General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 242 Views
  • 0 replies
  • 0 Likes

Management interface routing

I'm working on isolating the management interface onto its own network. The firewall will be the router for this traffic and the network switch it connects to will be L2 only. If my management IP is 10.10.20.10/24 and the gateway is 10.10.20.1 where

...

Phase 2 tunnel status

 

Please excuse me as I am still learning and am relatively inexperienced. I assume the phase 2 status can be red for following reasons (assuming IKE phase 1 is all correct and working) Authentication, Encryption, DH settings being incorrect/mismatche

...

ipsec tunnel status.jpg

FW in Palo IP changed

Hello -

I have an HA pair of palo's that were added to Panorama. The management IP for each of those palo's has changed and are now showing in a disconnected state. How can I correct this?

 
Thanks in advance.

require admin users being member of LDAP groups

Hello

We are using LDAP for authentication of the admin users (for Panorama as well as the firewall nodes).

Is it possible to adjust this, enforcing the user being a member of a specific AD group?

Last info found was regarding PAN-OS 8.1 (https://live.p

...

Setup VPN Global Protect DynDNS

Setup VPN Global Protect DynDNS

 

Dear community:

Good afternoon, is it feasible to be able to configure VPN access with Global Protect, on a Palo Alto with the following scenario:

Palo Alto with:
-Public IP Dynamically ( DHCP )
-Firewall configured with t

...

Metgatz by L4 Transporter
  • 3557 Views
  • 4 replies
  • 0 Likes

Resolved! Captive Portal w/2FA in Azure

Hi All -

Hopefully I make this clear.  

 

What I'm looking to do is set up Captive Portal with a push notification in Azure AD.  I can't seem to find any documentation around this, can someone give me the general steps or point me to existing documentat

...

Specific Action change on Individual Signature

Hi Experts,

We've configured a Vulnerability profile with the Action of Default. For the Windows Print night mare vulnerability (Version ID: 8424, signature ID:91333) and the CVE ID: CVE-2021-1675 I see the default action is marked as 'Alert' which wi

...

URL filtering

I have one query it is necessary to add a URL Category to add in URL Filtering Profile or I can add a separate URL category in the Security policy without adding any URL filtering Profile.

for example, I Create a URL Category name test which having so

...

Web Activity Monitoring for BYOD School

Hello All...

 

We are looking for a solution for a medium sized private school (k -12) to track users web activity. We'd want to be able to go back a week or so..nothing crazy. But would love to be able to get a report on a site\url and see what user

...

Bind 2 separate IPSEC tunnels to separate ISPs

I am trying to setup a separate IPSEC tunnel to a new ISP while keeping the rest on the old ISP.  I am doing this as a test.  My issue is lack of connection.  The message I get from the logs is that it try's the connection then I get another saying i

...

VPN Ipsec SitetoSite DynDNS

Good afternoon everyone, a question, is it possible to set up a Site-to-Site VPN between two sites with Dynamica IP, but that have each their FQDN with DynDns services.

Example:

Site 1: FQDN: mysite1.dynalias.net ( DynDNS )
Site 2: FQDN: mysite2.dynalia

...

Metgatz by L4 Transporter
  • 3319 Views
  • 3 replies
  • 0 Likes

Resolved! VPN TWO Interconnected Sites Public IP DHCP ( DynDNS )

Good afternoon, I have some doubts regarding a configuration:

 

Scenario: I have two sites that I have to configure with Site-to-Site VPN. Both sites have dynamic public IPs. In both of them DynDNS services are configured and operating.

 

The sites with

...

None_Ip_Dhcp.JPG
Metgatz by L4 Transporter
  • 3381 Views
  • 3 replies
  • 0 Likes
  • 23625 Posts
  • 107 Subscriptions
Labels