General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4223 Views
  • 0 replies
  • 0 Likes

Panorama via S2S VPN

Hi everyone, We have our PA Firewalls in different countries all around the globe.Lets call them Country1, Country2. Country3 and so on.All locations are connected to each other via S2S VPN.We have Panorama in location Country1. And it manages firewalls in all countries over the S2S VPN.At all sites, we do have local admin accounts.Now, my conce...

Active/Passive HA direct link between firewalls

Hi All, I use PA-220's in HA pairs often, and I've always used a straight-through cable to connect port 7 and 8 from FW1 to port 7 and 8 on FW2. I've never had ANY issues with this configuration. I just learned that PAN says to use a crossover cable when connecting the firewalls directly to one another like I have been doing all this time with ...

not able to access certain web sites from host behind PAN firewalls

I am trying to access http://www.brokercheck.com from behind the PAN firewall via dynamic NAT without any success. I have other customers behind different PAN firewalls, regardless of PAN OS version, with the same issue access website http://www.brokercheck.com. The FW rule is wide open "any any accept log" It works for customers NOT behind PAN...

dtran by L4 Transporter
  • 7524 Views
  • 4 replies
  • 0 Likes

Best Placement Integration Approach

Hi Guys,Just want to seek your inputs about what can be the best integration approach for this scenario.Currently, the VLAN gateway is in my core switch and I will be introducing PA FW into my network. I want to have control and visibility for my intervlan switching, will the virtual-wire approach be the best for this scenario? I am a bit not co...

Nikko by L1 Bithead
  • 2452 Views
  • 2 replies
  • 0 Likes

Best way to apply log Forwarding setting to multiple security policies in Panorama

I recently migrated a few HA pairs into Panorama in my environment. Historically, our security policies were configured to only send traffic logs from deny rules to our syslog. Any allows were only logged on the local firewall (due to costs of Splunk ingesting logs). It was simple to also send those to Panorama. However, I also want to now send ...

Daryl_B by L0 Member
  • 4185 Views
  • 2 replies
  • 0 Likes

The data length of the http2 message exceeds 65526 and later will be discarded

We then pass the data through http 2.0 in plaintext, the data length of http2 messages exceeding 65526 will be partially discarded, resulting in incomplete data and affecting normal operations.Currently, the solution is to turn off the HTTP 2.0 checks, not to do checks on HTTP 2.0, and the business is back to normal.May I ask if anyone has encou...

jianghxa by L1 Bithead
  • 2254 Views
  • 1 replies
  • 0 Likes

Resolved! Can't browse web pages

Hello all, I'm new in Paloalto firewalls, i'm doing a migration from Fortigate to PA220. i configured all interfaces, router... but I'm struggling with Policiesattached the basic policy i created to allow my LAN users to access internet:After testing the PA:users can only ping to internet eg: 8.8.8.8users can access website using IP address not ...

dns config.PNG
NAT config.PNG
policy.PNG
wzahri by L1 Bithead
  • 6750 Views
  • 8 replies
  • 0 Likes

user-id agent log showing machine account, expected behavior or bug?

Hello community, I´d like to check with you regarding the following:Since upgrading the user-id agent from 8.0 to 8.1 the user-id logs in the firewalls are showing "Managed Service Accounts" (computer accounts with "$" appended at the end) in the way "domain\computer_account$" as well as the user account who logs into the computer.Does anyone kn...

Carracido by L4 Transporter
  • 4484 Views
  • 2 replies
  • 0 Likes

Self-Signed Certificate expiry warning

Our GlobalProtect VPN was using a self-signed certificate which got expired caused end users not being able to connect to the VPN.This raises the question that what are the ways to get alerted for these sort of incidents. Is there any in-build mechanism on the firewall or the Panorama that we could use to get notified of the Certificate Expiry i...

PaloAlto FW RDP Across multiple AD domains

I'm part of a cloud team that does not manage the FW but am not getting clear answers from them.My operations counterparts have the following issue: Support person logs into IP address x.x.x.x into production domain. As part of their function, they must RDP into servers on prod/dev/pat/sit domains. Each domain with a separate ID once the rdp cli...

Resolved! Panorama Template/Template-Stack Variables Override

Is it best practice to override template variable settings at the template-stack or at the device level? It looks like template stack would be sufficient unless you have multiple firewalls and only a select number with different settings.

Firewall Palo can advertise aggregate route...

Hello, In our lab, we made a set up about peering BGP between Palo and a third part device.According to this kb from Palo : "The Palo Alto Networks firewall does not advertise an aggregated route to its peer when it receives a prefix falling within the aggregated route range from the same peer" but in our case it's workingDoes it mean the KB is ...

  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels