General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 777 Views
  • 0 replies
  • 0 Likes

Include or Exclude Subnetworks for User Mapping

I would like to know when to use Include or Exclude Subnetworks for User Mapping. in other words I would like to know whether it is used when we use agentless user id or external user id agent or in both cases?

 

 

 

 

 

 

 

perumalj by L2 Linker
  • 1792 Views
  • 1 replies
  • 0 Likes

Resolved! Viewing BGP traffic logs

We have BGP setup between our core switches and out Palo Alto FWs but I never see any traffic logs for port 179 or application BGP on the Palo Altos.

 

How do I go about seeing this traffic ?

iqbal786 by L0 Member
  • 10995 Views
  • 2 replies
  • 0 Likes

Sort feature would be helpful

I'm fairly new to Palo Alto gear and wanted to submit a suggestion about adding a sort capability to the information presented in the various tabs/pages. Just a few examples on the benefits of being able to sort: Trying to find that one rule where yo

...

HTTP brute force alerts to gameplayapi.intel.com

I have started noticing PaloAlto firewall generating a lot of HTTP brute force alerts with the URL gameplayapi.intel.com/api/games/getagsgames2/ . Do any of you aware of what this could be? I couldn't find anything malicious related to this but I'm s

...

Resolved! GlobalProtect - failed to allow *.google.com through the VPN

hello everyone

 

Merry Xmas,

 

Our SSLVPN has tunnel split enabled, but I want to allow all my traffic or the *.google.com through the VPN, so I tried:

1. added 0.0.0.0/0 to here, does not work.

2. added *.google.com to here, does not work.

 

Can please some

...

DongQu_0-1640352331374.png
DongQu_1-1640352422177.png
DongQu by L2 Linker
  • 6041 Views
  • 8 replies
  • 0 Likes

Firewall dropping HTTP only from specific source network

Hello. I've come upon an extremely strange situation that I'm hoping to get some assistance on. I've already opened a case with Palo support, but they seem to be at a loss as well.

 

For one specific internal network, the edge Palo Alto is dropping HTT

...

mhill99 by L0 Member
  • 2626 Views
  • 3 replies
  • 0 Likes

Palo Alto SDWAN zone

I am deploying Palo Alto SDWAN and the hub currently terminates dedicated L2 WAN circuits for each remote site. My plan is to build tunnels to each site across their dedicated L2 WAN and across the Internet. Example:

 

Palo Hub connects to site 1 on e1

...

BBartik by L2 Linker
  • 1889 Views
  • 1 replies
  • 0 Likes

help

PA2020  had factory reset  

its show Unable to create directory /mnt/panrepo

and  can't into maint

Can someone explain what the problem is?

ALiu25 by L0 Member
  • 2307 Views
  • 3 replies
  • 0 Likes

40 g connectivity

Hi,

I have the below topology 

 

 

PA has two 40 g ports and my core has 4 40g ports . server SW  also has  40 g ports ( the switch is for connecting servers ) 
core required two 40g Ports for cross-connection.

So remaining two 40g connections,

Do I need to

...

pa1.png
simsim by L4 Transporter
  • 3218 Views
  • 6 replies
  • 0 Likes

Resolved! Transparenlty NATing IPsec traffic to other device

Hello,

 

We have an issue with forwarding an IPsec connection to a VPN device behind the PAN-OS FW.

 

So the setup is supposed to be the following:
* PAN-OS is using outside interface 192.168.1.1/24
* 192.168.1.2 is an address with DNAT to 10.10.10.1 on an

...

ifstciss by L1 Bithead
  • 2395 Views
  • 1 replies
  • 0 Likes

Resolved! Cannot reach server at DMZ via Nat

Hi 

NAT is setup at PA for outside users to reach DMZ server based on protocol
The topology is like the below:

SW1(f1/1) -------- (e1/1,DMZ)PA(Outside,e1/5)--------(f1/5)SW2

Interface config:

e1/1 10.100.255.1/24
f1/1 10.100.255.2/24 as inside Server

e1/5 4

...

DavidyPalo_0-1640193938552.png
DavidyPalo_1-1640192264988.png
DavidyPalo_2-1640192562824.png
  • 23985 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Authors
Labels