General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4469 Views
  • 0 replies
  • 0 Likes

Resolved! PBF for incoming connections

NAT translation goes like this:Destination NAT and Security Policy:https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat/nat-configuration-examples/destination-nat-exampleone-to-one-mapping.htmlPolicy Based Forwarding:Polices > Policy Based Forwarding >Under General Tab > Name "Incoming"Under Source Tab > Zone "Out...

jmora by L1 Bithead
  • 3015 Views
  • 1 replies
  • 0 Likes

Site to site vpn

Hello, can anyone please help me for the below request? site to site vpn setup for oracle cloud using palo alto CPE. Can someone please tell me recommend setting for Phase 1 (ISAKMP) and Phase 2 (IPsec)?? thank you!

Poo173 by L0 Member
  • 2245 Views
  • 1 replies
  • 0 Likes

Mitel telework phone one way audio

Anyone ever seen a one way audio when mitel phone configured for telework mode is on the inside trusted network? The mitel border gateway is in the dmz nat'd to an outside public ip, and works fine with all phones but telework enabled phones when on the inside lan. Thanks, Jeff

Customer ID or Sales Id

Good day, I have a trouble creating an account for customer support, I don't know where can i find the customer id or sales id. Hope you help me with this problem. Thank you

jreyes by L0 Member
  • 4680 Views
  • 1 replies
  • 0 Likes

Seeing Decryption Policy Usage on Prisma.

Does anyone know if there is a way to see what traffic, or if traffic, is hitting decryption policies for Prisma traffic? I have some policies I would like to clean up if I can, but unlike security policies, I can't seem to filter traffic that may be utilizing decryption policies. Thanks.

PAN syslog stream into AWS S3 bucket

I am looking for creative ways to get my VM-300 instances to syslog directly into an S3 bucket for pickup by our logging systems. Given the PAN only has the ability to send syslog TCP to an endpoint I am not sure this is possible without some middleware.Has anyone else figured something out to achieve this?

danecott by L1 Bithead
  • 12393 Views
  • 5 replies
  • 0 Likes

Authentication server option

I have a new Palo Alto 820 and my Radius server is a Juniper running 9.1 . At this time my Cisco and other device use a share key to Authenticate to the Juniper device. On the Palo 820 Pan os 9.1.4 it want me to use the following Auth methods "PEAP-MSCHAPv2, PEAP with GTC, EAP-TTLS with PAP, CHAP, PAP" which I do not use. I want to know how I...

Thinking about moving from SonicWall NGFW to Palo Alto

My company has been using SonicWall for the last 7 years or so, and we're currently on a NSA 3600 (NGFW) HA pair for main branch and a TZ500 for a small remote office. The TZ500 is totally fine and the 3600 works ok for the most part but there are always a lot of bugs and issues seemingly for every service and feature (espeically HA). Changes an...

Resolved! SSL decryption issue for Windows Store

Hello, After enabling SSL Decryption, we cannot download from Windows store. Getting error below.Tried excluding hostname with Microsoft but no luck. How to fix this issue? Thanks in advance.

Error-windows-store.jpg
exclude-store-list-decrypt.JPG
Farzana by L4 Transporter
  • 20965 Views
  • 14 replies
  • 0 Likes

Resolved! Using the Panaroma as a central manager for Cisco AnyConnect.

Team,Any one aware if we can even use the Panaroma a a central manager for the Cisco AnyConnect firewall?My use cases are: 1. Central management and to push policies to the Cisco AnyConnect. 2. Ensure policies are in sync and same across all AnyConnect nodes.3. Possible backup of the Cisco AnyConnect configuration.4. Possible historic logs stori...

nson2139 by L3 Networker
  • 2885 Views
  • 1 replies
  • 0 Likes

FW has stopped recognizing several users and does not map them with the corresponding domain group, so it does not apply the necessary policies.

Hello,We have changed a 2 palo alto 5220 in cluster for another 2 palo alto 5250 version 8.1.16.We have migrated the configuration by exporting and adapting the xml.Everything works ok except for a detail in the new passive fw. we have detected it when switching and testing.The fw has stopped recognizing several users and does not map them with ...

BigPalo by L4 Transporter
  • 4406 Views
  • 3 replies
  • 0 Likes

PXE boot not working through FW

Hi all,I have a FW with PanOS 9.1.7 that is causing PXE boot issues with TFTP protocol.When traffic is not routed through the firewall it all works and I have seen several threads about this problem but no solution. DHCP server: Windows Server 2012 R2 172.18.76.23WDS server: 172.18.76.20 DHCP option 66: 172.18.76.20DHCP option 67: \boot\x64\wdsn...

Resolved! Azure HA not coming up

Do I need license to test Azure HA scenario. I am following all the steps but HA1 doesn't come up.I don't have any licenses. And doing a test run of implementation as HA active/passive.Default 10.0 gets installed with BYOL, but we don't have license yet.

raji_toor by L4 Transporter
  • 3075 Views
  • 2 replies
  • 0 Likes
  • 24379 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels