General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 350 Views
  • 0 replies
  • 0 Likes

Resolved! Transparenlty NATing IPsec traffic to other device

Hello,

 

We have an issue with forwarding an IPsec connection to a VPN device behind the PAN-OS FW.

 

So the setup is supposed to be the following:
* PAN-OS is using outside interface 192.168.1.1/24
* 192.168.1.2 is an address with DNAT to 10.10.10.1 on an

...

ifstciss by L1 Bithead
  • 2291 Views
  • 1 replies
  • 0 Likes

Resolved! Cannot reach server at DMZ via Nat

Hi 

NAT is setup at PA for outside users to reach DMZ server based on protocol
The topology is like the below:

SW1(f1/1) -------- (e1/1,DMZ)PA(Outside,e1/5)--------(f1/5)SW2

Interface config:

e1/1 10.100.255.1/24
f1/1 10.100.255.2/24 as inside Server

e1/5 4

...

DavidyPalo_0-1640193938552.png
DavidyPalo_1-1640192264988.png
DavidyPalo_2-1640192562824.png

Agentless User-ID Not Connected (RESOLVED)

EDIT: I have resolved my issue... adding this in case someone runs into the same issue I did. Basically, I'm an idiot lol. Issue was because my AD servers are in a security zone and I needed to add a security policy that allowed the management IP add
...

Resolved! Firewall Events as Report

Hi All,

 

Is there a way where, I can generate report of firewall events, Like login events from system logs, As daily basis. And I will share through email. 

 

NGFW 

Migrate Panorama from VMware to AWS

Has anybody migrated Panorama from on prem to AWS? There are a few options that are available to us, and I am trying to decide which option is the best. Also, if you can list any "gotchas" during the migration that would benefit us, that would be rea

...

Fr4nk4 by L2 Linker
  • 3653 Views
  • 2 replies
  • 0 Likes

Resolved! IPSEC ON SECONDARY ADDRESSES

Hello,

just a little question it is possible to terminate a vpn-ipsec with a secondary adresses on external interface or I must use the main interface?

thks,

ALex

alle by L3 Networker
  • 4137 Views
  • 3 replies
  • 0 Likes

Resolved! SSL forward-proxy certificate import

I've gerenated a CSR to give my enterprise CA. Now, I've recieved the enterprise CA-signed certificate ann imported it onto the firewall.

The status reads "valid". The "Key" box is checked, however the "CA" box isn't. 

Also, when I select the certifica

...

Geoblocking Missing

We are on 8.1.21 - When creating a geoblocking rule I do not have the option for 'Regions' in my rule drop down.  Is this due to my version OR do i need to upload a geoblocking list [how?]

 

thanks!

NAT before IPSEC

Hi folks,

 

We have a vendor requiring a public IP for the encrypted traffic.  Their guidance is based on Cisco configurations using "NAT before IPSEC" configurations.  Can anyone share/link a guide for this configuration on Palo?  Currently on PAN-OS

...

dmz data flow

Hi,

 

Please advise 

Hi,

I have a design flaw . I am trying to test dual dmz . dmz server the gateway is on the dmz firewall . 

If the server in dmz wants to send data to dc server it has to go back through the same switch 

 

How to avoid this ? 

 

And also,

...

dual dmz.PNG
simsim by L4 Transporter
  • 3932 Views
  • 7 replies
  • 0 Likes
  • 23830 Posts
  • 112 Subscriptions
Top Liked Authors
Labels