General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

"end" but no "start" log while session breakdown. logging set to start and end of session

Hello, we have the following issue: Customer complains, that their web services, that are reachable from the internet through a palo alto firewall, show sporadic breakdown of incoming ssl connections for a couple of minutes. After analyzing the logs on the palo alto, I see in the corresponding time frame log entries with type session "end", but ...

Resolved! Dynamic IP and Port - Session Browser s2c

Hi All, Firstly many thanks for checking out my query. I have a virtual router that has an ISP connection. This ISP has assigned us a /30. I have configured an interface on the FW with the designated add from the /30, this address is used to NAT our clients to access the Internet using dynamic ip-and-port (nat overload). The internal client ...

DForde by L1 Bithead
  • 2353 Views
  • 1 replies
  • 0 Likes

MFA no longer active/available at all

Hello,i read the info from april 14th, that mfa is mandatory in the future.Before, i had mfa enabled with the authenticator app, which worked fine.Since the information, no mfa at all is active/available on the account.

Access to PA-200 Web GUI is Denied.

When I open up a https://if_of_pa-200I get access denied message with You dont have authorization to view this page.I have logged into this firewall many times before but have not for several months now.I can use putty to get into the console. I found some online solution that would give this error is I was out of space.My root partition was at...

Omni918 by L1 Bithead
  • 7884 Views
  • 10 replies
  • 0 Likes

Resolved! VPN proxy ID limitation Error

Is this still an issue and or what models pertain to this? I see the Pan os version is old on this article, but does anyone know if the limit here still applies? If it's been increased, what has it been increased to per model? Appears that aritcle/documentation is harder to find. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?i...

Sec101 by L4 Transporter
  • 3525 Views
  • 1 replies
  • 0 Likes

Daul ISP and specific ISP routing

Good Afternoon All I have read the various methods for Dual ISP configuration and they make sense. I could not find one last detail and I was hoping someone here could help. Desired Configuration: ISP 1 = Active for outbound traffic during normal operations.ISP 2 = Inactive1 Client IP on the internet network to have its traffic routed out via IS...

Mort2k by L0 Member
  • 2395 Views
  • 1 replies
  • 0 Likes

Resolved! Passing a Circuit Prefix Through Palo Firewall

I'll do my best to put this question into words.My company owns a /24 Public IP range. I have an engineering department that needs a /29 IP space off of that block for their Lab Environment. I have a Juniper MX104 Router and a Palo 5220 Firewall.I'm not sure what my best steps are to get this circuit passed through the Firewall straight to the L...

Resolved! how to Revert configuration by cli - pa 200 v 9.0.14

Hi Guys, we have a problem on a HA pair, the secondary firewall is no longer accessible via either GUI or CLI.We can only connect via console, to restore one of the saved and working configurations, is it necessary to do only these commands? > configure # load config+ key key> from Filename> last-saved Last saved conf...

MAerre by L2 Linker
  • 7525 Views
  • 2 replies
  • 0 Likes

Resolved! TLS version for WEB UI

Hi All,I am trying to check what all TLS version is allowed for firewall web UI .Is there way we can validate this. ? Thanks .

S2S VPN 2 VRs not working

Hello, I have an external IP /30 network. I also have another external IP /28.I have created 2 VRs (with their ZONES).VR1 is the main router with the /30 IP used for Internet connection.VR2 is the second router (the one I just created)I assigned one of the /28 IP to the second VR. When I terminate a S2S vpn (from another PA Box) to this IP(/28) ...

Pantelis by L1 Bithead
  • 2354 Views
  • 2 replies
  • 0 Likes

Resolved! rename a subinterface

Hello,I need to know if it's possible to rename a subinterface, I see that is not available this field to be changed, then I need to know how should be the process to do that. thanks!!!!

Agentless user id issue

i am facing user id issue it's show connected but some time is not show not connected. when i check the USER-ID log i find this error. please suggest. Error: pan_user_id_win_log_query(pan_user_id_win.c:1364): log query for <Server-IP > failed: NTSTATUS: NT code 0xc002001b - NT code 0xc002001b2020-09-03 13:09:08.934 +0400 Error: pan_user_i...

Captive Portal HTTP only landing page?

Hi,I have set up the CP successfully. I see the CP is running on PA redirect IP:6082 with HTTPS.Is there any way that we can use HTTP only on the CP landing page?like http://PA_redirect_IP:6082not https://PA_redirect_IP:6082We are not using credentials for CP login, our CP just accept and go.No SSL encryption and protection needed.So, does PA st...

natwong by L0 Member
  • 2759 Views
  • 2 replies
  • 0 Likes
  • 24431 Posts
  • 125 Subscriptions
Top Solution Authors
Labels