General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4109 Views
  • 0 replies
  • 0 Likes

NAT before IPSEC

Hi folks, We have a vendor requiring a public IP for the encrypted traffic. Their guidance is based on Cisco configurations using "NAT before IPSEC" configurations. Can anyone share/link a guide for this configuration on Palo? Currently on PAN-OS 9.0 should it matter. Thank you.

Update to PAN-OS 10.0.8-h4 causes slow GUI response on PA-820

Hello,After updating our PA-820's to 10.0.8-h4 I have noticed the GUI to be extremely slow to respond. I am actually getting a faster GUI response from a PA-220 on 10.0.7 than our PA-820's. Has anyone else noticed this? Waiting for 'Monitor, Traffic' is incredibly slow and almost unusable. It can take up to 25 seconds for the screen to respo...

dmz data flow

Hi, Please advise Hi,I have a design flaw . I am trying to test dual dmz . dmz server the gateway is on the dmz firewall . If the server in dmz wants to send data to dc server it has to go back through the same switch How to avoid this ? And also, please point out pros and cons for the below design Thanks

dual dmz.PNG
simsim by L4 Transporter
  • 5221 Views
  • 7 replies
  • 0 Likes

Resolved! GlobalProtect MAC Address Filter?

Hello folks, I am being asked if GlobalProtect could be locked down to only except a specific list of MAC addresses (our corporate laptops) only. I see information about Device Block list or HIP configuration. I don't really want to specify a block list, but rather an allow list and block everything else. Is that possible? We using PA 3020 ...

OMatlock by L4 Transporter
  • 13712 Views
  • 6 replies
  • 0 Likes

Resolved! Unable to Commit

I've just changed the configuration of the management ip address, but can't commit the change. When I attempt to submit it I get the following error: admin@PA-3050# commit...ID population failedError: id 10630 is outside allowed range [1-3583](Module: device)Commit failed admin@PA-3050# show deviceconfig systemsystem {ip-address 192.168.0.50;ne...

Resolved! A connection issue between PA and SW

Hi, PA port e1/2 is connected to switch port f1/5(L3). Both devices can see each other's ip and mac address. The Virtual router and Security zone and Magagement profile Ping are configured. but both devices cannot ping each other. Did I miss some step? Thank you

Resolved! OSPF v2 and v3 in PA

Hi, ospf is configured at the PA. please see the below screenshot. but after commit, it shows the below error message. Based on the picture, PA is using ospf2, why it shows the erro message? Thank you

DavidyPalo_0-1640018474562.png

Globalprotect PanGPS service

Sometimes our Globalprotect client application stops working on windows 10 OS.It seem to start after an uninstall\reinstall happend.After the reinstall, GP works, but then when the user reboot or logoff\login to windows, and start GP,GP removes the PanGPS service and stops working. If I do a quick repair, it works again until the next reboot. I ...

URL Override is missing

Hello, I just upgraded to PAN-OS 9.0.0 succesfully, but I cannot find the URL Override setting? Does anyone know where is it located? Thanks.

qafcopa by L1 Bithead
  • 4620 Views
  • 4 replies
  • 0 Likes

Port Mirror Query

Hi Team,Palo Alto port mirroring will forward only a copy of encrypted traffic "https" after decrypting itor also can forward un-encrypted traffic "http" as well

PA-220 not reaching Palo Alto

Our company was recently sold off and their IT department erased our firewalls leaving them reset back the to manufacturer’s configuration. I’ve built it back as much as possible, but I’m missing something. I’ve worked with other firewall devices, but PA is proving challenging. How do I configure it to connect to serverlist.paloaltonetworks.com,...

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels