General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Dedicated Log Collector interfaces

All, I am having trouble finding good documentation on this. Hoping maybe the community has experience with it. I need a few questions answered. We have 2 M600 dedicated log collectors. We plan on utilizing the 10 GB interfaces for Device Log Collection. That part is clear as spring water. The part that is very muddy Log Collector External Log F...

Administrative Install

I'm having trouble finding the correct administrative installation process. I have several field reps that do not have administrative rights to their laptops. I need to install GlobalProtect for them and have it pre-configured with proper certificates, portal addresses, etc. My certificates are self-generated by the firewalls, so are not trus...

Syslog - LFP options

Hi Guys We have PA with version 9.0.4 and have to configure Syslog server log forwarding on the same. Created (syslog) server profile..Now creating "Log Forwarding Profile" there are options "forward method" and "built-in-action" available there. which is not giving so much clarity what need to be configure there, Referred few articles available...

Jimmy20 by L2 Linker
  • 4671 Views
  • 5 replies
  • 0 Likes

Converting a cluster to FIPS-CC?

Given all of the hurdles one has to go to to get a stand alone device converted to FIPS-CC, I'm told I have to do this on a cluster, so needless to say my anxiety is a bit on the "through the roof" side. Maybe I'm not looking hard enough, but I'm unable to find the steps for an active/passive cluster. I'm assuming someone has already done this,...

UserID agent sessions to public IPs

Hi, We are detecting in Palo FW that there are sessions from UseriD-Agent servers to publics IPs. Our SOC confirmed that some of these public IPs are categorized like low reputation. Sessions are in port 135. I know the UserId agent uses this port but its reaching publics IPs.We have GP enabled, and there are also connections port 135 to the pub...

BigPalo by L4 Transporter
  • 3868 Views
  • 4 replies
  • 0 Likes

Resolved! BGP "Router ID" and multiple peers

What exactly is the "Router ID" field used for in the BGP tab of Virtual Router configuration?I ask because I'm planning on announcing a /24 to two different ISPs/peers, and each ISP has its own /30 for the transit segment. So, if I make the router ID the IP address for one segment, it is incorrect for the other segment... or does "Router ID" n...

bradenmcg by L3 Networker
  • 35436 Views
  • 14 replies
  • 0 Likes

Converting a cluster to FIPS-CC

Given all of the hurdles one has to go to to get a stand alone device converted to FIPS-CC, I'm told I have to do this on a cluster, so needless to say my anxiety is a bit on the "through the roof" side. Maybe I'm not looking hard enough, but I'm unable to find the steps for an active/passive cluster. I'm assuming someone has already done this,...

bwsaloum by L2 Linker
  • 4265 Views
  • 3 replies
  • 0 Likes

Resolved! How do i setup a BGP inbound filter that allows only 1 AS

Been looking and googling and can't find it . so I have created a BGP import filter.attached to router group.But the match ... "AS Path Regular Expression" what do i put in there to limit it to 1 AS Find it hard to believe somebody hasn't done this. Also the doco ... sigh I'm thinking something like ^[^_]*$might work . not even sure is pa regex...

Resolved! Major flaw in Panorama: can't configure anything without a real firewall added!

1. Create a Template. Add some network interfaces and zones and related stuff to it. 2. Create a Device Group. Add some Address Objects to it, that you'll be referenceing in your Security/NAT Policies later. 3. Try to create a Security/NAT Policy ... and notice how none of your Zones are available! There's nothing in Panorama that links Tem...

fjwcash by L4 Transporter
  • 11006 Views
  • 5 replies
  • 0 Likes

Traffic Question

Hello everyone, I am seeing a strange issue that I haven't come across before and I'm not sure how to troubleshoot it. To make it as simple as I can, sometimes traffic going to a specific destination isn't using the defined OSPF route. So for example, the destination is 10.50.0.0/16 and OSPF is enabled on the virtual router using a specific t...

COlson by L2 Linker
  • 2149 Views
  • 1 replies
  • 0 Likes

Problem with exporting APP-ID list with all filter options

So. I have found a way to export app-id data from my Palo alto fw (From: Object > Applications) into a CSV format.I see on top the following filters: category; subcategory; risk; tags; characteristicHowever I am missing the Characteristic filter in my spreadsheet. Is there a way to get a column or some alternative which will allow me to filte...

Resolved! PA-VM-100 No traffic logging

Hi,I have just installed VM Series and configured it. Traffic goes through, rules are working but there is no logs in the monitor page.I haven't installed the license yet because I want to be sure that I want to keep it as I configured and without errors.I will try to provide more details;PA Version: 6.0.0VM version: ESXi: 5.1 vSphere:5.1 vCente...

CLIGURU by L1 Bithead
  • 8567 Views
  • 6 replies
  • 0 Likes
  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels