General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

How to create policy between vsys.

Hello Team,New to palo alto..and need one help. Below is my topology.I want 10.1.1.0/24(vsys1) to communicate to 10.2.2.0/24(vsys2) and the route is via L3 device.What should be my policy here? Shall i create below policySource Zone-Zone ASource IP-10.1.1.0/24destination Zone- InsideDestination IP-10.2.2.0/24Service -AnyAllow And one more fromSo...

topology.png

User grouping firewall policies for all firewalls

Hi all,I like to ask if it is possible, and and hot to build a scalable solution for AD grouping info to all firewalls managed by panaroma so that they can create firewall rules based on user id and grouping. Current environment I am testing:1 panorama1 VM firewall configured as standalone master device in a device group. It queries AD, look in...

Resolved! Deny Facebook Posting

I've been playing around with trying to block Facebook posting but allow all other access to Facebook. I setup a deny rule for the 'facebook-posting' app and then setup a rule below it allowing 'facebook' but, this doesn't seem to stop posting. The logs don't show any traffic for 'facebook-posting' so wondered whether this will only work with SS...

Ash2k by L2 Linker
  • 7241 Views
  • 3 replies
  • 0 Likes

Resolved! Access is denied. EDU-110 why?

Hi, I am new to Paloalto network. I really like EDU-110 training which give a great opportunities for people to learn about Paloalto firewall.I don't understand why I got a "403 - Forbidden: Access is denied." when I tried to access EDU-110. I was 70% there .. some day work and some day don't ? Any idea? Thank you

External/Untrust IP's showing up as Internal/Trust

I am at a complete loss as to what I am seeing. I have PA-3250's running 9.1.2 code in L3 mode. The interfaces are split up into 2 aggregated ethernet interfaces, each using subinterfaces (ae1.706, ae1.707, ae2.699, ae2.698, etc.) When looking at traffic logs I see my interfaces assigned to ae1.706 and ae1.707 sourcing traffic from my trust zone...

lost access to the GUI after installed a certificate

I have installed a certificate that was working fine with my firewall, but suddenly I lost access to the GUI of the firewall.I tried what is mentioned here in the link below with no luck.https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cli0CAC

Resolved! wildcard certificate for log forwarding app

Hi All, We are doing a POC for prisma access, customer wants to test log forwarding app and since they have wildcard certificate they want to use it.Can we use wildcard certificate for log forwarding app and is there any limitation/caveats in using wildcard certificates.

HA1 showing down

HA1 is showing down, but HA1 Backup and HA2 are showing up. FWs recently configured by contractor who has left. Configuration appears correct. Any suggestions?

Resolved! How do I add disk space to Panorama?

We have had Panorama running but we want to add disk space to it. We have added the disk space to the VM but how do I actually get Panorama to recognize it? version 4.1.6

JeffTQT by L2 Linker
  • 5720 Views
  • 3 replies
  • 0 Likes

suspend both firewall

What would happen if you suspended both of your firewall in an active/passive HA configuration? Starting with suspending the passive firewall first and then the primary firewall.

jdprovine by L4 Transporter
  • 10296 Views
  • 9 replies
  • 0 Likes

PR_END-OF_FILE_ERROR in firefox

I am having trouble with https://support.microsoft.com in firefox and getting this message. It works fine in chrome though, After i disable decryption for it, it works fine in firefox as well. Why it is breaking in one browser with decryption enabled. Maybe there are other sites as well that i yet don't know are breaking as well for same reason.

image.png
raji_toor by L4 Transporter
  • 4643 Views
  • 2 replies
  • 0 Likes

GlobalProtect Pre-Logon NULL issue

Trying to setup new config for pre-logon, seems to be not working. I am getting machine certificate null error. First i was using internal PKI but then i found this KB and i was hitting the same issue.https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClR8CAKI then tried to setup with self generated certs, while i have ask...

image.png
image.png
image.png
image.png
raji_toor by L4 Transporter
  • 13346 Views
  • 12 replies
  • 0 Likes

Resolved! Site to site tunnel routing issue

I have 2 ISP. My site to site VPN is configured at on 1/10 (ISP A).I want to move my all vpn to other isp1/9(ISPB). Once i change is interface from ike gateway and add the virtual route toward (ISP B) tunnel is up but traffic is not passing through tunnel.when i ping from my PC toward destination ip traffic is still passing via (ISP A). When i ...

  • 24379 Posts
  • 123 Subscriptions
Top Solution Authors
Top Liked Authors
Labels