40 characters (we use email IDs).

 

Getting an auth-success log message for this user, but then a Critical "create-admin-acct-error" message:

 

F

...

cdwing by L1 Bithead
  • 2480 Views
  • 2 replies
  • 0 Likes

PRTG monitoring thresholds

Hello, i am implementing PRTG and monitoring my PAs. We can monitor CPU, Disk free and Memory. My question is which should be the thresholds and how to react?

PaloAlto_LiveCommunity.PNG

interest in a MineMeld ESXi 6.5 OVA?

I have a working OVA of MineMeld installed on Ubuntu 18.04 server. One of the guys here where I work put in a ton of hours getting it installed and working. Is anyone interested in getting a copy.

If so does anyone know a good repository to put it?

Mattk by L2 Linker
  • 2281 Views
  • 1 replies
  • 0 Likes
  • 23842 Posts
  • 112 Subscriptions
Labels