General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! PA sending TCP RST for a NAT rule

Hi everybody,


Adding a bidirectionnal NAT rule for an ssl web server and the according security rule, connections from outside are dropped as "Incomplete". Traffic capture show that first SYN packet received is directly rejected by PA with a RST respo

...

Want to Uninstall .bat file Terminal Server Agent.

Hi,

 

While installing the VM the terminal server agent was installed through the .bat file.

Now our requirement has changed, I don't know how to uninstall the terminal server through the .bat file.

While Install the Terminal server agent this error is c

...

NAC VLAN Redirection failing

We are trying to implement a NAC solution. The basics are that the NAC is connected to the switch stack and upon sensing a device connecting, it checks it for authentication against the NAC and if it fail it quarantines it into a specific VLAN. That

...

Nonaxium by L1 Bithead
  • 4089 Views
  • 6 replies
  • 0 Likes

Certificate chain not correctly formed

Hello,

 

I am getting the warning below after importing a certificate. Is there a link/KB I can check to fix this?

 

Warning: certificate chain not correctly formed in certificate dc1pa.abcd.com.au

 

Thanks in advance!

Farzana by L4 Transporter
  • 8687 Views
  • 5 replies
  • 1 Likes

IKE Certificate Authentication Peer ID

Hi,

 

Im trying to setup a VPN connection using certificate based authentication. When Phase 1 tries to establish I'm getting the following error

 

Peer's ID payload ' IPv4_address:xxx.xxx.xxx.xxx' does not match certificate ID, Error: failed to get subj...

Are EDLs updating from passive device?

Dear community,

 

We´ve configured a couple of external dynamic list (IP and URL) on a local minemeld server and the passive device fails to fetch those lists.

 

Error obtained is: "Unable to fetch external dynamic list. Couldn't connect to server. Usin

...

Carracido by L3 Networker
  • 2385 Views
  • 2 replies
  • 0 Likes

HA1 and HA2 Links

Hi Guys,

I have configured each of my HA links to have backup links. I would like to know, are the backup links also sending and receiving traffic like port-channel in which both ports are active? Especially the HA2 if we want to have 20G or more link

...

Nikko by L1 Bithead
  • 2269 Views
  • 3 replies
  • 0 Likes

Resolved! GlobalProtect Split-Tunnel via cli.

I am trying to add the MS IP's via cli for split-tunnelling.

 

the documentation states the following...

set network tunnel global-protect-site-to-site <name> client split-tunneling access-route [ <access-route1>

 

but this is not working on 8.1.9

 

I can g

...

Mick_Ball by L7 Applicator
  • 5261 Views
  • 3 replies
  • 0 Likes

Resolved! updates.paloaltonetworks.com connectivity

hi all,

we have been trying to test our networks connectivity

to updates.paloaltonetworks.com and have been unsuccessful.

we tried ping to updates but it fails and also traceroute it also fails.

and when we tried from different networks all the coonectiv

...

Resolved! EDL dynamic list is URL access error

i  have created the new EDL  with this  URL  (http://panwdbl.appspot.com/lists/mdl.txtbut unable to fetch We have changed the service route with outside interface but the same issue was happening.

 

 

 

Joshan_Lakhani_0-1583264831448.png

Resolved! Palo alto networks licence

Hello,

 

I'd like to know if this fonctionnality need a licence GlobalProtect in PAN or not:

 

* VPN client for MAC OS , Windows XP and Vista 

* The third party: Apple iOS, Android 4.0 

 

I will be appreciated for all your helps 

 

 

Thank you 

RCHAIBI by L2 Linker
  • 3539 Views
  • 4 replies
  • 0 Likes

GlobalProtect: The server certificate is invalid

I am trying to configure GlobalProtect (hereafter: "GP") TLS VPN on a PA-3050 running PAN-OS 8.0.6-h3. I am working with a GP client version 4.0.5.

 

I have successfully configured GP so that I am able to connect when using a self-signed certificate

...

  • 23579 Posts
  • 103 Subscriptions
Top Liked Authors
Labels