General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 2980 Views
  • 2 replies
  • 14 Likes

Resolved! LACP not active, negotiation failed. One member is not happy

Hi All,

 

PA-3060, PAN-OS 7.1.17

 

Please see below:

 

 

LACP:

**********************************************************************************
AE group: ae1
Members: Bndl Rx state Mux state Sel state
ethernet1/17 yes Current Tx_Rx Selected
ethernet1/18 no Cur

...

ddd.JPG
myky by L3 Networker
  • 8670 Views
  • 3 replies
  • 0 Likes

DNS Application uses more DP CPU utilization

Hi,

 

We are facing issue with DNS Application, it uses more DP CPU Utilization 60 to 70%.

We have done DNS Application override but no luck.

 

Please find the DNS Session details below.

 

Mem-Pool-Type MaxSz(KB) Threshold MinSz(KB) CurSz(B) Cur.Alloc Total

...

Clear text traffic to DLP

What do you guys do to send clear text or SSL decrypted traffic over to a nDLP for further action?  In my case, the nDLP only support ICAP in order for it to accept traffic from its peering devices. Since PAN doesn't support ICAP at all and I am in s

...

rKarki by L1 Bithead
  • 2037 Views
  • 1 replies
  • 0 Likes

Resolved! cannot find matching phase-2 tunnel for received proxy ID

We have a site to site VPN setup that was allowing one IP. On the ipsec tunnel sec proxy-id allow local (10.1.2.1/32)  which was working just fine.

We had to recently allow two more IP's 10.1.2.20 and 10.1.2.75. I Changed the ipsec tunnel sec proxy-id

...

bino150 by Not applicable
  • 26281 Views
  • 7 replies
  • 1 Likes

Internal Gateway configuration problem

I'm using PA-3220 firewall.

Ethernet 1/1,1/2,1/3,1/4 is connected to main switch, Cisco AP, Internal router and server 10Gb switch.

 

I setup a GlobalProtect internal gateway for using User-ID and used vlan 1 (192.168.1.2) as the gateway and Portal's IP

...

Use Google Apps as User-ID Identity Source

Fellow Engineers -

 

Wondering if there is a way to integrate User-ID with Google Apps, such that a school that has deployed Chromebooks can use the students' existing Google login IDs to identify the users on the Chromebooks.  Does anyone know if this

...

Authentication Sequence not working

Hi All,

 

I have successfully tested Authentication policy using LDAP, MFA (Okta API), SAML and RADIUS (Okta). I am working on the redundancy scenarios wherein if Okta fails, the fallback would be LDAP. I am using RADIUS (Okta) and LDAP in the Authenti

...

Chromebooks user-id ?

Has anyone tried to get a userid authentication from users with Chromebooks?  We are evaluating Chromebooks to be used in a laptop cart setting in our school.  I don't want to fall back to a portal login if there is any way I can get a current user o

...

Resolved! Alert mail for threat detection

Hello all,

 

I try to set up alert mail to prevent when my PA220 detects an threat (inboud attack for example).

 

I configured scheduled PDF reports (daily and weekly) but I want also be informed instantly when a threat is detecting ?

 

It is possible ?

 

Th

...

feelgood by L2 Linker
  • 4122 Views
  • 5 replies
  • 0 Likes

Resolved! Terminal Server Agent port redirection

We are having some issues regarding the port redirection when combined with third party program. 

 

This program brings up a TCP listening port that TS Agent redirect to the designated port in the default range (20000-39999) but the program doesn't not

...

patsa.png
  • 24040 Posts
  • 99 Subscriptions
Top Solution Authors
Top Liked Authors