General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Inconsistent policy action on the same traffic flow

Hello, I do have a connection flow for Microsoft Teams direct routing domain sip-all.pstnhub.microsoft.com where I do have a NAT rule and a security rules for bidirectional traffic with the Microsoft domain from our DMZ. The issue is that the firewall sometimes allows the traffic from one of the IP addresses that it resolves to (e.g. 52.114.76.7...

bambox by • L1 Bithead
  • 4512 Views
  • 3 replies
  • 0 Likes

Does Palo Alto Support IPv6 source NAtting for IPV4 addresses

Hi Everyone, We had recently bought an ISP connectivity and we had got the IPv6 address. When we configure natting for IPV6 host to ISP IPv6 IP address it is working but we need to provide internet access to IPv4 devices on our environment. We need to know whether it is possible to perform Source NAT translation of IPv4 LAN network devices to I...

Inter-working of PBF and DHCP Relay

Hi All, I have a query regarding DHCP Relay working with Policy based forwarding. We have a setup where DHCP relay is configured on firewall and DHCP server is in remote location reached via IPsec tunnel. We have 2 IPsec tunnels configured (tunnel1 & tunnel2). We want to configure VPN failover with PBF monitoring the DHCP server IP. PB...

Web Application intermittently having a performance issue

From the tcp dump at the server end, I am seeing a lot of traces on TCP Dup ACK, retransmission and out of order being flag out at the pcap file The connection made is via VPN client to the Web Application server. Tried few scenario where we access directly bypass the PaloAlto firewall and we don't see this traces on tcp dups and retransmissi...

afifdin_0-1618935667620.png
afifdin_1-1618935712790.png
afifdin_2-1618935811755.png
afifdin by • L0 Member
  • 6247 Views
  • 3 replies
  • 0 Likes

Policy Commit Failed

I am trying to push a template stack to FW, the same one is pushed to a lot other FWs but here i get this error . In virtual-router vr1, OSPFv2 is not supported on unnumbered interface ethernet1/1 in area 0.0.0.0.. In virtual-router vr1, OSPFv2 is not supported on unnumbered interface ethernet1/2 in area 0.0.0.0.

Resolved! Error No valid URL filtering license

Hi All, Recently license has been renewed and part of the renewal was change to "Advanced URL Filtering". I got the error whenever commit a change. But looking at the licenses section I can see PAN-DB URL Filtering listed as expired. Any step to fix this issue or I need to check with TAC?Thanks !!

isentric89_0-1645597092589.png

Resolved! QoS - show drops in web view

Hi there, where can I find the packet drops of an interface in the PA web frontend, I wanna monitor the QoS function, without the use of ssh command line tool.

Netzer by • L3 Networker
  • 3217 Views
  • 2 replies
  • 0 Likes

URL allow list for some of the subdomains

Hi all I want to limit the user to access the company's sharepoint only, but not other sharepoint from other tenant or even the sharepoint from personal account. Then I found the below KB (section 6) and show how to use allow list in the URL filtering profile to block *.sharepoint.com but allow company.sharepoint.com. But I cannot find the allow...

alextsa by • L1 Bithead
  • 11273 Views
  • 8 replies
  • 0 Likes

Decryption GitHub not working

Hi We are trying to run a api from passbolt to Github. In this we are doind decryption in PA. If we add a SSL exception *.github.com is working fine or "no decrypt" policy is working fine. any idea? Here our health check: passbolt]# su -s /bin/bash -c "./bin/cake passbolt healthcheck" nginx ____ __ ____/ __ \____ _____ ____/ /_ ____ / / /_/ /_...

BigPalo by • L4 Transporter
  • 5440 Views
  • 2 replies
  • 0 Likes

Resolved! Panorama logs per second

Does upgrading the CPU and memory for panorama increase the logs per second that a single virtual panorama in panorama mode can handle? Link below appears to show that as the case. I always thought that the limits were around 10k per second regardless. Upsizing specs must increase that? https://docs.paloaltonetworks.com/panorama/10-1/panor...

Sec101 by • L4 Transporter
  • 4340 Views
  • 3 replies
  • 0 Likes

DNS resolution stops working as long as GlobalProtect connected

hello guys, Some of the users got the DNS issue for the external websites after globalprotect connected, the users are able to ping the external IP address but just the DNS does not work.There was no change applied to the Firewall recently and only a few users got this issue.not sure if someone else got the same issue and how did you fix that? T...

DongQu by • L2 Linker
  • 2098 Views
  • 1 replies
  • 0 Likes
  • 24463 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels