General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Question about moving traffic to new rule

Hello Palo Alto Community, I have a question regarding moving https traffic off a rule to another existing rule. The traffic being moved is critical to operations and cannot be disrupted. For this reason I've been asked to confirm the behaviour of this change. I don't see any issues with proceeding however would like to confirm the impact. My th...

PA_User by L0 Member
  • 2774 Views
  • 2 replies
  • 0 Likes

Impact on Processing rulebase order

Hi,Is there and if so what is the difference on processing speed of a PA rulebase when most hit rules are on top vs when most hit rules are spread throughout the rule base?For example: Imagine a rulebase of 15000 rules. What would be the processing speed difference if a certain rule is hit 10000 times a day if it's on top (say 1th rule in the ru...

General question about firewalls

Hi Guys,I am extreme beginner on firewalls and network. I have a question, which will sound very naive. My brother company has around 500 employees in the same branch where he works. They have two firewalls in HA and then switches and then their servers. They run many web applications in their servers and a large amount of data is uploaded to th...

Satyam by L1 Bithead
  • 3256 Views
  • 3 replies
  • 0 Likes

Resolved! Cert renew

I imported the new Cert to Palo . how do I Update the Global protect and SSL/TLS Service profile? Old cert expiring tomorrow.

How to identify high dataplane CPU

Hi Community, Could you please to identify a problem with palo alto device. The device is with processing is too high. What could be causing this consumption? This is normal or is a problem? Data Plane CPU stay always with =100% Follow a message:Management CPU: 81%Data Plane CPU: 100% (It´s problem, stay always = 100%) Thanks a lot for help Ca...

PA VM IPSEC Tunnels in Azure

Ok, I've been stumped for a few days now. I dropped a support call in for help, but they are taking their time...and I am behind schedule. LOL. I have a PA-VM-100. Its sitting in an azure cloud. There is an NSG on the Trust, Web (DMZ), and Mgmt interfaces, and a separate NSG on the Untrust. The IPSEC tunnel is green on both phases 1 and 2. I hav...

ndresang by L0 Member
  • 2480 Views
  • 1 replies
  • 0 Likes

Limiting users access in palo alto firewall

Hi Team, I have a query where i need to know whether there is any features or configurations needs to be done on simultaneous login by users.Currently its unlimited for users by palo alto firewall. we need to restrict users unlimited access by any means possible.Let me know what are the possibilities. Either by hip profiles or user credential ba...

Not able to upgrade MacOS

Not able to upgrade macOS. We are trying to upgrade macOS from Catalina to Bigsur. Whenever we try to upgrade it from the app store or download the dmg and install, the installer fails.But when it is connected to a different network, it goes through without any problem. I wonder if there is something in firewall that needs to be allowed. Please ...

Akhil_B by L2 Linker
  • 2926 Views
  • 2 replies
  • 0 Likes

Network Interface configuration into V-Sys Environment

Hi,can anybody help me for below queries:How to make a shared (sub-interface) into multi V-sys environmentHow to create VLAN interface (L2/L3) on specific V-sys.Is there any concept of virtual-switch concept in V-sys environment?How to make a inter V-sys communication.

vijKumar by L0 Member
  • 1999 Views
  • 1 replies
  • 0 Likes

Easy way to deal with Google SMTP (1e100.net)?

Anybody found an easy way to deal with allowing SMTP traffic to Google but nowhere else. The problem here is 1e100.net IP space is all over the place (since it's Google's world wide distrubted cloud) and FQDN address object type, when it even works [bugs all over the place with that code], doesn't allow wildcares.Really need a day to say someth...

PeterT by L2 Linker
  • 18735 Views
  • 10 replies
  • 0 Likes

One of interface is down in vm

Hi, Palo Alto firewall is VM in ESXi. In the ESXi, I can see the firewall interface e1/1 , e1/2 and e1/3 are up. but I do not know why we can see the firewall e1/3 is down. Anyone can advise this? Please see the below. Thank you

PAFrank_0-1633882439084.png
PAFrank by L2 Linker
  • 5120 Views
  • 3 replies
  • 0 Likes

NOT ABLE TO ACCESS PUBLICY NATED IPS VIA GP IN FULL TUNNEL

Hi Guys, We are not able to access nated ips from GP full tunnel scenario. We have 50+ hosted servers publicly and we have GP in full tunnel mode. All the nated servers are accessible without any issue but when we connected to GP in full tunnel we are not able access it. need you suggestion on this to achieve it

saifulla by L0 Member
  • 2019 Views
  • 1 replies
  • 0 Likes

multiple MAC address on switch port connected to the PAN firewall

Dear Community, We have a few Palo Alto firewalls in several locations where we are seeing a weird behavior.The firewalls are connected directly to switches and in some ports of the switch we see two learned MAC addresses: one 001b17-XXXXXX belonging to the FW´s interface but also another one 34e5ec-XXXXXX for which we cannot find explanation. B...

Carracido by L4 Transporter
  • 2977 Views
  • 1 replies
  • 0 Likes
  • 24393 Posts
  • 123 Subscriptions
Top Solution Authors
Labels