General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4477 Views
  • 0 replies
  • 0 Likes

New setup PA-VM Active/Active external routing not working on standby

I have a pair of VM 300s in active/active mode and everything is running OSPF. PA1 is primary and PA2 is standby. I noticed I was missing a bunch of traffic for anything going to the standby router. I can ping every interface on the standby sourced from the loopbacks on each router but I cannot route through the standby.The OSPF table shows both...

Capture1234.PNG

Email Link Analysis - does it look at all emails?

I am curious to know if the organization I work at gets a blast email to 500 employee's from an external B2B marketer does the wildfire analysis get performed on all 500 identical emails or does it simply do it once knowing the email and links are identical.

joecbrown by L1 Bithead
  • 10762 Views
  • 12 replies
  • 0 Likes

Resolved! Palo Alto lab in VMware Workstation

Hi guys,I need some help with configuring network in VMware Workstation and Palo Alto. I tried to build VMware lab using both Udemy and CBT Nuggets video courses:The problem is that I can't have my Palo Alto to have an access to the Internet. It doesn't matter what type of network adapter I use NAT or BRIDGE. Below are my network settings:Networ...

4kusnik by L1 Bithead
  • 24304 Views
  • 14 replies
  • 0 Likes

Panorama: cannot use in templates objects from DG

Dear Community, I have a Panorama with several firewalls in a device group under the share one.I have several templates and I cannot select any shared object from DG into any part of template configuration, for example adding an address object as an interface´s address or into the user ID´s include list. I´m using super admin account to attempt ...

Carracido by L4 Transporter
  • 2729 Views
  • 1 replies
  • 0 Likes

Pre-logon for specific user only

My requirement is that some user should use Pre-logon and other should use User-logon. Currently all users are using only user-logon mode. Is it possible to use both mode in global protect, because we have to call client certificate profile on globally for pre-logon user?If yes can you please guide me how can i archive this and Is there any dow...

gp1.png

Allow only MS Intune and Windows Update - block all internet access

HI, I am after permitting only MS Intune and Windows Update - block all internet access.I have followed the custom URL filtering as mentioned in the link below:https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRfCAK&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetailCreated the custom url filte...

kams19_0-1597318380297.png
kams19_1-1597318419497.png
kams19_3-1597318525650.png
kams19_4-1597318560001.png
kams19 by L1 Bithead
  • 14322 Views
  • 8 replies
  • 0 Likes

Resolved! disable qos

Hi, I have the below configuration for qos , and there are policies also configured . If I want to disable for sometime , Just unchecking the checkbox under Enabled will help ? Or even after un checking the traffic will fall under class 4 ? Or do I need to remove or disable all the policy ? Thanks

Capture.JPG
simsim by L4 Transporter
  • 4635 Views
  • 1 replies
  • 0 Likes

Qos question

Hi,I have traffic shaping enabled on FG and at the same time PA also.traffic flow is as below client goes through FG then PA then go to internet or wan traffic shaping policy running on fortigate , and qos policy is there on PA also Let's say if i set bandwidth for client A ON fortigate 10 Mbps and 20 Mbps on PA , Speedtest Showing 10 Mbp...

PA-DEL-1.png
simsim by L4 Transporter
  • 9304 Views
  • 13 replies
  • 0 Likes

Session created by Syn Cookie

Hello, what process and what is going on if a session (SIP) is created by "Syn Cookie" ?Is this a valid Session, does this indicate a Problem ? We configured an App-Override Policy to mitigate Problems between Phone-System and SIP ALG.We see now all Sessions are created based on Syn Cookies. René

rekuhn by L2 Linker
  • 2374 Views
  • 1 replies
  • 0 Likes

IPSec site-to-site tunnel not allowing all traffic both ways

I followed the guides to set up an IPSec site to site VPN tunnel between our main office and satellite office using static routing, but I can't access our servers through the tunnel. From the main office, I can access everything on the satellite office's subnet, but from the satellite office, the only thing I'm able to access through the tunnel ...

GlobalProtect Xauth for iPhone and Android

We have setup GlobalProtect Portal and Gateway working perfectly with SAML auth on MacBook Pro and Windows laptop. The only issue is, GlobalProtect Mobile app is not available in our app stores. So I'm looking for setting up IPSEC Xauth on PAN so that mobile could connect to IPSEC as well. How to set it up? I've tried to use the current Gate...

ZhenGuo by L1 Bithead
  • 4469 Views
  • 1 replies
  • 0 Likes

Resolved! Implementing SSL Forward Proxy

I have a problem!!, I'm implementing SSL Forward Proxy, all the guides say I have to install the certificate in all the clients, isn't there an alternative to this? I have a lot of visitors and I shouldn't have to install a certificate.I used to have pfSense and this made it transparent. PanOS 9.1

Need Help deleting files on PAN /dev/sda8 and /dev/root

Hi All,Need help on how to free up spaces on the below partitions on my PAN device, support cannot seem to figure this out. Please help.. Filesystem Size Used Avail Use% Mounted on/dev/root 4.0G 3.4G 407M 90% /none 4.0G 56K 4.0G 1% /dev/dev/sda5 24G 16G 7.3G 68% /opt/pancfg/dev/sda6 4.0G 1.3G 2.6G 34% /opt/panrepotmpfs 4.0G 110M 3.8G 3% /dev/shm...

sokonta by L2 Linker
  • 7062 Views
  • 1 replies
  • 0 Likes

install PanHandler on Windows 10 system.

Published install instructions for PanHandler are for MAC and Linux systems. I run Windows. Here is how I installed PanHandler on my Windows 10 system. Install Docker for Windows from the Docker Hub -- https://docs.docker.com/docker-for-windows/install/ I’m at Docker Engine v19.3.5 Once Docker is installed and after your system has reboote...

  • 24379 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels