General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4273 Views
  • 0 replies
  • 0 Likes

getting traffic after the interface is down

Hey guys hope you doing well I got a question I get a challenge one of my user getting traffic logs of NetBIOS by source Pvt IP from LAN to WAN the device from the source side is down the 2 Pvt IP still hitting the cleanup rule. The Policy is denied by the firewall but why do the traffic logs show the two source IP which is down from that side. ...

Resolved! global protect remote vpn unable to reach internal network?

im having big problem , after my remote vpn connects i cannot reach my internal network even though my core switch is directly connected to palo alto , i checked i set the access range for the vpn for 0.0.0.0/0 and i set a security rule from vpn zone to inside zone , also i can ping the inside interface on the firewall itself but not the directl...

chuckles by L2 Linker
  • 24992 Views
  • 5 replies
  • 0 Likes

Disable new apps in content update

Hi Experts, We've a pair of firewalls (9.1.6) managed by the Panorama (9.1.6). We've Threat prevention license in place and client would like to install just the threats and not the apps by selecting disable the new apps in content update.As recommended by the TAC, we've downloaded the latest version and when installing the new version, we selec...

TAC support has gone missing, again :-(

Opened a S2 TAC case @7pm ET 07/21/2021. The SLA response time is 2 hours. TAC didn't get back to me until 5:43am ET 07/22/2021. The response from TAC is very vanilla, not helpful at all. Call back to TAC this morning has been waiting for an hour and had to give up. Awful....

dtran by L4 Transporter
  • 3862 Views
  • 4 replies
  • 0 Likes

Resolved! Destination NAT Error

Hello All, Doing an destination Nat but getting below Error. Could anyone please help me. Also pls find below my nat rule Please note : Ethernet 1/1 is my Outside Interface

vishal_07_2-1627031851196.png
vishal_07_3-1627032032760.png
vishal_07_4-1627032054212.png

Exception Handling in Palo Alto Support Page 7/22/2021

Hello Palo Alto Team, I would like to bring this up with you. I noticed that your support page went down today 7/22/2021 and that is fine. What worries me is the way your system handles exception. I think you are exposing to much that end user like myself has no business reading. 1. No connection could be made because the target machine actively...

NAT SDWAN

Hello,My Name is Dwi. I have case with SD-WAN configuration.I have 2 ISP DIA provider, and i want to combine 2 ISP provider in to single logical SD-WAN for Load Balancing Internet Traffic.the Palo Alto device is under NAT, please help me to configure NAT in SD-WAN ? thanks very much.

dwinur by L0 Member
  • 4711 Views
  • 3 replies
  • 0 Likes

Using GlobalProtect , ExpressVPN and Remote desktop

Dear All, I am pondering following scenarios: 1- I connect to Server "S" using GlobalProtect on my Computer "A". Now Assume i do not have access to computer "A" physically because i have moved to another city. I want to access computer "A" from another computer "B" using remote desktop sharing. My question is the connection between "A" and "B" g...

shaukafa by L0 Member
  • 4491 Views
  • 1 replies
  • 0 Likes

Resolved! Always On Global Protect VPN

When I am looking at GP Gateway Users I see some USERs withID prelogin and others where USER matches the COMPUTER namefield. Any idea why I might see one or the other? I am using certificateauthentication.

MichaelMedwid_0-1626972848253.png

Why does URL Filtering Profile with a custom URL Category assigned require the same custom URL category assigned in a security rule to work?

Hi all, Pardon me for the lengthy title. Here is the layout of what I am working with:😅I am currently running PAN-3020 on PAN-OS 9.0.13I do not have a URL filtering licence I do not yet do decryption (long story).Security rules are any/any for testing this. I have been tinkering with custom URL categories and filtering profiles. I have got wh...

inter-vsys vs shared virtual router

Hi all It seems like 1 virtual router can be shared by multiple vsys Reading uphttps://knowledgebase.paloaltonetworks.com/servlet/fileField?entityId=ka10g000000UADEAA4&field=Attachment_1__Body__s1 VSYS can have all multiple VR’s as well as multiple VSYS can share the same VR https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/virtual-s...

iFAST-SG by L0 Member
  • 5154 Views
  • 1 replies
  • 0 Likes

Resolved! techsupport file info

Does anyone know if you can see session tables in the tech support file? Trying to troubleshoot a session sync issue and wondering if I can go back and look at the table when the TS file was created.ThanksJoe

jdemares by L1 Bithead
  • 2723 Views
  • 1 replies
  • 0 Likes

ECMP and PBF not work

we have a PA-820 with dual ISP internet (ethernet 2, ethernet 3) and ECMP. all PC 10.1.0.0/16 can load balancing through 2 Internet connection.If I use PBF so PC 10.1.3.250 only go out through ISP 2( ethernet 3), I see this PC cant connect to Internet any more. It seem ECMP cant work with PBF, is there any way to do this ? this is PBF rule

test pbf.PNG
duyennv by L0 Member
  • 2339 Views
  • 1 replies
  • 0 Likes

Resolved! BGP on PanOS: allow route with own as number in as-path

hi,i am new to panos and have problems in allowing a route with its own as number in as-path incoming from a peer. looks like the route is not accepted as a loop prevention but it is just the fact that the as number is used twice as two companies connect together with private as numbers. what do i have to do in order to accept the route like all...

daniel by L0 Member
  • 4967 Views
  • 1 replies
  • 0 Likes

10.0 user-id agent ignore_user_list not working

Since upgrading to pan os 10.0.6, we've noticed the "ignore_user_list" on our server user-id agents doesn't seem to be working. We did not have any issues prior to upgrading to 10.0.x. Has anyone else noticed this issue? We upgraded our user-id agent to 10.0.3-10 (latest version) at the same time. We have a support ticket open, but have yet ...

jmurphy by L2 Linker
  • 2519 Views
  • 1 replies
  • 0 Likes
  • 24362 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels