General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Authentication issue with Global Protect

We are having difficulty with our Active/Passive pair of PA_820’s where they are setup to allow auth to GlobalProtect based on AD group membership.If we create a new OU in AD and move a user to the newly created AD OU whilst still having the same group membership, they can no longer auth to connect to global protect from internal nor external ne...

Group Mapping.jpg
Auth Profile.png

Resolved! Welcome Page - Iframe

Hello,we want to include a (external or internal) website via iframe in the welcome page. My test HTML site:<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Frameset//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-frameset.dtd"> <HTML><HEAD><TITLE>Palo Alto Networks - GlobalProtect Welcome Page</TITLE><meta http-e...

Hithead by L4 Transporter
  • 9567 Views
  • 13 replies
  • 0 Likes

Resolved! Not able to ssh access Active after config on mgmt interface on Passive standby

We have a pair of PA-3220 running 9.1.6. We made a config change on the passive and now not able to access the active firewall. Config was added to passive host where we added ssh ciphers / mac / host key to the mgmt interface. After the change we could access passive device (where the config was added) after a putty upgrade. We were not abl...

Resolved! Change speed/duplex on 10G SFP port for PA-5220

Hello, Is it possible to hardcode speed/duplex for 10G SFP port on PA-5220 device? i am getting below error: >set network interface ethernet ethernet1/5 link-speed 10000 link-duplex full Error: Server error : ethernet1/5 -> link-duplex 'full' is not a valid reference ethernet1/5 -> link-duplex is invalid I have gone through the article...

skanani by L2 Linker
  • 14008 Views
  • 4 replies
  • 0 Likes

Policy not matching actual traffic

Hi All, I have a security rule to allow ip "A" to ssh to ip "B". I can see the traffic actually hitting the fw but it gets dropped with interzone-default. The test policy match also verifies that it matches the traffic. IP "B" is actually the firewall. And IP "B" is nated like this: original packet source IP "C", original packet dest ip "A", tr...

olloczky by L1 Bithead
  • 5709 Views
  • 3 replies
  • 0 Likes

Why tcp aged-out?

Hi all,Our developers are connecting from Zone1 to Zone2 with tcp (on ports between 2000 and 3000)The tcp session timeout on firewall is 3 hours.The security policy allows any application, any port from Zone1 to Zone2. But there are all default security profiles applied on that rule.When going to Zone2, the source IP is NATted to the firewall in...

Global protect Notification

Hi, When I connect global protect Gateway. Once is connected I received this notification.I have check the internet connectivity it's working fine. Can you please let me know how to avoid this notification

Joshan_Lakhani_0-1614493398995.jpeg

Need help with logging in case of App-Id

Hi, I have below rule in my Palo Alto and another default rules which are Intra-zone and Inter-zone.Source: 10.0.0.0/8Source Zone: TrustDestination: AnyDestination Zone: UntrustApplication: ssl, web-browsing, dns, Facebook-base, YouTube-base, etcService: Application-defaultAction: AllowLog: At session endI am trying to understand behaviour of Pa...

Resolved! IKE and IPsec Encryption and Authentication Parameters for Site-to-site IPsec VPN

I was configuring a Site-to-site IPsec VPN and I was having a hard time matching my Encryption and Authentication parameters. The remote end device is Huawei Eudemon 1000E and my local device is PA-800. I have finished the configuration both sides by picking the closed parameters(I suppose) which I presume would work to get the tunnel up and run...

PMO-Side.JPG
MOFA-Side.JPG
sisayfe by L0 Member
  • 8799 Views
  • 2 replies
  • 0 Likes

Resolved! FWs not sending logs to Panorama, logs show constant disconnect

Woes with RMA M-100 continue. Sometime yesterday logs stopped showing up on our m-100 and no idea why. It was working after we restored the configuration but stopped yesterday. I can push policies to the FWs and as far as they can tell they are forwarding logs to Panorama but I simply don't see them there. I cannot manage the firewalls from...

drewdown by L4 Transporter
  • 8481 Views
  • 4 replies
  • 0 Likes

GlobalProtect and RDP

Hi All, I have made a change to our GlobalProtect app config to cater for RDP connections by amending the "User Switch Tunnel Rename Timeout" value to 60 seconds. I was hoping to be able to confirm this setting had been applied to the GP clients via the registry as I understand this value can be added manually mentioned hereApp Behavior Options...

IanBroadway_0-1614336060587.png

Resolved! Is it possible to write a rule matching any IP ending in .xx

Hi all,I have a question, is it possible to write a rule that matches only a part of the IP address? For example match any IP ending in .51? Using wildcards this would be *.*.*.51Put another way, i would like to match all IP's that are x.x.x.51 where x is any number. Someone in our teams suggested using 0.0.0.51/32 but this does not work, altho...

Saqib by Not applicable
  • 8331 Views
  • 8 replies
  • 0 Likes

How to add static routes on panorama M-600

Hello , We have M-600 Panorama device and we need to get 2 seperate networks :MGT : for firewalls administration and to receiving logs ( this network is isolated from internet)Ethernet 1/2 : a new interface just to make panorama reach internet for updates. the problem is that i can't specify route to internet through ethernet1/2 next hop. any id...

Elwess by L0 Member
  • 2347 Views
  • 1 replies
  • 0 Likes
  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels