General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

PA Firewall 3 Wan

PA Firewall With 3 WAN , Wan 1 (1.1.1.1) , Wan 2 (2.2.2.2) , Wan 3 (3.3.3.3)we wan three wan have port forward to internal web server ip: 192.168.1.10 port 80but only response on 1.1.1.1 wan 1 interface , another wan no response on port forward

Global Protect Connection method : Always-on not working on Mobile Apps

Hi Guy ,I would like to know about the GP connection method: Always-on not working on global protect mobile-apps both android and iOS (iPad, iPhone) is shown about "The network connection is unreachable or gateway is unresponsive" but on Notebook or PC is working normally.So, Please help meThank you in your advance.

Resolved! Problems signing in to the support site

I have a PA-220 at home I have a problems signing in to the support site. I get the following message when I want to log in to the support site: An unexpected error has occurred. Please contact support. And of course I can't create a ticket regarding this problem. Any idea how I can fix this problem

Biga01 by L0 Member
  • 2776 Views
  • 1 replies
  • 0 Likes

Resolved! Can "Decryption Mirroring" forward non-encryption traffic?

I am planning to forward all traffic to traffic collection tool. As I know there are "Decryption Mirroring" (https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/decryption-concepts/decryption-mirroring.html) and it will forward the traffic after decryption.I would like to know if the traffic is non-encrypted traffic such as htt...

JoeKwok by L2 Linker
  • 4413 Views
  • 4 replies
  • 0 Likes

Network segmentation via routers VRFs to Palos VRs and OSPF

Hello everyone and thank you for your answers, I would like to implement segmentation in the data center, we will create VRFs in a Cisco Nexus Core switch and each VRF will have its own OSPF process to peer with a Palo Alto Firewall, all VRF traffic needs to go through the Palos for policy and routing, the question is: -Should we create multiple...

BBravo by L0 Member
  • 15234 Views
  • 5 replies
  • 0 Likes

Very weird PanOS upgrade issue

We have a pair of active passive firewalls on PanOS 9.0.11. We have attempted to upgrade to 9.1.10 4 times out of which 2 times was with tech support. Upgrade seems to cause issue with some linux servers which are critical to us. As an example we have system running Nagios which starts alerting immediately for number of devices. And when we try ...

raji_toor by L4 Transporter
  • 3005 Views
  • 3 replies
  • 0 Likes

Globalprotect client losing dns intermittently

hello everyone We have a intermittently issue with GlobalProtect client and the local DNS resolution. We have conigured local dns servers on network services and we have established "Resolve All FQDNs Using DNS Servers Assigned by the Tunnel (Windows Only)": YEThis configuration is working fine, but intermittently, the local DNS servers are not ...

AORTIZ by L0 Member
  • 2556 Views
  • 1 replies
  • 0 Likes

Inbound traffic to DMZ issue

We have reports of certain users not being able to access our public website but majority of users are able to. The traffic log shows that the application is incomplete. Packet capture reveals the 3-way handshake does not complete and the session times out. The same person who is NOT able to access the public website is able to access another we...

x by L1 Bithead
  • 8356 Views
  • 5 replies
  • 0 Likes

VPN IPSec Configuration Disappeared from GUI

An issue where I can’t view any configured IPSec Tunnels in GUI,From CLI, the IPSec tunnels appear normally. Tried failover, restarting management service, even rebooting both Palo Alto units, using different browsers, different computers, and export; import and load the configuration file with no success. Device Model: PA-5220 HA Mode Active-st...

PA-850 Migration to 10Gb SFP+ Interface

Hi, I have a customer who was a PA-850 firewall. There connection to their LAN is currently using a 1Gb Ethernet port (Port 4). They are in the process of upgrading the network backbone to be 10Gb and wanted to change their connection to the Firewall to 10Gb too. Is there any easy way to migrate all of the settings they have setup from port 4 to...

dvdkevin by L0 Member
  • 4907 Views
  • 2 replies
  • 0 Likes

Resolved! Block Windows 7

I am trying to block Windows 7 clients from accessing the internet. I have followed the steps here: https://live.paloaltonetworks.com/t5/Configuration-Articles/Custom-vulnerability-signature-for-identifying-Windows-XP/tac-p/72273#M1496but I am unclear on what to set for the Pattern. Any suggestions/help to accomplish that goal will be apprecia...

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels