General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! BGP on PanOS: allow route with own as number in as-path

hi,

i am new to panos and have problems in allowing a route with its own as number in as-path incoming from a peer. looks like the route is not accepted as a loop prevention but it is just the fact that the as number is used twice as two companies con

...

daniel by L0 Member
  • 2954 Views
  • 1 replies
  • 0 Likes

10.0 user-id agent ignore_user_list not working

Since upgrading to pan os 10.0.6, we've noticed the "ignore_user_list" on our server user-id agents doesn't seem to be working.  We did not have any issues prior to upgrading to 10.0.x.  Has anyone else noticed this issue?  We upgraded our user-id ag

...

jmurphy by L2 Linker
  • 1738 Views
  • 1 replies
  • 0 Likes

Http traffic to https

Hi Guys 
Can we redirect someone trying to access http://www.xxx.com to https://www.xxx.com ( port 80 to 443 ) ?

If we are using Dest NAT for https://www.xxx.com ? 

Thanks 

i_maddy by L0 Member
  • 1688 Views
  • 1 replies
  • 0 Likes

Resolved! Assign multiple netflow profile to an interface

Hi All

We have multiple netflow servers in the environment and i want to configure palo alto firewall interface with multiple netflow server profiles. I have already one netflow server profile attached to my Layer3 interfaces and now i want to configu

...

Resolved! GlobalProtect uninstall problem

Hi,

Our user have a problem with GlobalProtect client on a computer running Windows 8. Client was behaving very unpredictable (constantly connecting and disconnecting from the VPN), so it is uninstalled (from Control Panel\Programs\Programs and Featur

...

Decrypt GlobalProtect traffic

Hi Guys!

I have a GlobalProtect (IPSec) configuration with an external gateway, all remote user traffic goes through the vpn tunnel, to which I apply decrypt policies for this traffic.
The problem is that in applications like "teams", it is not possibl

...

PA-220 Thermal Shutdown

Morning All,

 

Here in the UK, we are in the midst of a heatwave and we have had 2 PA-220's shutdown for heat issues.

 

I can't find anywhere at what temperature the Palo shutdown due to temps? I thought it was the MAX Chasis temp, however, we have anoth

...

Guide for mp-log and dp-log troubleshooting

Hi All,

 

Is there a comprehensive guide for knowing which logs to look at in the mp-log and dp-log eg. what log files to look when troubleshooting a particular issue on.

 

For example if im troubleshooting some OSPF issue, i can look at the mp-log route

...

Timeout while adding ip address to block list

Hello Everyone,

 

trying to get this container working which is good until the part where I push IP from let's another SIEM into minemeld it gives timeout error.
I have another instance running on Linux 16.04 and this container is 20.04.

Configs were

...

rosmanov by L0 Member
  • 1283 Views
  • 0 replies
  • 0 Likes

Settings missing in Management Interface

I cannot see any option to change any Management Interface settings under Device > Setup > Interface.

>show system info is showing ip-assignment: dhcp. I need to change it to Static.

I have tried the commands below but no change.

> configure
# set device

...

Interface Settings.jpg

Prototype and Miner for IPv6 Lists

Looking for some guidance on how to create a prototype to pull IPv6 addresses from a hosted CSV/txt file.

Currently I have IPv4 working:

 

 

Here's what I have for IPv6 but it isn't working. I've messed around with many different IPv6 regex with no

...

mgarippoNDIT_0-1626818194014.png
mgarippoNDIT_1-1626818404828.png

Traffic block due to EDL

I have found traffic blocked due to edl inbound policy. Traffic is blocked for random time like hour or one and half hours for random port.after some time traffic is moving. Another thing is traffic is moving for one destination ip and this destinati

...

SurajN by L2 Linker
  • 1741 Views
  • 1 replies
  • 0 Likes

PA 410 reboot time

Anyone know the reboot time on a PA 410?  Looking to see if its better than the PA 220.

 

Thank you,

Ted

treese by L3 Networker
  • 2234 Views
  • 2 replies
  • 0 Likes

Resolved! Required permissions for Active Directory integration

Hello,

 

I am trying to get AD authentication to work for GlobalProtect.  I have been following this document https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmAdCAK for configuring the AD integration part, and it says:

 

Before

...

  • 24034 Posts
  • 102 Subscriptions
Top Liked Authors
Labels