General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Hardware Problems in PA 3220

I had similar problems in 4 firewall pa 3220 in which I could not even enter maintenance mode to take it to the factory reset mode and I had to send them via RMA to the 4 firewalls for their change. Someone had a similar problem , to me a lot of attention that firewalls with very good MTBF have this type of problem if someone knows something...

Resolved! How can I allow an application on default and a non-standard port?

I have a Security rule that allows Oracle traffic between two subnets. The problem is that three Oracle servers use standard port 1521, and another Oracle Server uses a non-standard port 13062. I know that I need to allow the non-standard port in the rule, but that breaks traffic on the standard port. For now, I have explicitly added the stan...

kcampion by L1 Bithead
  • 6932 Views
  • 4 replies
  • 0 Likes

URL 9.0 URL Category Cache Build Time?

How long does it take for the URL categories to build in the 9.0 release? We have an issue with google-base app, where almost all google searches come back as the 'not-resolved' category for the first 5 minutes when we change datacenters. 8.1 you could just re-download the seed database, and we never had a problem. 9.0 there isn't such a...

Sec101 by L4 Transporter
  • 3462 Views
  • 2 replies
  • 0 Likes

Resolved! Shadow Rule Notice - Really Not a Shadow

I have a firewall (lab unit) with version 9.1 and I configured two Security Policy Rules.The top rule (1) is Trust to Untrust, a source user is a group, all default options, and an Action of Deny.The second rule (2) is Trust to Untrust, a source user is a group (different from above), all default options, and an Action of Allow. When I commit th...

Migrate pa vm to pa 820 facing issues

Hi to all,one of our customer migrated their complete infrastructure from PA VM to PA 820 physical device.post migration they are facing issues like, they have generated report and seeing PA 820 and PA VM as well. but here thing is, customer doesn't want see PA VM. He wanted to see only PA 820 physical device. and it showing, it misses some gap...

RameshD by L0 Member
  • 2723 Views
  • 3 replies
  • 0 Likes

setting counter thresholds with snmp monitoring

Any one have a good handling on where to set dos counter thresholds for alerting via SNMP? Also trying to figure out what are the best ~50 sensors to monitor for the firewall via SNMP. pan tcp drop packet, pan flow dos pf strict ip, and pan flow dos pf icmperr look potentially interesting in my particular environment.

Resolved! Destination NAT issue or routing change

Hi All, I have had a destination nat running for months without issue. NAT: Source VPN Interface to Inside Interface: Destination Address: 192.168.90.231 Destination Translation: 10.0.8.82 Rule: Source VPN to Inside : Source IP to 192.168.90.231 It has been working for months without issue. Suddenly last night, the traffic to 192.168.90.231 star...

a.jones by L3 Networker
  • 3348 Views
  • 2 replies
  • 0 Likes

Iphone MAC won't connect Global Protect

Hello All,We have Global Protect License for mobile we upgraded recently to 5.0.8 and i see my iphones will not connect.did any one face this issue ? Works fine with windows and desktops only with iphone i face the similar issue.Any help will be much appreciated.

Possible bug in 'load config partial' command

Hello Yesterday I was setting up a new PA-220. As always I cloned template and used load config partial command to clone device-group: load config partial mode replace from-xpath /config/devices/entry[@name='localhost.localdomain']/device-group/entry[@name='SRC'] to-xpath /config/devices/entry[@name='localhost.localdomain']/device-group/entry[@n...

WildFire for the new guys

When I started using Palo Alto firewalls about a year ago, I heard the term 'wildfire', but didn't know what it was. So, for anyone else who may be new, here's wildfire in under 5 minutes:https://youtu.be/bj9Scj-QKEY

Luke_R by L2 Linker
  • 2795 Views
  • 1 replies
  • 0 Likes

DHCP Lease Time

HiWe are distributing dhcp with mac reserve on paloalto. rental period is 10 minutes. is this time too short? Does the system get tired because the time is short?

Aykut1 by L1 Bithead
  • 6715 Views
  • 4 replies
  • 0 Likes

FQDN Addresses

I need your help on this please. Is it possible to have a wildcard FQDN as a source or destination address (example *.microsoft.com) Is is possible to mix wildcard FQDN with a non wildcard FQDN in an address group (example add in *.microsoft.com with google.com in the same address group) Thanks in advance.

rockfort by L1 Bithead
  • 3211 Views
  • 2 replies
  • 0 Likes

Correlation Event logs are not showing the same values as in Summary

Hi, We have configured the firewall to forward the correlation event logs to the syslog server. We started verifying the logs in syslog server and found the logs were not matching, all are showing the same value in the syslog server "host visited know malware URL (11 time). Whereas in firewall we see random values. In Firewall:In Syslog server:P...

CSFCSLU_0-1594674922533.png
CSFCSLU_1-1594675215685.png
CSFCSLU by L0 Member
  • 3398 Views
  • 3 replies
  • 0 Likes

Dual ISPs and PBF

Hi I have 2 ISPs on my PA 3220. I need to set it up in a way so our core traffic passes through ISP1 and guest WIFi and other non-critical traffic passes through ISP2. Also I need to make ISP2 as my backup ISP if ISP1 goes down. I have read about creating 2 VRs anfd setting up PBF but not too sure how to accomplish this fully.

m_virk by L0 Member
  • 3600 Views
  • 3 replies
  • 0 Likes
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels