General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! When will the GlobalProtect GUI be supported on Ubuntu 20.04

I see on the following documentation page that only the CLI version of GlobalProtect is supported on Ubuntu 20.04, not the GUI version. Does anyone know when the GUI version wil be supported, or where I should look to find this information? Thanks!https://docs.paloaltonetworks.com/compatibility-matrix/globalprotect/where-can-i-install-the-glob...

arderyp by • L0 Member
  • 17016 Views
  • 3 replies
  • 0 Likes

Resolved! unable to block exe files after using File blocking Profile

I have followed https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/threat-prevention/set-up-file-blocking and created a file blocking profile to block Downloads of exe format while browsing. But it still does not block the exe downloads on the server i applied the file blocking profile. Please check and suggest the fix.

Palo Alto unable to route traffic into LACP trunked subinterface vlans

Hi,I have an issue with routing traffic over to a new DMZ SW implementation. Hope someone can crack the nut.Issue : Palo Alto unable to route traffic into LACP trunked sub-interface vlans in VRFs1. Each switch VRF is a Zone on the PA.2. All routes defined in respective VRs.3. All VRFs default route is the respective vlan IP tagged at the subinte...

BTC.pa by • L0 Member
  • 3412 Views
  • 2 replies
  • 0 Likes

Site to Site IKE Gateway Setup on 5250

Trying to set up ptp vpn between PA200 and corporate 5250. I haven't found a "How to set up if the PA200 is behind home modem" article as of yet. Is it my understanding that when I select the 5250 "Peer IP Address Type" = Dynamic it means that the peer address (home ip) is unknown. The PEER would be the 200 nat'd to the home public ip. ...

vnt90 by • L2 Linker
  • 4204 Views
  • 3 replies
  • 0 Likes

SDWAN DIA Path Monitoring

When I have a firewall configured as a SDWAN function with 2 DIA interfaces (2 ADSL) How to check whether links are ready for use? Any options? I tried to configure path monitoring but there are no options for source IP, It's seem SDWAN interface do not support path monitoring

Screen Shot 2563-10-07 at 23.27.00.png

Application ID's

Recently Cisco WebEx deployed a software update and it changed enough so the Palo Alto could NOT recognize the application ID as being webex, causing an impact to our client. So my question is, is there anyway to determine if a software update for any vendor will cause the application ID to NOT recognize the application after the update?

skobel by • L0 Member
  • 3847 Views
  • 3 replies
  • 0 Likes

Sporadic Applications Fail to Load - Downloads Sporadically Freeze

For a few weeks now, we have been experiencing sporadic issues with some applications that do not load correctly or at all. We have also had sporadic issues with downloads that freeze and eventually fail. This isn't isolated to a browser issue. We have primarily noticed issues associated with "amazonaws" related IP addresses. On the firewa...

duttonr by • L0 Member
  • 2696 Views
  • 1 replies
  • 0 Likes

MineMeld txt from IIS

Hello, I am trying to setup a static list i am updating a txt file hosted in IIS (from output in our IDS service) on IP's I would like to block. I have tried to supply the list directly to EDL list from IIS (created txt via so may ways - including in Linux and transfering file to IIS) but firewall sees the list, and ignores them all. I opened a ...

Next-Generation SD-WAN has been released

Hello everyone, Not sure if you have seen the news, but the new Next-Generation SD-WAN, Prisma SD-WAN (formerly CloudGenix) has just been released. Next-Generation SD-WAN Solution Please be sure to check out my blog here about it: https://live.paloaltonetworks.com/t5/blogs/introducing-next-generation-sd-wan/ba-p/349909 There are lots of ...

ALL LIVEcommunity Graphics (3).png
jdelio by • L7 Applicator
  • 3940 Views
  • 2 replies
  • 0 Likes

Where to check to total amount of disk in Panorama

Hello, I need to check to the total amount of disk in Panorama. In where can I check it? It is because if I run the "show system logdb-quota" it give me, just the amount of the log space. I need the total of the system. Regards,

iscott by • L2 Linker
  • 16521 Views
  • 2 replies
  • 0 Likes

What is the role of an IP address on a tunnel interface?

I noticed that in some of our SOHO sites, the tunnel interface for VPN to the data center has an IP address and in other cases it does not. Can someone explain the value of having an IP address on the tunnel interface versus not? I'm working through an arp cache issue that arises on a SOHO site which does not specify an IP address but the site...

Resolved! virtual router to virtual router communication

hii'm using vm series, and i have 2 virtual routers, each of them has it's own lan and wanhow can i make the lans connect to each other? i've tried to do static routing but the traffic doesn't go through. what's the correct way to do that? thank you

Critical System Alerts on a PA-220

Hello,We recently implemented a secondary line on our network and were testing the failover process. Everything worked well, however, we realized that we were not alerted of the primary circuit going down or recovering. It was confirmed when looking through the system log that the failure and recovery were reported, yet no emails was sent out....

vanglee by • L1 Bithead
  • 4912 Views
  • 5 replies
  • 0 Likes

HIP Checks for Browser Version

I have a customer that would like to limit GP authentication based upon browser version running on the clients. They would like to collect all browser versions and then start blocking connections from clients below minimum settings. Trying to figure out how to do this but not seeing any straightforward method to collect all web browser versions...

  • 24462 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels