General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 248 Views
  • 0 replies
  • 1 Likes

t.120 and Twitter-base

Hello all,

 

Looking for more information on these two applications if anyone can assist. We're deploying firewalls as an MSSP and some of the traffic we're seeing hit application-based policies doesn't seem to make sense. Some of the examples we've se

...

MathewRD by L0 Member
  • 2905 Views
  • 2 replies
  • 0 Likes

upgrade of PA-500

when in process of upgrading OS for pa-500 active/passive pair, on the passive devic i upgraded from 7.115 -- 8.0.0(download)-->8.0.20(install) -->8.1.0(download) -->8.1.12(install) 

now passive device is 2 major os version ahed , looking for ideas ho

...

Ritika by L0 Member
  • 2138 Views
  • 2 replies
  • 0 Likes

Resolved! Connect to Two Palo Alto VPNs

I have an employee who travels often with a need to simultaneously connect to two Global Protect VPNs, neither of which are clientless VPNs.

The first connection is to the main office.

The second connection is to another company, which has whitelisted

...

SSL VPN REDUNDANCY

Hello everyone,

 

I want to make redundancy ssl vpn for two ISP.I have two ISP.I will use DNS failover.And write nat rule for two publıc to loopback interface.(I use loopback interface for globalprotect).I write symmetric return for two external interf

...

Resolved! HA Active/Active Mode with Multi VSYS

Hi All,

 

Is it possible to use a Multi-VSYS Palo Alto to have the active-primary on one Palo Alto and a second VSYS Active-Primary on the second Palo Alto in Active-Active HA mode. I've done this on Cisco Active-Active firewalls but I need to do this

...

a.jones by L3 Networker
  • 14619 Views
  • 18 replies
  • 0 Likes

Palo Alto URL Filtering Test Pages unreachable via HTTP

Anyone else notice that the Palo Alto URL filtering test pages (example: http://urlfiltering.paloaltonetworks.com/test-command-and-control) are no longer reachable using http?

 

This article describes the pages and why you would want to use them to val

...

PeteS by L1 Bithead
  • 3272 Views
  • 3 replies
  • 0 Likes

Resolved! BGP Communities in Palo Alto Firewall

Hi,

 

It's possible to use well-known communities in Palo Alto like in Cisco Router? I mean, community no-export, no-advertise, local-as or Internet.

 

We need to propagate some routes to a peer but indicate to that peer that don't propagate outside the

...

nanukanu by L2 Linker
  • 15468 Views
  • 6 replies
  • 0 Likes

Want to allow SFTP only and not SSH Traffic

Hi Team,

 

I am trying to achieve my requirement however, unable to achieve it. Please review my requirement below and suggest your thoughts if there are any possible way to accomplish.

 

I want to block SSH traffic and at the same time i need to allow S

...

SahulH by L3 Networker
  • 13699 Views
  • 5 replies
  • 0 Likes

Rename Panorama template and template stack

Hello,

 

We have a few firewall clusters managed by Panorama and are looking to change the naming schema for templates and template stacks. Does anyone know if changing these would have any affect on firewall operations? We previously changed the zone

...

URL Filtering Whitelist

Hi,

 

We have a case that 1 user would like to access URL (example a.com) that is currently blocked in existing URL filtering profile.

 

We know we can allow this by

 

1. clone existing URL profile and add a.com into allow list or add it through custom URL

...

L1_ENG by L1 Bithead
  • 4817 Views
  • 4 replies
  • 0 Likes

Resolved! DNS sinkhole database view or test

We are finding that even domains configured as malware/c2 are not getting sinkholed.   I'm aware from other posts, that these are not the same database on the firewall.   

 

Why are these not persistent?  Why would you not flag on a DNS lookup that is

...

Sec101 by L4 Transporter
  • 6565 Views
  • 4 replies
  • 0 Likes

DNS proxy

Hello

In one of my subnets I'm using google 8.8.8.8 as DNS server (received via DHCP).

But only form one entry I want to provide my own FQDN and IP.

Could I use DNS proxy feature for this ? (enable DNS proxy with primary DNS server 8.8.8.8 and add stati

...

polak71 by L1 Bithead
  • 1760 Views
  • 1 replies
  • 0 Likes

NFS datastore change

Customer integrated NFS datastore with panorama to store logs.

 

Now they are planning to change old NFS data store with new NFS data store, But their concern is they want old NFS datastore logs to be retained in new NFS datastore after migration and t

...

  • 23627 Posts
  • 107 Subscriptions
Top Liked Authors
Labels