General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 777 Views
  • 0 replies
  • 0 Likes

IP spoofing /source routing

Hi Friends,

 

I have nt enabled Zone protection for our palo alto firewalls as its connected to trusted zones. I want to know the whether IP source routing is disabled in the PA NG Firewall (Pan OS > 9.0) by default or not.  Also steps to protect again

...

IpSec VPN Phase1 negotiation problem

Hi All,

 

I have two 4G router and two ipsec vpn tunnel. Routers are exactly same.

VPN configs are exactly same (except Ips) one tunnel up and running but other one failed at Phase1

 

It gives me "IKE phase-1 negotiation is failed. Peer\'s ID payload 192.

...

Lacrymae by L1 Bithead
  • 6283 Views
  • 4 replies
  • 0 Likes

SDWN and PAT

Trying to setup a LTE link as a backup link for an SDWAN deployment.  All of the LTE gateway devices do PAT as they get a single IP from the provider.  Will this work.  Don't think it will work in the hub but in the branches believe it will.  Just wa

...

Palo Alto QOS - WRED drops

In Palo Alto firewall,  we observed WRED drops on QOS (150Mbps)  applied egress interface eth 1/11 – due to which DB sync/mirroring is randomly getting failed/dropped between DC & DR. Please let me know for any configuration changes/workarounds to av

...

preetpk by L2 Linker
  • 3814 Views
  • 1 replies
  • 0 Likes

Resolved! IKE-NEGO-P1-FAIL

We are trying to setup a IPSec VPN from our VM-300 Palo Alto Firewall running in AWS. Using PANOS 9.0.11.

 

I’m having issues with the configuration of the IKE Gateway as the Interface IP address is set via AWS DHCP and does not reflect the public (ela

...

gateway.png
System logs.png

Resolved! GlobalProtect issue on Android device

Error message: gateway external server cert is invalid

 
Only for Android users who are using GP version 5.1 or 5.2.
 
No issues with 5.0. Using PANOS 9.1.3
 
Using Public Certificate and we only received 1 PEM file from the client.
The server cert (SSL1_Ne
...

Certificate.jpg
FarzanaMustafa_0-1612932636837.png

Slow speed via Global Protect.

I have VM300 with GP without split tunnel. Between with and without GP their is a lose of around 6mb.

Is it acceptable to have 6mb of overhead lose? Will enabling/disabling ipsec in ssl vpn setting make any difference.

Global Protect: Full Tunnel Enforcement

I have already contact Palo Alot Networks support about this issue and their comment back to me was "you need to protect the route preference/configuration from the host side."

 

The issue that I am facing is that we have third parties that are not man

...

Resolved! VM-100 will not configure management interface.

We have a VM-100 to run int our test environment ( VMware 5.5)

Pan-OS8.0.0

 

Despite reading the same information over and over I can't get the management interface to come up.

 

I have applied the config

 

#set deviceconfig system ip-address 128.129.10.40

...

Fresh from scratch firewall config

So i can't find much on what rule of thumb to follow. If you know what applications you want to be allowed, should you start with the level4 version of the rule using just a port and then migrate to app based rule? Once app id identifies it properly

...

Anydesk config

Hello,

I have tried to allow some specific users to use anydesk, but it did not work.

in security policy, under application allowed anydesk, service allowed any

in nat, service allowed - tcp 80, 443, 6568, 7070 (destination tcp)

but it did not worked. 

pl

...

dwalll by L0 Member
  • 2491 Views
  • 1 replies
  • 0 Likes
  • 23985 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Authors
Labels