General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 2157 Views
  • 0 replies
  • 0 Likes

Resolved! IPSEC ON SECONDARY ADDRESSES

Hello,

just a little question it is possible to terminate a vpn-ipsec with a secondary adresses on external interface or I must use the main interface?

thks,

ALex

alle by L3 Networker
  • 4697 Views
  • 3 replies
  • 0 Likes

Resolved! SSL forward-proxy certificate import

I've gerenated a CSR to give my enterprise CA. Now, I've recieved the enterprise CA-signed certificate ann imported it onto the firewall.

The status reads "valid". The "Key" box is checked, however the "CA" box isn't. 

Also, when I select the certifica

...

Geoblocking Missing

We are on 8.1.21 - When creating a geoblocking rule I do not have the option for 'Regions' in my rule drop down.  Is this due to my version OR do i need to upload a geoblocking list [how?]

 

thanks!

NAT before IPSEC

Hi folks,

 

We have a vendor requiring a public IP for the encrypted traffic.  Their guidance is based on Cisco configurations using "NAT before IPSEC" configurations.  Can anyone share/link a guide for this configuration on Palo?  Currently on PAN-OS

...

dmz data flow

Hi,

 

Please advise 

Hi,

I have a design flaw . I am trying to test dual dmz . dmz server the gateway is on the dmz firewall . 

If the server in dmz wants to send data to dc server it has to go back through the same switch 

 

How to avoid this ? 

 

And also,

...

dual dmz.PNG
simsim by L4 Transporter
  • 4789 Views
  • 7 replies
  • 0 Likes

Resolved! GlobalProtect MAC Address Filter?

Hello folks,

 

I am being asked if GlobalProtect could be locked down to only except a specific list of MAC addresses (our corporate laptops) only.  

 

I see information about Device Block list or HIP configuration.  I don't really want to specify a bloc

...

OMatlock by L4 Transporter
  • 13115 Views
  • 6 replies
  • 0 Likes

Resolved! Unable to Commit

I've just changed the configuration of the management ip address, but can't commit the change. When I attempt to submit it I get the following error:

 

admin@PA-3050# commit


...
ID population failed
Error: id 10630 is outside allowed range [1-3583]
(Module

...

Resolved! A connection issue between PA and SW

Hi, PA port e1/2 is connected to switch port f1/5(L3). Both devices can see each other's ip and mac address. The Virtual router and Security zone and Magagement profile Ping are configured. but both devices cannot ping each other. Did I miss some ste

...

  • 24247 Posts
  • 119 Subscriptions
Top Liked Authors
Labels