General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1716 Views
  • 0 replies
  • 0 Likes

How to allow a specific file extension

I work for a K-12 school district that uses a program that reads books to students.  The file extension is .kes (KES is a file extension that belongs to Text Files of Kurzweil Educational Systems) and is blocked in our file blocking profile as an Enc

...

almay by L2 Linker
  • 4541 Views
  • 2 replies
  • 0 Likes

PA config replication through Panorama

Hi All,

 

I am looking for a method to replicate the configuration of one of our virtual firewalls to a physical firewall through Panorama device-groups and templates.

 

Let me explain the setup:

We have a core firewall with multiple vsys enabled, and one

...

VarunRao by L2 Linker
  • 3435 Views
  • 3 replies
  • 0 Likes

Vwire interfaces are flap

We have a Paloalto connected in vwire mode Cisco ASR1 is  connected on PA eth1/21 (Primary) and Cisco ASA (Primary)is connected on PA eth1/22. Same as Cisco ASR2(secondary) is connected on ethernet1/23 and Cisco ASA(secondary) is connected via Ethern

...

Joshan_Lakhani_0-1595447238139.png

Overlapping Proxy ID"s

I have a IPSEC site to site VPN with a Check Point firewall.  In the Palo Alto I have networks / proxy ID's that overlap each other?  Can this cause issues?

 

For example I have:

 

Local                                                   Remote

192.168.50.

...

DMZ server is not accessable by Global protect

Hello,

 

I have one server belongs from the DMZ zone.
Example:-
server ip- 2.2.2.2
source ip for VPN user - 1.1.1.1
VPN zone
DMZ zone

There is 2 scenerio:-
policy(1) - I have created a policy like:-
sourcezone- VPNzone
source ip - 1.1.1.1
destination zone - DMZ

...

Global Protect in Linux error

Hi,

 

We are trying to connect to our VPN using Global Protect client in a Fedora laptop. We have tested the following articles: https://docs.paloaltonetworks.com/globalprotect/4-1/globalprotect-app-user-guide/globalprotect-app-for-linux.html#


but we ar

...

BigPalo by L4 Transporter
  • 10590 Views
  • 6 replies
  • 0 Likes

Best way to load balance to ISP with Global Protect

We have an active/passive 3020 and in from of them we have an A10 Load balancers. We want to change our current configuration so we can have a load balance between our two ISPs.

 

What is the best practice regarding the Palo Alto? Which would it be the

...

JUrenaG by L1 Bithead
  • 8540 Views
  • 7 replies
  • 0 Likes

Is windows VPN client and split tunnel supported?

Dear community,

 

I configured Windows 10 vpn client to connect to the globalprotect gateway and it works fine, the only thing that it´s not working is split tunneling.

 

Cannot see the Access Route For Third Party Client on the gateway like this example

...

Carracido by L3 Networker
  • 3284 Views
  • 3 replies
  • 0 Likes

CDL - Disconnect from log server

Has anyone else experienced many more "Disconnected from Log collector Server" alerts since the CDL Migration to GCP? I used to get one every now and then but since the change, it's increased dramatically.  Every time I check, the firewalls are loggi

...

MikeC by L3 Networker
  • 3105 Views
  • 2 replies
  • 0 Likes

internet ipv6 to on-premise ipv4 nat

Hi all,

 

there is a domain abc.com and there is an ipv6 dns record for that.so when using ipv6 from cloud is it possible to destination nat this to the ipv4 server inside.

 

I know as a workaround we can add an ipv6 ip to that server but it is not possi

...

PanIst by L3 Networker
  • 3479 Views
  • 3 replies
  • 0 Likes
  • 24223 Posts
  • 117 Subscriptions
Top Liked Authors
Labels