General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4222 Views
  • 0 replies
  • 0 Likes

CPS calculation per server

'Log at Session End, captures the number of connections at the session end." I am little confused by this statement. How does 'Log at Session End' help in calculating CPS for a server.https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/zone-protection-and-dos-protection/zone-defense/take-baseline-cps-measurements-for-setting-flood-thresho...

raji_toor by L4 Transporter
  • 6442 Views
  • 6 replies
  • 0 Likes

High Availability question

Hi all, This is my first post on this forum. I am also a brand new Palo Alto customer and we just purchased a pair of 3220 firewalls. As the subject says my question revolves around HA as I would like to start putting together a plan for design and deployment. My question is probably really stupid but I just want a bit of clarification on how an...

Mushussu by L0 Member
  • 5369 Views
  • 2 replies
  • 0 Likes

Anyone have issues with 10.0.6

Just kind of a broad general question, but has anyone had any issues going from 9.1.x to 10.0.x in a large environment? Or would the preferred 9.1.x version be the way to go?

Show Shadow Rules 2021 Post

Hello -I saw a post about this from 2012 and the answer was basically no. Well, it's been nine years now and I'm hoping there is a way to view shadow rules without doing a commit.

Resolved! HSCI Port

Hi, I finally received my pair of 3250s and noticed there is the HSCI port used for HA. I didn't realize this before purchasing, so I do not have the cable. Is there a reason why I can't just dedicate an interface for HA to use for HA2? In case it matters, these firewalls will be located on internet edge.

ce1028 by L4 Transporter
  • 16400 Views
  • 6 replies
  • 0 Likes

Resolved! Web-GUI certificate not applying

Hello all, After letting my cert expire (duh), I've imported a new one, exactly the same process as before.For some reason the firewall isn't picking it up for Web-GUI, sticking with a self signed cert with the serial number as CN, but uses the intended cert for GP portal with no problem.Running 10.1.0, couldn't find any mention in the documenta...

Block malicious domains at interface level

Hi Team, I have a concern where is there any way to block malicious domain based or malicious ip based traffic ingress through the firewall to trust zone or dmz zone from untrust zone to be blocked at interface level even before it reaches to pbf or policy or processing over firewall.Is there any way to block malicious domain before it is being ...

Resolved! Captive portal URL not working when accessed from inside zone

I have configured Captive Portal with MFA and it works fine when the user traffic is originated from Untrust side of the firewall. When the URL "https://<firewall name>:6082/php/uid.php?vsys=1&rule=0" access from one of the internal zones (e.g.) Trust, it does not work. I have user-identification enabled on all zones. User from outsid...

GlobalProtect breaks internet access

hello guys,Did some of your GP uses complain that they lost the internet after GP connected?It just happens recently and for some users only.GP version is 5.2.7 Thanks

DongQu by L2 Linker
  • 2295 Views
  • 1 replies
  • 0 Likes

Regarding blocking unknown or malicious domains or malicious user

Hi Team, I have a query where i need to block some unknown attacker or someone malicious from external trying to access my internal network or DMZ.I need to ways to block or deny those specific traffic. We have enabled country based block, we have IP based block yet is there anyother way to block or deny malicious domains except using EDL, Which...

Regarding EDL domain list which is not working.

Hi Team, I have a query where i need to block domain based malicious domains to be blocked with regards to EDL which we have internally. I have called the EDL over the Application/URL category of the policy which has the EDL name which consist of certain number of malicious domains which need to be denied.For this i had not seen any hit counts t...

GlobalProtect - how to edit the download page

Is it possible to edit the GlobalProtect download page?On the page where users are prompted to download the 32bit, 64bit, or Mac version version of GP, I would like to add some instructions for the not so savvy user on which version to select and how to install the client. If there's a better way of doing this I'm open to it. Setting it up via...

etnerual by L1 Bithead
  • 24590 Views
  • 14 replies
  • 1 Likes

Remedies for block attacks.

Dear Team, One of our faced some attacks from their wan interface IP. The issue is reported by their ISP team, when we checked in the firewall there are no logs. In customer network, huge number of traffic is going at the same time. The device is 3020. Already customer is facing some slowness in the network traffic. Kindly share the Remedies for...

VishnuPS by L3 Networker
  • 2686 Views
  • 2 replies
  • 0 Likes
  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels