General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4223 Views
  • 0 replies
  • 0 Likes

40 g connectivity

Hi,I have the below topology PA has two 40 g ports and my core has 4 40g ports . server SW also has 40 g ports ( the switch is for connecting servers ) core required two 40g Ports for cross-connection.So remaining two 40g connections,Do I need to use it to connect the DC fW,or yes which link ?or Do I need to use it to connect to server swit...

pa1.png
simsim by L4 Transporter
  • 4172 Views
  • 6 replies
  • 0 Likes

LDAP Authentication not working when using include group settings

Hi Team, We had configured LDAP authentication on Palo alto firewall. The LDAP server had been configured and we had checked the connectivity and it was successful. Created an group mapping and included an group in the include group mapping. Checked the groups and the user details via CLI of the firewall and could see that the user under the in...

Resolved! Transparenlty NATing IPsec traffic to other device

Hello, We have an issue with forwarding an IPsec connection to a VPN device behind the PAN-OS FW. So the setup is supposed to be the following:* PAN-OS is using outside interface 192.168.1.1/24* 192.168.1.2 is an address with DNAT to 10.10.10.1 on an internal vlanNote that the FW also processes IPsec VPNs itself on its own IP 192.168.1.1. NAT ru...

ifstciss by L1 Bithead
  • 2846 Views
  • 1 replies
  • 0 Likes

Resolved! Cannot reach server at DMZ via Nat

Hi NAT is setup at PA for outside users to reach DMZ server based on protocolThe topology is like the below:SW1(f1/1) -------- (e1/1,DMZ)PA(Outside,e1/5)--------(f1/5)SW2Interface config:e1/1 10.100.255.1/24f1/1 10.100.255.2/24 as inside Servere1/5 44.33.22.1/24f1/5 44.33.22.2/24 as outside UsersPlease see below PA configurations for NAT and Sec...

DavidyPalo_0-1640193938552.png
DavidyPalo_1-1640192264988.png
DavidyPalo_2-1640192562824.png

Agentless User-ID Not Connected (RESOLVED)

EDIT: I have resolved my issue... adding this in case someone runs into the same issue I did. Basically, I'm an idiot lol. Issue was because my AD servers are in a security zone and I needed to add a security policy that allowed the management IP address of the Palo into the AD Zone. Once that was added, I get a connected status in Server Monito...

Resolved! Firewall Events as Report

Hi All, Is there a way where, I can generate report of firewall events, Like login events from system logs, As daily basis. And I will share through email. NGFW

Migrate Panorama from VMware to AWS

Has anybody migrated Panorama from on prem to AWS? There are a few options that are available to us, and I am trying to decide which option is the best. Also, if you can list any "gotchas" during the migration that would benefit us, that would be really helpful.These are the options that I see. Option 1: Use SRM and our connected VMware on Cloud...

Fr4nk4 by L2 Linker
  • 4676 Views
  • 2 replies
  • 0 Likes

Resolved! IPSEC ON SECONDARY ADDRESSES

Hello,just a little question it is possible to terminate a vpn-ipsec with a secondary adresses on external interface or I must use the main interface?thks,ALex

alle by L3 Networker
  • 5010 Views
  • 3 replies
  • 0 Likes

Resolved! SSL forward-proxy certificate import

I've gerenated a CSR to give my enterprise CA. Now, I've recieved the enterprise CA-signed certificate ann imported it onto the firewall.The status reads "valid". The "Key" box is checked, however the "CA" box isn't. Also, when I select the certificate, the option for "Forward Trust Certificate" is grayed out. Did I do something incorectly when ...

Geoblocking Missing

We are on 8.1.21 - When creating a geoblocking rule I do not have the option for 'Regions' in my rule drop down. Is this due to my version OR do i need to upload a geoblocking list [how?] thanks!

IOS users are unable to connected with global protect

Hi, Iam facing the issue with global protect is not connected with IOS users and getting this error after entering username and password. )P1839-T259 12/22/2021 17:19:18:962 Debug( 127): set session proxy to 1-0x104d4b5d0.P1839-T259 12/22/2021 17:19:18:962 Debug( 237): Portal or gateway login, set connect timeout to 30.0P1839-T259 12/22/2021 1...

Joshan_Lakhani_1-1640180248925.png
Joshan_Lakhani_2-1640180278610.png

NAT before IPSEC

Hi folks, We have a vendor requiring a public IP for the encrypted traffic. Their guidance is based on Cisco configurations using "NAT before IPSEC" configurations. Can anyone share/link a guide for this configuration on Palo? Currently on PAN-OS 9.0 should it matter. Thank you.

Update to PAN-OS 10.0.8-h4 causes slow GUI response on PA-820

Hello,After updating our PA-820's to 10.0.8-h4 I have noticed the GUI to be extremely slow to respond. I am actually getting a faster GUI response from a PA-220 on 10.0.7 than our PA-820's. Has anyone else noticed this? Waiting for 'Monitor, Traffic' is incredibly slow and almost unusable. It can take up to 25 seconds for the screen to respo...

  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels