General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Questions about Migrating HA Firewalls to Panorama

I'm working through the documentation to migrate a active/passive HA pair of 3220's to Panorama management and had a few questions (https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management.html). 1) Before I push the configs to...

myamane by L0 Member
  • 3629 Views
  • 2 replies
  • 0 Likes

Problem with URL Filtering Order

Hello All, I need a help in my case, i have a bunch of urls which must be permitted and any thing else must be denied. so i create a white list url using the (Custom Objects - URL Filtering) and then i create a URL Security Profile and blocked every categories and just alert my URL Filtering white list and then add it to my (Inside to Outside) p...

PA850 HA Switchover Delay

I have setup two PA850 in a active passive pair. I am simulating failover manually, when I disconnect the cable, I see around 8 packet drops. Is there any specific settings to reduce the delay. 4 packet drops are acceptable. I have bundled interfaces on the firewall.

aataro by L1 Bithead
  • 2706 Views
  • 2 replies
  • 0 Likes

Resolved! Data redistribution: mappings learned via agentless user-id are okay, mappings via globalprotect(type GP) not redistributed

Hello. so I'm setting up data redistribution (mainly for user-id) between 2 clusters. 1 cluster has a globalprotect license and a working internal gateway (this solution will in time completely replace the agentless user-id) I configured data redistribution. GP-firewall is configured with a collector name( multi vsys setup) and even sees 1 clien...

Blue screen on Windows 10 after GlobalProtect 5.2.4

Hi team, I've been facing the following issue. I did an upgrade in the GlobalProtect version (from 5.1.8 to 5.2.4). And it worked normally but, I saw in 3 specific laptops that, when the user installs the app on his laptop, the laptops start to see bluescreens and restarts. And then the user's support team removes the app and goes back to normal...

Cannot ping ethernet1/1 in PA_VM

Hi PA_VM installed in ESXi. PortGroup1 is connected to PA management interface. and Portgroup2 is connected to ethernet1/1. PC1 in Portgroup1 can ping the PA and visit it via GUI using management interface 10.0.10.16. Security zone is setup for ethernet1/1 with ip address 10.0.20.16. PC2 with ip address 10.0.20.10 is connected to Portgroup2, but...

PAFrank by L2 Linker
  • 2805 Views
  • 2 replies
  • 0 Likes

Dual ISP Active/Active Best Practice?

Hi all, We are in a situation now where we are trying to effectively configure our new dual ISP circuits in our primary location. Our initial thought was we would leverage these circuits using PBF and manually govern traffic flow. Ex: All video traffic to streaming-service, go out ISP-A. All web traffic, use ISP-B, etc. We were looking at PBF to...

VM300 Live Migration - MS HyperV S2D - MAC Address/ MAC Spoofing

We have a 4 node Hyper V S2D cluster with a single VM300 appliance. We have been able to successfully live migrate the VM from node to node without any issues.We are in the process of modifying the North / South network fabric. I have successfully update the network on 3 of the 4 nodes. When I went to do the final node (the node that the VM30...

Resolved! NAT over IPSec tunnel.

hello all I have an IPSEC tunnel with ASA(99.1.1.23<> 123.2.4.105), the tunnel is UP but the source client is not able to access the destination server.The proxy ID on PA side islocal: 1.1.1.1remote: 2.2.2.2 both sides are using nat for the client/server behind the FWsthe source client IP is 10.10.10.10(NAT to 1.1.1.1) and the destination ...

DongQu by L2 Linker
  • 16675 Views
  • 8 replies
  • 1 Likes

Resolved! Global protect External gateway in remote user time format issue

In global protect I want to see the Total number of user are Login in and Log out at which time. In Global-protect Gateway when i click on remote user i see current and previous user connected to through VPN. When i fetch PDF/ CSV file. In file the time it will see correct but when i downlaod this file the format is change like 15182019 for lo...

Resolved! How to give supply to PA220 R

We want to power on PA220 R , but it requires DC power supply.Is there any options available in market to provide DC supply to this model ?Can we use SMPS for DC supply ?Can we get AD to DC power adapter from Palo Alto Networks ?

Deepak_K by L3 Networker
  • 4053 Views
  • 3 replies
  • 0 Likes
  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels