General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 536 Views
  • 0 replies
  • 0 Likes

Global Protect fails after some time

GlobalProtect fails mid way after connecting, remote sessions are opened and then suddenly everything stops working. On checking route table though it seems routes get removed. We have tried installing latest version global protect version 5.0 or 5.1

...

raji_toor by L4 Transporter
  • 2114 Views
  • 1 replies
  • 0 Likes

Ipsec proxy id has exceded

We are getting error when configured ipsec tunnel and the error is that "number of entry has exceeded" in proxy id.

PA-5220

OS-9.0.5

 

For your information please find attached screenshot.

proxyid1.png

Missing Zone Assignment

I have an issue where traffic coming in one zone is not being forwarded to the right zone.  It seems the destination zone is not being assigned right when the session is setup.  It seems to be matching the predefined intrazone policy trust-trust.   H

...

eridavis by L1 Bithead
  • 2357 Views
  • 2 replies
  • 0 Likes

Resolved! GlobalProtect Connect to one of two data centers

My customer has two data centers with GP access.

What is the best way to make this a redundant setup and have the GP client prefer to access the closed DC and fail-over to the other DC, in case the preferred DC becomes unavailable?

 

Thank you for your

...

CHKlomp by L2 Linker
  • 3109 Views
  • 1 replies
  • 0 Likes

Designing Networks - Access Denied

Hi community,

 

I'm wondering if it is possible to gain access to the below live community link or is this just for Palo Alto Networks employees?

 

https://live.paloaltonetworks.com/t5/Internal-Knowledge-Base/Designing-Networks-with-Palo-Alto-Networks-Fi

...

Rasmgr GlobalProtect

Hi,

 

We are SNMP monitoring the number of users connected by GlobalProtect Gateway. Sometimes we see how the graph goes to 0 and recover the value some minutes later. No issues were reported by users connected by SSL-VPN.

 So we are investigating if th

...

Captura1snmp.JPG
Captura2snmp.JPG
BigPalo by L4 Transporter
  • 3244 Views
  • 1 replies
  • 0 Likes

App-ID Policy to Explicitly Block - Allow WiFi Calling

Hello,


I tried searching but was surprised to find no ready answers for this.. I'm trying to determine the App-ID policy to explicitly block or allow voice calling over wifi (or wifi calling) on Verizon, AT&T, etc. I can't seem to find this in App-ID'

...

REganEVO by L1 Bithead
  • 5290 Views
  • 2 replies
  • 0 Likes

Global Protect will connect then immediately disconnect

A GP issue I am dealing with at the moment is where the client will successfully connect but I cannot ping anything on my network.  It appears to immediately disconnect.  I have attached the log files if anyone may know how to help determine the caus

...

nthen by L3 Networker
  • 7377 Views
  • 8 replies
  • 0 Likes

Enabling Jumbo Frames on HA Pair

I have an active passive PA850 pair, and want to turn on jumbo frames. 

I wondering about the best order-

Can I:

do the passive unit first, and reboot

fail over and do the primary then fail back.

 

Any issues with the HA function while one unit has jumbo e

...

NeilR by L2 Linker
  • 3505 Views
  • 1 replies
  • 0 Likes

Resolved! GlobalProtect HIP check issue

 

HIP object is correctly setup.

 

We are testing the missing patches HIP check object and noticed that an VPN endpoint is showing 3 missing patches (on the HIP report).
However the machine is showing it's installed these patches already.
How does Palo de
...

  • 23904 Posts
  • 113 Subscriptions
Labels