General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 440 Views
  • 0 replies
  • 2 Likes

tunnel monitor with VPN tunnel in passive mode

Hello community,

 

Do you think if having tunnel monitor for an IPSec tunnel in passive mode makes any benefit?

 

When tunnel monitor detects tunnel down, the firewall would attempt to accelerate the recovery by negotiating new IPSec keys. If firewall in

...

Carracido by L3 Networker
  • 5727 Views
  • 4 replies
  • 0 Likes

Traffic over IPSEC slower than usual

Hello, Recently we have been facing issues where traffic over IPSEC tunnel towards AWS is very slow. when downloading a file ( over SCP) getting less than 100KB/s from a resource in AWS over ipsec tunnel.  Didn't had this issues for months but it sta

...

P2P2 links to be connected on PA220

Hello,

 

I have 2 pairs of palo alto, one pair at one site and the second is at another site, I got 2 p2p links between these two locations, I want to configure those links in faliover between these locations. How can I do this.

 

Resolved! Override Template sub-interface in a Stack

I am creating a template interface with several subinterfaces.  IP is handled by a variable.  What I am attempting to do is to override the template setting so I can add the zone in the Stack and not in the Template.  This way I can create a global z

...

template.PNG
stackBefore.PNG
stackAfter.PNG

*URGENT* Captive Portal Authentication.

Hi team,

 

Query about Captive portal Authentication.

 

One of our customer enabled the CP auth but they needs to allow particular URL's without CP auth redirect even for unknown users.

 

How to achieve this ? also please share the KB articles which is rel

...

Resolved! URGENT: Custom Application issue.

Hi peeps,

 

I have created a custom application for a particular TCP port and added that particular application in to my security policy, but traffic gets hit to deny policy. It works only when i do App override but it is not recommended to do app over

...

Resolved! Palo Alto blocks outbond cisco any connect traffic

Hi , 

 

i a new to Palo alto world. one of my user is trying to connect a VPN connection using anyconnect, but it not working when traffic is passing from palo alto, but when i access it from open internet it is working fine.

 

Prompt response will be hi

...

SachinA by L0 Member
  • 5642 Views
  • 3 replies
  • 0 Likes

Firewall not Import to Panorama

 

 Multiple Firewall are configure on Panorama. All the devices are successfully uploaded to Panorama. Now,I am making all the changes through Panorama to firewalls – which are being pushed to the firewall. But for one firewall,If made few changes to

...

Resolved! LACP not active, negotiation failed. One member is not happy

Hi All,

 

PA-3060, PAN-OS 7.1.17

 

Please see below:

 

 

LACP:

**********************************************************************************
AE group: ae1
Members: Bndl Rx state Mux state Sel state
ethernet1/17 yes Current Tx_Rx Selected
ethernet1/18 no Cur

...

ddd.JPG
myky by L3 Networker
  • 10294 Views
  • 3 replies
  • 0 Likes

DNS Application uses more DP CPU utilization

Hi,

 

We are facing issue with DNS Application, it uses more DP CPU Utilization 60 to 70%.

We have done DNS Application override but no luck.

 

Please find the DNS Session details below.

 

Mem-Pool-Type MaxSz(KB) Threshold MinSz(KB) CurSz(B) Cur.Alloc Total

...

Clear text traffic to DLP

What do you guys do to send clear text or SSL decrypted traffic over to a nDLP for further action?  In my case, the nDLP only support ICAP in order for it to accept traffic from its peering devices. Since PAN doesn't support ICAP at all and I am in s

...

rKarki by L1 Bithead
  • 2262 Views
  • 1 replies
  • 0 Likes

Resolved! cannot find matching phase-2 tunnel for received proxy ID

We have a site to site VPN setup that was allowing one IP. On the ipsec tunnel sec proxy-id allow local (10.1.2.1/32)  which was working just fine.

We had to recently allow two more IP's 10.1.2.20 and 10.1.2.75. I Changed the ipsec tunnel sec proxy-id

...

bino150 by Not applicable
  • 30435 Views
  • 7 replies
  • 1 Likes
  • 23700 Posts
  • 110 Subscriptions
Top Solution Authors
Labels