General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Global Protect issue with Windown server 10

The issue is that when I connected to a server through Global Protect, I can't connect to another server.I have to disconnect from Global Protect and then connect to the desired server. So basically he can connect to one server at a time.However, with Windows 10, version 1903 have no issue. But when I try to connect to Windows 10, version 2004 h...

Resolved! PA-2020 Update PAN OS 7.1.11 possible?

Good morning,we have a PA-2020 with sw-version: 7.1.11Can I update the software version to latest PAN OS?We want to use SAML 2.0.is there a way to achieve this? kind regards,Roland warten mit Login admin / admin show system environmentals ----Thermal---- Slot Description Alarm Degrees C Min C Max C S0 Temper...

SD-WAN internet link (DIA) monitoring

I have a PA-220 with dual ISPs (WiFi and LTE). I tried to configure SD-WAN for direct internet access (DIA). Both gateways (routers from both ISP) are localy connected via ethernet. As far as I know, SD-WAN pings the gateway IPs to calculated the link quality and because they are both locally connected, there is usually no issue. The troubles o...

Problem with routing of NATted reply packets over IPSEC tunnel

I have an IPSEC tunnel to another organisation, they have two endpoints at the other end on addresses which conflict with our networks. We can just focus on one to keep it simple. We have an IPSEC tunnel set up and passing traffic fine (tunnel.3 interface on the untrust zone).The external endpoint’s native address (at the other end of the tunne...

djr by L4 Transporter
  • 5866 Views
  • 3 replies
  • 0 Likes

Resolved! SMB & Robocopy

Hi,I have server 2016 with all patches and I use Robocopy to sync files to the backup server. RC kill smb "server service" several times per day, no event log. Windows 10 clients cant access shares.The only solution is to restart the server. Can even restart server service, which stuck in stopping state. I like robocopy But, can't anymore use...

rasil66 by L1 Bithead
  • 7546 Views
  • 6 replies
  • 1 Likes

GlobalProtect SMB file transfer results in error for large files

We have some users that need to transfer large files on-preemies. When copying files shortly between 5-20% data transfer this error is thrown. Files are MultiGig in size. Small file around 100M that I tested did not show this error. Copying to the same file share from within on-prem network does not give this error. I have tried changing mtu as...

image.png
raji_toor by L4 Transporter
  • 5925 Views
  • 3 replies
  • 0 Likes

Setup Azure MFA with Global Protect - NPS/ISE

I am building this new but don't have concrete steps to start with. What I understand until now is that we need NPS extension for MFA to work with Azure. We last year moved away from NPS as our radius server to Cisco ISE. So do I have to figure out how to integrate ISE with Azure or do i have no choice but to implement NPS to get this working.

raji_toor by L4 Transporter
  • 3879 Views
  • 2 replies
  • 0 Likes

User-id issue.

Hi All, Firewall is 3050 with pan-os version 9.0.9-h1 we are using user-id agent as well as agentless for user-mapping.Sometimes we are getting machine names instead for ip-address instead of source usernames.we have user-based security policy. Why do we get machine names for usernames in the user-id logs. Agent version is 9.0.5-8 Thanks and reg...

Trouble with NAT and VPN

Hi there,i want to finish an easy setup which needs a simple DNAT and forwarding into a VPN tunnel on my PA5020.I've created a working VPN tunnel which is the destination for my traffic. And this works fine if i'm using the tunnel ip to reach targets inside the vpn destination network (192.168.5.0/24). To use this setup it is necessary to hide t...

QoS and GlobalProtect

We have a use case where many users need to upload files on premises and these are very large video files to on-premises. We want to rate limit/control the organization bandwidth consumed by these users. What are our options. Also we use subinterfaces so there is a QoS already in use for rate limiting traffic traffic to another campus. How can w...

raji_toor by L4 Transporter
  • 2674 Views
  • 2 replies
  • 0 Likes

Second Gateway and PPPoE

Hi allI'm in trouble whit this scenario:- Internet connection by PPPoE protocol with 1 static IP (ie 3.3.1.205)- additional 8 public IP like: 3.3.3.0 to 3.3.3.7 with 3.3.3.1 as gateway- Internet connection on ethernet1/1- internal LAN on ethernet 1/8 set with IP 192.168.80.254 (and LAN 192.168.80.0/24)- Web Server on ethernet 1/5 = 192.168.50.25...

Resolved! Logging - advise if CPU load same regardless of log export method HTTP(s) Syslog and Netflow logging

Hello Experts, I tried to find any information to assist with understanding if some log export protocols taxing CPU (Management and DP) more then others. Perhaps ones DP pass log events to MP it is for Management to package and ship the logs, therefore, as long as some rules has logging enabled, the DP load will be the same regardless of the pro...

SergGur by L2 Linker
  • 4169 Views
  • 2 replies
  • 0 Likes

Resolved! secure email alert configuration.

Hi, I have now a problem and that is I have been through all discussions here related to email alerting, but all uses non-authenticated smtp.my problem that my used email uses secured smtp server, means I need to enter my email smtp authentication information which is not available in my current PAN-OS 9.0.any ideas how to configure this authe...

IP Spoofing understanding

I'm planning to implement IP drop - under Zone protection on a production system. I'm really only interested in the ' IP Spoofing ' aspect & I'd like to understand a little more on how it works so that I can addresses any issues, should they arise. Is the basis of IP spoofing to stop any RFC 1918 addresses from coming into the FW from the u...

smk391 by L0 Member
  • 16206 Views
  • 1 replies
  • 0 Likes

I can't open Support Cases.

I can't open Support Cases. Becauase single sign on error. I cleared the browser cache and tried with other browsers too. Other options work fine, but only the Support Cases is not open. What should I do?

  • 24432 Posts
  • 125 Subscriptions
Top Solution Authors
Labels