General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Vwire interfaces are flap

We have a Paloalto connected in vwire mode Cisco ASR1 is  connected on PA eth1/21 (Primary) and Cisco ASA (Primary)is connected on PA eth1/22. Same as Cisco ASR2(secondary) is connected on ethernet1/23 and Cisco ASA(secondary) is connected via Ethern

...

Joshan_Lakhani_0-1595447238139.png

Overlapping Proxy ID"s

I have a IPSEC site to site VPN with a Check Point firewall.  In the Palo Alto I have networks / proxy ID's that overlap each other?  Can this cause issues?

 

For example I have:

 

Local                                                   Remote

192.168.50.

...

DMZ server is not accessable by Global protect

Hello,

 

I have one server belongs from the DMZ zone.
Example:-
server ip- 2.2.2.2
source ip for VPN user - 1.1.1.1
VPN zone
DMZ zone

There is 2 scenerio:-
policy(1) - I have created a policy like:-
sourcezone- VPNzone
source ip - 1.1.1.1
destination zone - DMZ

...

Global Protect in Linux error

Hi,

 

We are trying to connect to our VPN using Global Protect client in a Fedora laptop. We have tested the following articles: https://docs.paloaltonetworks.com/globalprotect/4-1/globalprotect-app-user-guide/globalprotect-app-for-linux.html#


but we ar

...

BigPalo by L4 Transporter
  • 8605 Views
  • 6 replies
  • 0 Likes

Best way to load balance to ISP with Global Protect

We have an active/passive 3020 and in from of them we have an A10 Load balancers. We want to change our current configuration so we can have a load balance between our two ISPs.

 

What is the best practice regarding the Palo Alto? Which would it be the

...

JUrenaG by L1 Bithead
  • 6249 Views
  • 7 replies
  • 0 Likes

Radius configuration with multiple servers

Hi, 

      We have an issue that sometimes our Duo proxy stops responding to Radius requests from our Globalprotect solution. Our IT operation team blames Microsoft for the issue and they blame Duo. I found a blog describing a possible solution here h

...

Is windows VPN client and split tunnel supported?

Dear community,

 

I configured Windows 10 vpn client to connect to the globalprotect gateway and it works fine, the only thing that it´s not working is split tunneling.

 

Cannot see the Access Route For Third Party Client on the gateway like this example

...

Carracido by L3 Networker
  • 2652 Views
  • 3 replies
  • 0 Likes

LDAP Filter for Included Groups

All,

 

We have a requirement from our directory team to use ObjectCategory LDAP filter instead of ObjectClass attributes.

 

However it doesn't look like an option for Active Directory included groups. Only seems to be an option for custom groups, but thi

...

CDL - Disconnect from log server

Has anyone else experienced many more "Disconnected from Log collector Server" alerts since the CDL Migration to GCP? I used to get one every now and then but since the change, it's increased dramatically.  Every time I check, the firewalls are loggi

...

MikeC by L3 Networker
  • 2538 Views
  • 2 replies
  • 0 Likes

internet ipv6 to on-premise ipv4 nat

Hi all,

 

there is a domain abc.com and there is an ipv6 dns record for that.so when using ipv6 from cloud is it possible to destination nat this to the ipv4 server inside.

 

I know as a workaround we can add an ipv6 ip to that server but it is not possi

...

PanIst by L3 Networker
  • 2771 Views
  • 3 replies
  • 0 Likes

Devices Stopped Sending Logs to Panorama

We have five (5) devices managed through Panorama. Two of them are still generating logs, while three of them have stopped sending logs. Please assist.

 

it the logs Stops to receive from the device and The traffic and threat logs can be viewed when lo

...

  • 24197 Posts
  • 100 Subscriptions
Top Liked Authors
Labels