General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 776 Views
  • 0 replies
  • 0 Likes

U-turn Nat between isolated networks

Hey Guys and Gals

 

I am having an issue getting u-turn nat to work between two isolated networks on the same Palo.  I am basically tiring to allow Interanal clients to access a webcam server in a IoT network.  I think might issue might be that I need

...

u-turn Nat.jpg
trees by L1 Bithead
  • 5080 Views
  • 3 replies
  • 1 Likes

Palo Alto multiple configuration for log forwarding

Hello,

I am in the process of setting up a server for syslog relay to Azure Sentinel. Currently my Palo Alto systems forward their CEF logs to LogRythm. I am looking for a way to set up my Palo Alto to forward the same logs to the new syslog relay se

...

Ematek by L0 Member
  • 1812 Views
  • 1 replies
  • 0 Likes

Spotify and URL Filtering

Hello

 

Spotify, besides being detected as a application, connects to certain URLs for information.

 

What URLs are these? Id like to making a URL Filtering category so I can allow this traffic to pass.

 

Thank you.

riahc3 by L1 Bithead
  • 2777 Views
  • 2 replies
  • 0 Likes

Anyone else have a ton of these?

URL filtering I keep seeing lots of clients for this URL:

 

play.google.com/log?format=json&authuser=0

 

Anyone know what application can be causing this request from the client PC?

 

Block domains using EDL

Hi,

 

We are doing test in order to block the domains using EDL but its not working. We are doing test with this domain: unrealengine.com

This is the config:

 

The domain is added to the EDL domain list:

 

The antispyware profile is created with the list:

 

T

...

Minemeld1.JPG
Minemeld2.JPG
Minemeld3.JPG
Minemeld4.JPG
BigPalo by L4 Transporter
  • 3933 Views
  • 2 replies
  • 0 Likes

use of binaries in Global Protect

Hello

 

I want to know if the binaries  wa_3rd_party_host_32.exe and wa_3rd_party_host_64.exe are essential for use in Globlal Protect, and what service of Global Protect are use these.

I see this articule:

https://knowledgebase.paloaltonetworks.com/KCSA

...

BigPalo by L4 Transporter
  • 4807 Views
  • 1 replies
  • 0 Likes

Recommended ways to manage numerous firewall policies

For people who have many firewalls which have similar policy, what are good ways to manage these, say for example I want to add a particular rule from one zone to another, and the zones are identical across 80 firewalls.

 

Am looking at using Device Gr

...

Server management cannot be restarted

I cannot login to the web GUI, I receve error "Timed out while getting config lock. Please try again. ". I saw that it has to do with overloaded server managment plane so i tryed to restart it form CLI, ussing the comnad  "debug software restart proc

...

Resolved! Fortigate VIP Equivalent

Hello,

 

I am working on a Fortigate to PA migration and I am trying to wrap my head around the equivalent of a Fortigate VIP (we used VIPs to go from public IPs to inside web servers) on a PA. Would I just create addresses for everything and then do t

...

Allow only Zoom for a subset of machines

I want to lock down Internet access for some machines to just allow them to use Zoom, but using the App-ID means I have to allow SSL and STUN too and I don't want that as that opens up a ton of other sites, Anyone have any suggestions? Maybe a URL fi

...

froche by L1 Bithead
  • 4026 Views
  • 2 replies
  • 0 Likes

VPN Bandwidth Load Balancing

Hi Team,

 

I have three VPN connection for three isp network. We need to load balance the VPN connection when it reaches to a particular threshold for example 75% or 80% then the traffic need to shift to other tunnels.

 

For example if one tunnels is bei

...

Resolved! How to reduce downtime when migrate to an AE interface

Hi All,

 

Am going to bundle an existing layer3 interface (e1/1)with extra one (e1/2 ) to an ae1 interface. And then move the ip address from e1/1 to ae1. 

This is in a HA A/P configure, question is how to reduce the downtime to roughly 0?

If it will imp

...

AllanGao by L1 Bithead
  • 3006 Views
  • 3 replies
  • 0 Likes

Resolved! U-Turn NAT question

When setup U-turn NAT, can see SNAT part using an internal interface for DIPP. But in the scenario A/P FW has two downstream switches, ie. two internal interfaces, if need to setup 2 U-turn NAT policies . So that when the primary link down, can use t

...

AllanGao by L1 Bithead
  • 3795 Views
  • 4 replies
  • 0 Likes
  • 23985 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Authors
Labels