General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 167 Views
  • 0 replies
  • 0 Likes

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 597 Views
  • 0 replies
  • 2 Likes

Missing Zone Assignment

I have an issue where traffic coming in one zone is not being forwarded to the right zone.  It seems the destination zone is not being assigned right when the session is setup.  It seems to be matching the predefined intrazone policy trust-trust.   H

...

eridavis by L1 Bithead
  • 2297 Views
  • 2 replies
  • 0 Likes

Resolved! GlobalProtect Connect to one of two data centers

My customer has two data centers with GP access.

What is the best way to make this a redundant setup and have the GP client prefer to access the closed DC and fail-over to the other DC, in case the preferred DC becomes unavailable?

 

Thank you for your

...

CHKlomp by L2 Linker
  • 3005 Views
  • 1 replies
  • 0 Likes

Designing Networks - Access Denied

Hi community,

 

I'm wondering if it is possible to gain access to the below live community link or is this just for Palo Alto Networks employees?

 

https://live.paloaltonetworks.com/t5/Internal-Knowledge-Base/Designing-Networks-with-Palo-Alto-Networks-Fi

...

Rasmgr GlobalProtect

Hi,

 

We are SNMP monitoring the number of users connected by GlobalProtect Gateway. Sometimes we see how the graph goes to 0 and recover the value some minutes later. No issues were reported by users connected by SSL-VPN.

 So we are investigating if th

...

Captura1snmp.JPG
Captura2snmp.JPG
BigPalo by L4 Transporter
  • 3120 Views
  • 1 replies
  • 0 Likes

App-ID Policy to Explicitly Block - Allow WiFi Calling

Hello,


I tried searching but was surprised to find no ready answers for this.. I'm trying to determine the App-ID policy to explicitly block or allow voice calling over wifi (or wifi calling) on Verizon, AT&T, etc. I can't seem to find this in App-ID'

...

REganEVO by L1 Bithead
  • 5111 Views
  • 2 replies
  • 0 Likes

Global Protect will connect then immediately disconnect

A GP issue I am dealing with at the moment is where the client will successfully connect but I cannot ping anything on my network.  It appears to immediately disconnect.  I have attached the log files if anyone may know how to help determine the caus

...

nthen by L3 Networker
  • 7001 Views
  • 8 replies
  • 0 Likes

Enabling Jumbo Frames on HA Pair

I have an active passive PA850 pair, and want to turn on jumbo frames. 

I wondering about the best order-

Can I:

do the passive unit first, and reboot

fail over and do the primary then fail back.

 

Any issues with the HA function while one unit has jumbo e

...

NeilR by L2 Linker
  • 3360 Views
  • 1 replies
  • 0 Likes

Resolved! GlobalProtect HIP check issue

 

HIP object is correctly setup.

 

We are testing the missing patches HIP check object and noticed that an VPN endpoint is showing 3 missing patches (on the HIP report).
However the machine is showing it's installed these patches already.
How does Palo de
...

Resolved! DNS Security - High Risk Sites

thumbnails.trvl-media.com used by www.hotels.com to host its images is classified as a high risk site

If this is a false positive, how do I get Palo Alto DNS Service to take a second look or find out why it's classified as high risk?

 

How are other peo

...

DMZ, inside, outside - is it simple thing?

Hi there.

 

I have a PA-200.

Internal net is 192.168.0.0/24 eth1/2 , inside L3 interface  (default gw) -  192.168.0.254

One external ip address is using for outside inteface, eth1/1.

For connection to Internet I typically use pair inside-outside with:

1. N

...

mxe2fmk by L1 Bithead
  • 7348 Views
  • 6 replies
  • 0 Likes

Unable to reach GP Portal while on internal network

Hi All,

 

I was working with a site that has a PA firewall with a GP Portal and Gateway.  Some time ago, I had an issue where my users couldn't upgrade their globalprotect version while in the office. I was able to resolve this issue by creating a No N

...

ce1028 by L4 Transporter
  • 5291 Views
  • 4 replies
  • 0 Likes
  • 23757 Posts
  • 110 Subscriptions
Top Solution Authors
Top Liked Authors
Labels