General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 418 Views
  • 0 replies
  • 2 Likes

Resolved! About APP-ID icmp and ping.

Hi guys.

I have question about APP-ID that ICMP and PING. I found that some document said "ICMP is all of icmp procol and PING is only ICMP type 0 and 7 is echo request and reply".

When we have white list security policy, For open a PING application, S

...

ttongfly by L3 Networker
  • 7135 Views
  • 4 replies
  • 1 Likes

Adding L3 to vWire PAN

I currently have a PAN 3220 sitting in serial behind a Cisco ASA. The PAN's doing the higher level inspection, geo, correlation warnings, content filtering. I had written earlier on the forum about wanting to implement layer 3 on new interfaces and i

...

palomed by L3 Networker
  • 2338 Views
  • 2 replies
  • 0 Likes

Resolved! Certificate ca status from the CLI

I have successfully loaded my device certificate and a CA certificate from the CLI - took some seraching for format of the certificate strings, but they're in there now. 

One problem. 

In a firewall I have previously set up I show (in set format) the c

...

Palo Alto OSPF routing./wild card mask configuration.

Folks,

For OSPF configuration on the Cisco router, we normally define a wild card mask. 

 

e.g. network 1.1.1.0 0.0.0.255 area 0.

What this configuration tells the Cisco router is to form OSPF neighbor with all IP address that being with 1.1.1.x IP addre

...

nson2139 by L3 Networker
  • 2109 Views
  • 1 replies
  • 0 Likes

Trouble with multiple IPsec VPN Tunnel

Hi all,

I'm a fresh man to paloalto devices and I'm facing a problem.

Site A has a subnet 192.168.100.0/24. Site B has 192.168.40.0/21. Both sites use PA820.

Site A has a IPsec tunnel to Site B. This tunnel is running good.

Now we have a new Site C, 192.

...

mercurr by L1 Bithead
  • 4600 Views
  • 6 replies
  • 0 Likes

want to create two region in same country.

Hi,

 

I am facing an issue regarding the region configuration.

 

I want to create two custom regions.

 

I have tried, in the name, I added India and checked geolocation and added the coordinates of a city. This scenario is working.

 

When we keep the city na

...

LSVPN versus Cisco DMVPN

Looking for some feedback on anyone's experience with both/either.

 

In the Cisco realm say a mesh of 50 some sites each router has a tunnel between each site and a connection can go direct to the other location because routing is shared across the ent

...

view the urls hitting default interzon policy

Hi team,

 

We have a url filtering profile created for monitoring with action of all category as alert. And this profile has been called on default interzone policy (action deny). But nothing is gets logged, we have many traffic hitting default interzo

...

Resolved! LACP PROBLEM

Hi all,

 

I have some problems with LACP. Sometimes, randomly, the interfaces move out of AE-group.

I can see from log this error message: "receive PDU partner does not match local actor ".

Below the file l2ctrld.log .

 

 

 

 

2019-09-17 23:19:54.588 +0200 et...

Chango by L1 Bithead
  • 38070 Views
  • 10 replies
  • 1 Likes

License expiry

We're waiting for our new licenses to come through and getting a little nervous, of particular concern is our PAN-DB license which has the expiry date as 11/2/2020. 

 

It is my understanding that custom categories will work and it's just PAN-DB look up

...

kradmin by L0 Member
  • 1920 Views
  • 1 replies
  • 0 Likes

Resolved! How to access to linux mode in PA ?

Hello community,

 

Can you help me with this?

 

I need to know if its possible to instal Nagios Package into Palo Alto, hence how do I get access to the Linux Based Commands on the platform, I understand that PA is build upon Fedora.

 

Any guidance will be

...

Apadilla by L3 Networker
  • 18859 Views
  • 5 replies
  • 0 Likes
  • 23695 Posts
  • 110 Subscriptions
Top Solution Authors
Labels