General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4254 Views
  • 0 replies
  • 0 Likes

Read-Only Superuser by Security Zone

Hello, I hope everyone is staying healthy. I work at a company that provides ISP services to public schools, each school district is divided in to separate security zones on our Palo and I am trying to see if a read-only user can be created that is able to only look at security and NAT rules for their assigned zone. I've been fiddling around in...

Resolved! IPSec VPN restarts very often

Hallo,I have defined a IPSec VPN connection with following params:ike: 3des/sha1/dh5 Lifetime: 8 hoursipsec: ESP/3des/sha1/dh5 Lifetime: 30 minutes (life size not set, shows 0MB)ike gateway: main mode, DP enabledThe connection is established but in system log I see very often (every 5 sec.) tunnel is again and again down and up. We have packet l...

Resolved! Need help on configuring SNMP V3 to send trap messages to OpManager (Net Flow)

Hello Team, I have tried to configure SNMP V3 to send trap messges to opmanager in palo alto. - At the tiime we struct with engineID,here we are unable to find engineID for Palo Alto in Opmanager. - And also SNMP Walk itself its not working.- Its seems something i was missing in the configuration.- Can anyone help me here on what are things need...

Access Denied on doc links within Live Community

Maybe it's because I'm new here. BUT, every doc link I click on via a post in the Live Community gives me an 'Access Denied. You do not have sufficient privileges for this resource or its parent to perform this action. Click your browser's Back button to continue.'What am I missing? Please help.Below are several of the links I've tried and all g...

DCas by L0 Member
  • 4055 Views
  • 2 replies
  • 0 Likes

Traffic takes different routes depending on application

Hi community,I am facing a weird behavior that is driving me nuts.I have 2 sites linked by a Leased Line (zone L3-GW-InterDC) and an IPSec tunnel (zone L3-VPN) as a backup. 2 static routes are therefore configured, with different weight and path monitoring. I don't use PBF in this setupEverything works fine, except for this traffic between 2 hos...

FlowBank-IT_0-1610986904030.png

Resolved! Clientless VPN not displaying page content when using any browser

Hi, We have set up a clientless VPN trying to access a server with AIV Hub on it (this provides a customer portal). The VPN works fine and we can log in and see the application.The URL for the application is http tcp port 8080 so it has been written as http://x.x.x.x:8080/aivIf I click on the app a new browser tab opens but the page does not loa...

Detect ipsec vpn tunnel down with remote palo alto peer

PA5020/PAN-OS 7.1.10 I am trying to develop a NAGIOS check to get an alert , when a vpn tunnel between PA's at different locationsis down. So far I have been looking at the ifup-status of the corresponding tunnel interface at the local firewall. It turnsout that this is still up , even if the vpn tunnel is down. From the local firewall, this c...

Default interzone deny rule showing Allow traffic logs.

Default inter zone deny rule showing Allow traffic logs. There are expected deny logs but some requests are getting allowed by hitting default interzone deny rule.Very Strange behavior and we have already verified the Rule and its actions, it is configured to deny traffic from any to any. Please share if any thoughts on this....

Unable to connect to pool.ntp.org

HiI have a problem with the NTP sync. When i make a "show ntp" NTP state:NTP not synched, using local clockNTP server: asia.pool.ntp.orgstatus: rejectedreachable: noauthentication-type: noneNTP server: pool.ntp.orgstatus: rejectedreachable: noauthentication-type: none But my mgmt interface is alow via policy rule to use ntp. I am able to ping th...

shared folder in clientless VPN

Dears, Is it possible to configure the shared folder in clientless VPN?Example:- I have one file server and i want to give access to users via clientless VPN. please share any documents for configuration.

Resolved! Active Active BGP AS Number

Have a Active/Active spit data center solution and question has been brought up if it is possible to use different AS numbers on each of the Palo's. My thinking is why have Active/Active, just use each Palo as a separate individual firewall at each DC. I'v never seen Active/Active Palo's having separate BGP AS numbers. It looks like it is possib...

Resolved! SSL Decrypt does NOT work with TLS 1.1 or TLS 1.2

Hello,I'm running a cluster of PA (4.0.8) with SSL Decryption configured.SSL Decryption is not able to decrypt SSL traffic if the HTTPS session is using TLS 1.1 or TLS 1.2.Test with www.gmail.com Chrome : OK (see gmail application in the traffic log)Firefox : idemIE 8 or 9 with TLS 1.1 or TLS 1.2 DISABLED : idemIE 8 or 9 with TLS 1.1 or TLS 1...

licenselu by L4 Transporter
  • 21535 Views
  • 21 replies
  • 0 Likes

Palo Alto PA-3020 Won't Boot

I have a Palo Alto PA-3020 that I got from work a few months back, it was pulled in working condition a few weeks ago, but when I power the unit on the power LED lights up and the fans spin, but no other lights are on. I tried connecting to the unit via console but I can't seem to get console output, I've tried multiple USB to serial adapters bu...

Resolved! SSL Decryption and Security profiles

Hi I have a question . Currently PA 3020 cluster we don't have ssl decryption enabled . We plan to do it in March However , if we enable all other security features like AV,Antispyware File blocking , Vulnerabilty Protection , Wildfire etc , it wont be fully effective as all these Security profiles cant see what is going inside SSL unless we ...

add new local log collector in collector group

We are using standalone M-200 for 5 locations firewall and created collector group with single local log collector of M200. We are deploying our new M-200 at another location and it will be in HA with our existing M-200.This new M-200 will be Active-Secondary panorama and we will add local log collector of it in existing collector group. So in e...

Deepak_K by L3 Networker
  • 1856 Views
  • 1 replies
  • 0 Likes
  • 24362 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels