General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Bypassing "Packets dropped: forwarded to different zone" limitation

Dear community! I´d like to consult with you for a possible solution for this scenario:We have 2 internet lines from two interfaces of the PAN firewall connected to two different routers. Each interface is in a different zone.When incoming and returning packets follow different paths then we have an asymmetric routing condition. Situation simila...

Carracido by L4 Transporter
  • 7972 Views
  • 5 replies
  • 0 Likes

Resolved! GP VPN agent issue

Hi Team, We have a setup like GP VPN and cisco duo. When a user is trying to connect to GP it will send a request to the cisco duo and once the cisco duo will approve the connection, the user will access the GP. One of our system is not working properly. It will give the error "Unable to establish the connection and please restart your computer"...

VishnuPS by L3 Networker
  • 2790 Views
  • 1 replies
  • 0 Likes

Resolved! How to release a vpn tunnel?

I have alot of tunnels between nodes, and it seem periodically one will hang, almost like a zombie process.Is there away to break/kill this tunnel down without taking the other tunnels down?

erantanen by Not applicable
  • 10093 Views
  • 2 replies
  • 0 Likes

Licenses on Airgapped Panorama

Hi guys, I was wondering if anyone has any experience using a totally airgapped panorama/firewalls deployment.At the moment I have a case where none of the devices are allowed any outside connections.I thought it would be do-able since both software and content updates can be manually uploaded to panorama and deployed like this, and license keys...

How to configure FQDN

Hello, I need know how to allow create FQDN in PA firewall 3020 and to use URL name instead of adding all IP ranges. Appreciate your help Thanks

mmarie by L1 Bithead
  • 2658 Views
  • 1 replies
  • 0 Likes

IPv4 Processor receive cidr and output single address

Hi folks, Actually I can create a miner that pull an IPv4 list, send it to the processor and to the output. The output is always in that format: 1.1.1.1-1.1.1.1 (for an entry in the list with a single ip) 2.2.2.0-2.2.2.255 (for an entry with a subnet) Is it possible to acheive this instead : 1.1.1.1 2.2.2.1 2.2.2.2 2.2.2.3 2.2.2.4 and so ...

TCP reset packets being dropped

Hello Everyone, I have TCP reset packets being dropped in the Palo when they are sent from tcp-rst-from-server or tcp-rst-from-client. I've taken a pcap to verify the traffic is being dropped. I've put in a ticket with support and their solution was to change the TCP Drop configuration in Zone Protection Profile to not reject Non-SYN TCP. I test...

brieann by L0 Member
  • 6501 Views
  • 3 replies
  • 0 Likes

Spurious hits from the Expanse webcrawler...

Much the same as the issue in this post: https://live.paloaltonetworks.com/t5/general-topics/incoming-traffic-from-palo-alto-ip-address/td-p/196099 only with a different set of IP addresses (34.77.162.0 - 34.96.130.0).Telling me that "we crawl on a regular basis" is decidedly NOT an answer!One, I am not a client of Palo Alto or Expanse, Inc, so ...

Block chrome specific version

We have an requirement of blocking old chrome version over Palo Alto firewall.Kindly check for below PA versions and confirm if we can block Chrome User agent below 93 version.

SurajN by L2 Linker
  • 2638 Views
  • 2 replies
  • 0 Likes

Cortex XDR certifications

Can you please let me know the name of the certificate for cortex XDR and more about the certification like how much cost involved, Validity of the certification and reference guide so on?

Multiple Certs w/ Overlapping Expirations

We have a certificate expiring and we just uploaded the new certificate to take its place. To avoid downtime, we haven't revoked the soon to expire cert and have the other one imported already. They are both in valid state. When the first one expires, will the 2nd (new) cert "take its place" automatically? Or will there need to be some manual in...

tseger by L0 Member
  • 4485 Views
  • 3 replies
  • 0 Likes

Resolved! Secondary external ip adress help me please

Hello there,First of all, my English is not very good, so I apologize. I'm new to Palo Alto. So I'm a bit of a novice. In the structure I use, there are 10.0.15.15 - 16 - 17-18-19-20 external world ip addresses. These are separately assigned as mail server, backup, wifi. Let's consider one of them as connecting the 10.0.15.19 Wifi network to the...

acigdem by L0 Member
  • 4569 Views
  • 3 replies
  • 0 Likes

facing difficuty in terminal server agent

One of our clients facing an issue related to the terminal server agent. when the user is trying to connect VMware, it is connecting directly but when the user gets disconnected due to fluctuation in electricity or some other issue that time when a user needs to launch the session again that time it's not getting connected. But if before the ses...

termina_error.PNG
  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels