General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! HIP profile for external Partners

Hello ;We have to setup HIP profile check for Corp users and external partners Currently we have a common Loopback Interface having a Private IP and we have a tunnel interafce Both loopback and Tunnel are part of same zone called GP This is same Cluster on which Portal and gateway are running In order to assign separate HIP Profiles to Corp us...

session disconnect during A-P failover

Hi, Can anyone suggest, if we failover from Active to Passive unit on PA firewall. will this maintains the established sessions by default. Or we have to additionally enable some other setting to make this enable (should maintain session during cluster failover). Additionally, one more observation while we did recent failover....We have 09 IPSe...

Jimmy20 by • L2 Linker
  • 4498 Views
  • 2 replies
  • 0 Likes

LSVPN - Contingency

Hi guys, I have one snario that have some satellites connecting each with Global Protect Portal (Large Scale VPN) and I need implement contingency. I was trying to create other portal, other gateway , PBF in the satellites to control default route, and other tunnel ipsec (global satellite), but the problem is: when I change the default route ...

Password protected internal site

Hi everyone, I'm trying to migrate a rule of an ancient firewall (Microsoft ISA server) that was "publishing" an internal resource using regular HTTP - just a web page - but protected by an RSA SecurID login page. The ISA / RSA implementation was just enforcing a login page before showing up the published Web site: External User (Internet) ---&...

Rievax by • L2 Linker
  • 3755 Views
  • 4 replies
  • 0 Likes

PAN CLI: Verifying Service Object Existence and Adding New Service Objects

I am starting to do more work via the CLI such as security rules. How can I check if a service object already exists using the CLI? And if it does not exist how do I add the service object to I can use it in my security rule? If I try to add a service object and the name already exists will the PAN warn me and not all that to be input?What if th...

palomed by • L3 Networker
  • 12353 Views
  • 2 replies
  • 0 Likes

Resolved! Only 0.0.0.0/32 Obtained from MindMeld Query

I have been using MeldMeld for several months in a lab environment with great success. Recently I setup a new server for our production firewalls but I have encountered a problem that I have not been able to solve. I can query MindMeld using a regular web browser with no problems and obtain expected ranges of IP's by using the following URL form...

jnye by • L1 Bithead
  • 12881 Views
  • 6 replies
  • 0 Likes

Resolved! Multiple Portals for Global protect -Configuration check-Inputs needed

Hello ; For one our Customer running PA 3200 Series in HA having GP License ( HIP checks) Currently the GP Portal and Gateway have common Interface . The GP URL is vpn.connection.it ( sample name) The requirement is that Internal Users use the URL : internal.vpn.connection.itExternal Users(Partners) use the URL : external.vpn.connection.it ...

Resolved! Microsoft CERTSRV

Why does this have to be so difficult? I want to create a cert on the palo. Device > Certificate Management > Certificates > GenerateHighlight Generated Certificate > Export Certificate > Open with NotepadCopy contentsGo to my Microsoft CERTSRV > Request a CertificateHere is where it starts to get a little fuzzy.....User Cert...

Resolved! test security-policy-match command giving me odd output?

I was trying to work out which security policy applied to traffic through my Palo Alto from 10.77.22.10 (in the trust zone) to 10.99.0.1Firstly, I wanted to confirm what zone 10.99.0.1 was in using this page : https://alwaysnetworks.co.uk/identifying-which-zone-a-subnet-is-in-on-a-palo-alto-firewall-script/ administrator@CAMPA01(active)> tes...

Resolved! Polling JSON Format for AKAMAI

I am trying to create a prototype for a Miner that pulls IP's from a JSON formatted file. I have looked at the documentation for setting up a JSON miner (https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-MineMeld-to-extract-indicators-from-a-g...) and this topic similar to my issue (https://live.paloaltonetworks.com/t5/minemeld-discus...

Resolved! How to enforce GlobalProtect Connection for Network Access on iPhone with GP 5.0 App

Hey Guys, i'm currently testing the GlobalProtect App 5 with iOS Deviecs and Airwatch MDM. Everything works great, but it seems like that it isn't important which setting i've selected in the Portal > Agent > App (Settings). I've tried to enforce GlobalProtect for Network Access on iPhone but i can still deselect "connect on demand", so it...

Resolved! Migration without Expedition

HelloIf I wanted to migrate from Checkpoint to Palo with Panorama, but not use Expedition, what would be the general steps? Thank you for your time.

Configure HA1/HA2 command line

Need to configure the following in CLI:Control Link (HA1)Port ha1-a Control Link (HA1 Backup)Port ha1-b Data Link (HA2)Port ethernet1/1 Data Link (HA2 Backup)Port ethernet1/2 Any insight would be appreciated.

PA-5250 Power Supply Question

Do the power supplies within the PA-5250 load share? This is probably a real simple question but I have not found an answer within the documentation yet? Thanks!

B_Turner by • L0 Member
  • 3176 Views
  • 1 replies
  • 0 Likes

Resolved! import device state order

Hi,I've done this successfully in the past, but cannot remember the proper order. I have a PA-200 that I want to replace with a PA-220. The PA-220 is in Panorama, its a device group + template. Should I1) configure the PA-220 with basic ip connectivity to Panorama, add the serial add it to the device group, template, push the config and then ...

ce1028 by • L4 Transporter
  • 21144 Views
  • 12 replies
  • 0 Likes
  • 24463 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels