General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Converting a cluster to FIPS-CC

Given all of the hurdles one has to go to to get a stand alone device converted to FIPS-CC, I'm told I have to do this on a cluster, so needless to say my anxiety is a bit on the "through the roof" side. Maybe I'm not looking hard enough, but I'm unable to find the steps for an active/passive cluster. I'm assuming someone has already done this,...

bwsaloum by • L2 Linker
  • 4354 Views
  • 3 replies
  • 0 Likes

Resolved! How do i setup a BGP inbound filter that allows only 1 AS

Been looking and googling and can't find it . so I have created a BGP import filter.attached to router group.But the match ... "AS Path Regular Expression" what do i put in there to limit it to 1 AS Find it hard to believe somebody hasn't done this. Also the doco ... sigh I'm thinking something like ^[^_]*$might work . not even sure is pa regex...

Resolved! Major flaw in Panorama: can't configure anything without a real firewall added!

1. Create a Template. Add some network interfaces and zones and related stuff to it. 2. Create a Device Group. Add some Address Objects to it, that you'll be referenceing in your Security/NAT Policies later. 3. Try to create a Security/NAT Policy ... and notice how none of your Zones are available! There's nothing in Panorama that links Tem...

fjwcash by • L4 Transporter
  • 11168 Views
  • 5 replies
  • 0 Likes

Traffic Question

Hello everyone, I am seeing a strange issue that I haven't come across before and I'm not sure how to troubleshoot it. To make it as simple as I can, sometimes traffic going to a specific destination isn't using the defined OSPF route. So for example, the destination is 10.50.0.0/16 and OSPF is enabled on the virtual router using a specific t...

COlson by • L2 Linker
  • 2206 Views
  • 1 replies
  • 0 Likes

Problem with exporting APP-ID list with all filter options

So. I have found a way to export app-id data from my Palo alto fw (From: Object > Applications) into a CSV format.I see on top the following filters: category; subcategory; risk; tags; characteristicHowever I am missing the Characteristic filter in my spreadsheet. Is there a way to get a column or some alternative which will allow me to filte...

Resolved! PA-VM-100 No traffic logging

Hi,I have just installed VM Series and configured it. Traffic goes through, rules are working but there is no logs in the monitor page.I haven't installed the license yet because I want to be sure that I want to keep it as I configured and without errors.I will try to provide more details;PA Version: 6.0.0VM version: ESXi: 5.1 vSphere:5.1 vCente...

CLIGURU by • L1 Bithead
  • 8728 Views
  • 6 replies
  • 0 Likes

Blocking Google Games !

Has anyone had any success in blocking the Google browser based games yet? I have seen a few threads with no answers. I'm going to bust out the Fiddler and see where it is going during this but I don't want to interfere with normal users and their Google searches. I was thinking there would be an app-id for it but I may have to find domain name ...

In the traffic logs the users disappear from the assigned policies

Hi team We are having problems with user groups in the policies. When we see the logs in the users section it is blank after a while the users can be seen. Take the tsf out of the high pole and checking the authentication logs, no connection problems were observed.In the user-id logs I could see the following: Error: pan_user_id_win_sess_query (...

Resolved! Downgrade path from 9.04 to 8.1.6

Hi, what is the downgrade path from v9.04 to 8.1.16? can downgrade from 9.04 to 8.16 directly? or 9.04 --> 9.0 --> 8.16 ? or 9.04 -> 9.0 -> 8.1.0 -> 8.1.16? Please advise, thanks a lot in advance!

Panorama shared object rename bug?

Panorama 9.1.4. I'm sure this is a bug... When a shared and device-group specific object with the same name exist, renaming the shared object updates references in the child device-group resulting in those objects (policies, profiles, address-groups, whatever) inheriting the shared object value instead of the DG-specific one. This should not hap...

mb_equate by • L3 Networker
  • 3642 Views
  • 2 replies
  • 0 Likes

Resolved! static route issue

Dear community, after upgrading our PA220 to PAN-OS 9.0 our static routes are not working anymore and during a commit we recieve the error massage Static route default_route_to_WAN next hop IP 192.168.100.254 is not in subnet of outgoing interface ethernet1/1(Module: routed)Here is the configuration of our default route to the internet: What am...

Int_WAN.JPG
VR.PNG
commit error message.PNG

Expedition Query

I imported asa running config to expedition tool after that unable to export config file for PA it asking need to upload panos configuration.Please suggest for successful export.

Yasar2020_0-1598345806494.png

PARTNER PORTAL ERR CONNECTION RESET

Hi All,I am currently taking an online self-paced course in the education portal. But suddenly the videos stop and all palo alto related link as ERR CONNECTION RESET. The photo attached is link for CORTEX XSOAR Admin course.

  • 24462 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels