General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Active-Passive Cluster Link & Path Monitoring

Hi All, Referring my prior discussion Subject - "Firmware Updation A-P" , We have below configuration enabled on Link & path monitoring configuration at this moment, have a look on screen shot. Will this be sufficient to trigger auto failover to Passive , if in case we can disconnect / disabled any of the directly connected interface from A...

Link and Path Monitoring Screen Shot.jpg
Jimmy20 by L2 Linker
  • 3499 Views
  • 2 replies
  • 0 Likes

How to allow NTP ONLY to pool.ntp.org

I have a requirement to allow the internal NTP servers to sync with ONLY US.pool.ntp.org. I have tried creating the rule 2 different ways.Create a address object using FQDN for us.pool.ntp.org and use that in the rule destination.This doesn't work as there are like 500+ ips behind that poolCreate a custom URL category for us.pool.ntp.org and us...

Logon Method for mixed users using certificates

Hello , I have a requirement , Currently both Internal and external users ( both are AD users) connect to GP via their AD user name and Password Requirement is enroll Machine certificate to Internal Users and a Common Certificate issued by Palo Alto Generate Root CA to all External users Internal Users are having Machine Certificate issued by P...

Resolved! Mangement interface

Hi, i have distribution , core ,access layer data center are connected to core , Need to setup data center firewall In data center we are following 192.168.0.0 /16 in distribution 10.0.0.0/8 So what should be my managemnt interface ip address . I should choose one of the datacenter network ip address ? Thanks

simsim by L4 Transporter
  • 9582 Views
  • 9 replies
  • 0 Likes

Log Forwarding Rule/Object

I have a server that connects every 10 minutes to an SFTP server. I would ideally like to know when it is done for the day. So I setup an email server profile and started on a Log Forwarding object. It does not really have to be a log, just and email that says "Oi the server is done for the day". The server connecting is a third party so I c...

DIR_IT by L0 Member
  • 2578 Views
  • 2 replies
  • 0 Likes

Replace 5050 with 5250

Customer is replacing a 2 pair of 5050's multi-vsys with 2 pair of 5250's. All of the configurations are local to the firewall with the exception of objects which are managed by Panorama. The final plan will be to have Panorama manage the firewalls appropriately. The 5050's will still be in place for a while after migrating to the 5250's. What i...

Aruba AP with PAN, User-ID mapping with IP, Syslog Filters

I'm trying to map User-ID to IP in our intranet so that we could easily identify User in PAN Traffic. We have Aruba APs adn AC authenticating with external Radius Server, While our PAN is sitting at the gateway. What i'm trying to do is using Aruba AC sending debug level logs to PAN, PAN could use Syslog Filters to filter our the mapping. I'm ...

ZhenGuo by L1 Bithead
  • 9401 Views
  • 3 replies
  • 0 Likes

First time BGP setup VR question

We are about to implement EBGP for the first time. The EBGP will have two peers. The ISP wants it to be used as a primary/secondary rather than equal split. We currently have two ISPs that will be going away. We are a 24/7 shop so we need a strategy to test EBGP without interfering with existing traffic.Does it make sense to create a new VR stri...

Resolved! Global Protect PreLogon question

Hi All, I am testing a build for Global Protect PreLogon which I have working to a degree. When I log in for the first time I successfully connect to GP using machine cert. When I log out, it switches to the prelogon state. When I reboot or boot the laptop, Global Protect is disconnected. Is there a way I can make GP connect as soon as the wirel...

a.jones by L3 Networker
  • 17460 Views
  • 6 replies
  • 1 Likes

Resolved! Port Move - Using Panorama Templates

Hi Folks,I need to do a port move on a 3220 - RJ45 to an SFP port - part of an ISP upgrade. Everything else remains the same. The trouble i have is that all the config is managed from a Panorama Device group. I don't know of a way of editing the various dependencies in the GUI (static routes, GP gateways, tunnels, etc) - so i am considering XML ...

GN_ROS by L1 Bithead
  • 3185 Views
  • 2 replies
  • 0 Likes

Proxy id not seen in ssh session . but able to see in GUI.

Hi TeamWe are facing issue with Proxy ID, we have configured before 114 proxyID in IPSec Tunnel and its working fine but recently we have added 4 more proxy ID in the same IPSec Tunnel. While we are not able to see the proxy IDs configured via GUI. Proxy id not seen in ssh session . but able to see in GUI. Let me know if there is any Proxy ID Li...

Resolved! QoS either on Sub Interface or Vsys

I have 24 VSYS on the Firewall,All of them are using the same physical interfaces for incoming and outgoing traffic but different sub-interfaces. I have decided to apply the QoS profile for egress traffic. As I know I can apply the QoS on the physical interface. My question, how can I configure a dedicated QoS profile using only the sub-interfac...

Access GUI port.

There are two locations where the only dedicated link is (X) access to the management of the security teams is through publication (https: // xxxx: port) All security teams have a management IP and are published with the same public ip 200.15.21.1 After the upgrade, from version 7.1.25 to 8.1.15-h3, it is observed that when you want to access th...

Global Protect, Win 10 drive mapping issues

Hello all, Just throwing this out there to see if anyone has seen similar issues. Over the last 6 months we have been having intermittent drive mapping issues on clients that have Global Protect installed. All the clients have Win 10 on them and we have global protect 5.0.5 installed. The drives are mapped using group policy and in trying to ge...

  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels