General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 549 Views
  • 0 replies
  • 2 Likes

HTTP brute force alerts to gameplayapi.intel.com

I have started noticing PaloAlto firewall generating a lot of HTTP brute force alerts with the URL gameplayapi.intel.com/api/games/getagsgames2/ . Do any of you aware of what this could be? I couldn't find anything malicious related to this but I'm s

...

Resolved! GlobalProtect - failed to allow *.google.com through the VPN

hello everyone

 

Merry Xmas,

 

Our SSLVPN has tunnel split enabled, but I want to allow all my traffic or the *.google.com through the VPN, so I tried:

1. added 0.0.0.0/0 to here, does not work.

2. added *.google.com to here, does not work.

 

Can please some

...

DongQu_0-1640352331374.png
DongQu_1-1640352422177.png
DongQu by L2 Linker
  • 5504 Views
  • 8 replies
  • 0 Likes

Firewall dropping HTTP only from specific source network

Hello. I've come upon an extremely strange situation that I'm hoping to get some assistance on. I've already opened a case with Palo support, but they seem to be at a loss as well.

 

For one specific internal network, the edge Palo Alto is dropping HTT

...

mhill99 by L0 Member
  • 2371 Views
  • 3 replies
  • 0 Likes

Palo Alto SDWAN zone

I am deploying Palo Alto SDWAN and the hub currently terminates dedicated L2 WAN circuits for each remote site. My plan is to build tunnels to each site across their dedicated L2 WAN and across the Internet. Example:

 

Palo Hub connects to site 1 on e1

...

BBartik by L2 Linker
  • 1786 Views
  • 1 replies
  • 0 Likes

help

PA2020  had factory reset  

its show Unable to create directory /mnt/panrepo

and  can't into maint

Can someone explain what the problem is?

ALiu25 by L0 Member
  • 2189 Views
  • 3 replies
  • 0 Likes

40 g connectivity

Hi,

I have the below topology 

 

 

PA has two 40 g ports and my core has 4 40g ports . server SW  also has  40 g ports ( the switch is for connecting servers ) 
core required two 40g Ports for cross-connection.

So remaining two 40g connections,

Do I need to

...

pa1.png
simsim by L4 Transporter
  • 2967 Views
  • 6 replies
  • 0 Likes

Resolved! Transparenlty NATing IPsec traffic to other device

Hello,

 

We have an issue with forwarding an IPsec connection to a VPN device behind the PAN-OS FW.

 

So the setup is supposed to be the following:
* PAN-OS is using outside interface 192.168.1.1/24
* 192.168.1.2 is an address with DNAT to 10.10.10.1 on an

...

ifstciss by L1 Bithead
  • 2222 Views
  • 1 replies
  • 0 Likes

Resolved! Cannot reach server at DMZ via Nat

Hi 

NAT is setup at PA for outside users to reach DMZ server based on protocol
The topology is like the below:

SW1(f1/1) -------- (e1/1,DMZ)PA(Outside,e1/5)--------(f1/5)SW2

Interface config:

e1/1 10.100.255.1/24
f1/1 10.100.255.2/24 as inside Server

e1/5 4

...

DavidyPalo_0-1640193938552.png
DavidyPalo_1-1640192264988.png
DavidyPalo_2-1640192562824.png

Agentless User-ID Not Connected (RESOLVED)

EDIT: I have resolved my issue... adding this in case someone runs into the same issue I did. Basically, I'm an idiot lol. Issue was because my AD servers are in a security zone and I needed to add a security policy that allowed the management IP add
...

Resolved! Firewall Events as Report

Hi All,

 

Is there a way where, I can generate report of firewall events, Like login events from system logs, As daily basis. And I will share through email. 

 

NGFW 

Migrate Panorama from VMware to AWS

Has anybody migrated Panorama from on prem to AWS? There are a few options that are available to us, and I am trying to decide which option is the best. Also, if you can list any "gotchas" during the migration that would benefit us, that would be rea

...

Fr4nk4 by L2 Linker
  • 3570 Views
  • 2 replies
  • 0 Likes

Resolved! IPSEC ON SECONDARY ADDRESSES

Hello,

just a little question it is possible to terminate a vpn-ipsec with a secondary adresses on external interface or I must use the main interface?

thks,

ALex

alle by L3 Networker
  • 4059 Views
  • 3 replies
  • 0 Likes
  • 23742 Posts
  • 110 Subscriptions
Top Solution Authors
Top Liked Authors
Labels