General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Not Blocking EICAR June/2020

PA220, running 8281-6129 If I go to https://www.eicar.org/?page_id=3950 and try download test files using http, the firewall is not blocking of the download. If I go to the old site, http://2016.eicar.org/85-0-Download.html , the firewall will block it.

Migration of PAFW PA-5050 8.0.12 to PA-5220 Latest version

Hi,I have planning to migrate PA-5050 HA version 8.0.12 to PA-5220-HA to latest version. Constrains - The new PA-5220 cannot be downgraded to 8.0.12 to migrate the configuratoin. PA-5050 are in production so can't be upgraded to suitable version of PA-5220. Additional requirement - PA-5050 cfg has each interface for inside and ouside. New PA-...

DHCP option 43

Hello, Can we use Option 43 without Vendor Class Identifier, In GUI without VCI I can't select ok. If client doesn't use option 60 with DHCPREQUEST then what we do ? Matt

Mathew42 by L1 Bithead
  • 7778 Views
  • 4 replies
  • 0 Likes

destination nat from Mikrotik router to Palo ato

hello i am about to transfer from Mikrotik router to palo alto i have one issue i don't know how to do it in palo alto i have some servers with privet IP address and ports (web-server and database server) and these servers need to be accessible from our public IP address so what i do in Mikrotik router just add destination NAT its contain the se...

JALAL79 by L0 Member
  • 4374 Views
  • 2 replies
  • 0 Likes

Both LACP interface ethernet1/2 moved out of AE-group

We've a PA-3050 up and running for over a year now. It is configured with an agregated interface with LACP enabled (mode active, transmission rate Fast). These interfaces are attacheced to a procurve 5406 where the interfaces on the procurve are configured as a trunk of the type lacp. This was running fine till now. Last 3 days the connection on...

Sjoerd by L2 Linker
  • 30645 Views
  • 19 replies
  • 1 Likes

BGP RIB out and Local RIB

Can someone explain me the difference between RIB out tab and Local RIB in BGP. What is contained in RIB out and Local RIb?Also what is pupose of Import and Export tab in BGP Appreciate your help. -Rajaram.

Firewall Monitoring - Availability and hardware utilization

Hi There, I need to monitor the firewalls, actually are 2 Ingress, 2 Egress, 1 Management and 1 panorama in 5 different environments, (dev, no prod, and so on) If you google "custom pan os metrics published for monitoring" the first link has the step-by-step to monitoring using Application Insights that has some charges after 5 Gb, however, I d ...

laelijr by L0 Member
  • 4293 Views
  • 2 replies
  • 0 Likes

DFA in PA

As a result of the covid, many clients with GP are asking me about the possibilities for implementation DFA with Palo Alto GP. I was checking about client certificate config in GP but i think this is not very safe at all.What recommendation/DFA do you have?

BigPalo by L4 Transporter
  • 2437 Views
  • 1 replies
  • 0 Likes

Resolved! Route to ISP connected to other VR

Hi all. I have the this situation:- router VR1 has LAN network 10.0.0.0/16 (zone LAN1) and ISP network X.X.X.128/27 (Zone WAN)- router VR2 has LAN network and 10.0.0.0/8 (zone LAN2)- Users in both LAN segments need to access internet I made a static route from VR2 to VR1 like this:- name: default- destination: 0.0.0.0/0- next hop: type = next-vr...

Resolved! Can't get a route

I have new Palos that I didn't set up myself. I created the interfaces and added OSPF. Network team says they can't get a route for a network. Tried everything I know. Suggestions?

Resolved! Panorama Config Report(s)

Hello, I know this information can be gathered via the 'Configuration Log' but is there a report I can build (I can't seem to find) that I can schedule daily or weekly reports to show edits to the configuration(s) made from Panorama? Thanks.

COlson by L2 Linker
  • 3584 Views
  • 2 replies
  • 0 Likes

Session Timeout Issue - Tunnel Active but User ID Authentication removes

Dear Team, We are facing an issue in VPN where in Authentication of users is removed frequently at a random time. IMPACT : We have created Source User base policy - Hence once a user session is timed out, browsing of the user is impacted. User needs to relogin and then can access Internet Traffic. However Tunnel is always active and only "User A...

Captive Portal + Global Protect

Hi team, How to make work the Palo Alto Captive portal after users logged in to Global protect. ?Users who got connected to GP should get captive portal auth page while they try to use internet.Is there any way to achieve this ?

Microsoft Edge is blocked.

Hi everyone! I have such kind of problem, maybe some of you have faced this.I've blocked Chrome, Firefox and Opera, but it also blocked Microsoft Edge, which should work.I tested deleting this application filters, which I created and found that the problem was with Chrome app filter.I have shared it here. What can cause a problem?

blocking.jpg
  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels