General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Global Protect showing "Connecting" and "Still Working"

I have been stuck at this thing for days . Have even tried reinstalling the application , but still it is stuck at "Still Working" and connecting. Just a heads up, No prompt is showing in security&privacy for allowing the application.Have tried "spctl kext-consent add PXPZ95SK77" in recovery mode and restarted mac . Still issue persists.In P...

Object Group with exclusions

Checkpoint has option to creat an address group object with exclusion (e.g Include 10.20.x.x/16 and exclude 10.20.30.0/24 or other subnets from supernet). Is similar option available in Palo Alto.Negate option in PA is just to negate all source/destination.

Resolved! Ping to internet from 2nd interface IP is not working"

I have 2 outside interfaces configured with the below IP’s. When I try to ping 4.2.2.2 using source as 94.56.143.XX interface 1/1 , ping is successful ( Untrust Zone ) But if I try ping to 4.2.2.2 & using source as 94.56.202.XXX interface 1/2, ping is unsuccessful. ( HE Zone )When I try from HE zone , it should go through HE zone but it is g...

Veeam file transfer issue

Hi,Can someone help me ? Does anyone here experience when you are transferring huge files. It suddenly drop the traffic and cuts the tcp sessions. Got this veeam error from my colleague.Error: The specified network name is no longer available. Failed to write data to the file [\\172.18.77.54\Primary Backup\NOES0003-EM-09062020 - NOES0003\NOES000...

Layer 2 Setup no network traffic no MAC addresses

My organization recently purchased a VM firewall. Originally there were a couple other people who were going to implement it but it's now fallen on my shoulders. I found this tutorial that was straight-forward enough for me to follow but after adding a couple VMs to the port groups I am not seeing any MAC addresses when running "show mac all"...

vCenter Server Appliance Web user interface HTTPS Security Rule

Hi All, Due to a number of system administrators working from home, I have been asked to allow vCenter Server Appliance Web user interface HTTPS port 5480 through the firewall for administration over VPN (Global Protect). Specifically port 5480. vCenter uses standard ports 80 and 443 and successfully navigates to the site. I have been unable to ...

ccarter by • L1 Bithead
  • 16512 Views
  • 1 replies
  • 0 Likes

Downtime when chaging DNS IP

Hello - I need to change IP of the DNS server under Setup - Services on our Panorama, FWs and Global Protect devices. Would like to know what kind of downtime I can expect with the cutover to the new IPs especially on t he FWs and VPNs. - Jisha

JJoseph by • L1 Bithead
  • 2951 Views
  • 1 replies
  • 0 Likes

Are You Ready for PAN-OS 10.0 and the ML-Powered Next-Generation Firewall?

In case anyone hasn't heard that the NEW version of PAN-OS 10.0 is going to be released soon, This will be a new ML-Based NGFW (Machine Learning) and there is going to be a huge launch event for it. Palo Alto Networks is beyond excited to announce the world's first ML-Powered Next-Generation Firewall. REGISTER NOW for the PAN-OS 10.0 launch ev...

jdelio by • L7 Applicator
  • 11573 Views
  • 2 replies
  • 3 Likes

Resolved! Warning: Disabled applications in vsys1

Hi, For a while when committing we would see the message below because the applications were disabled. We have since enabled all of these applications, but are still seeing the same warning. Curious if anyone else has encountered this, and whether there is a fix for it? Warning:Disabled applications in vsys1: assembla-base assembla-uploading cel...

Resolved! 500 Internal Server Error - CAPTIVE PORTAL

Dears, PA220 with interfaces as per belowethernet1/4 19 1 Local-Network vr:RT-LAN 0 172.26.57.1/25ethernet1/5 20 1 Local-Network vr:RT-LAN 0 172.26.57.129/26ethernet1/7.105 269 1 Local-Network vr:RT-LAN 105 172.26.59.1/27ethernet1/7.106 270 1 Local-Network vr:RT-LAN 106 172.26.59.97/27Captive portal already configured and we double checked every...

ScreenShot640.jpg
ScreenShot642.jpg
ScreenShot644.jpg
ScreenShot646.jpg

Using MineMeld to build a list of IP addresses from a list of domains

Our current MineMeld instance is doing a great job of handling our Office 365 requests. Now I'd like to use it to solve a different problem, but I'm not sure how to go about it. We need to allow outbound app-specific traffic to *.somedomain.com. I tried a URL category but that's not working, probably because this traffic isn't HTTPS or HTTP. I...

efritz by • L1 Bithead
  • 7899 Views
  • 4 replies
  • 0 Likes

PA 7.1.0 - IPSec SA goes into create delete loop after enabling tunnel monitor

Hi, I am facing a strange issue in IPSec connection with PA (7.1.0) and strongswan (5.6.2) where I see Paloalto starts sending CREATE_CHILD_SA rekey requests to strongswan when I enable tunnel monitor. Earlier we were using strongswan (5.3.5) and didn't have issue with tunnel monitor, but recently we upgraded strongswan to 5.6.2 and started see...

pa-logs.png

Resolved! Source NAT on a IPSec VPN tunnel due to overlapping IP space.

Folks, Our team has been tasked to work on a VPN tunnel from a customer premises to our corporate DC. The access would be unidirectional with the Customer accessing on-prem resources. The first challenge is that we have overlapping IP addresses at the customers end. Our team wants to use some NAT policies which will act like a 1:1 policy. i.e. w...

VPN tunnel.jpg
nson2139 by • L3 Networker
  • 10045 Views
  • 1 replies
  • 0 Likes

Multiple ISP

Dear Team,I have a query. One of the customers wants to load balance their Internet traffic between multiple ISPs ( they have 5 actually). Can we do that ? I know we can do for dual ISP. But will this be feasible ?

PA3250 - L2 - L3 interface communication

Hi Team! I have simple topology ( pls see at the picture). I configured eth 1/1 ( for PC2) as L2 interface, but without Security Zone. I want to ping from PC2 - default Gateway (AE1.121) and PC1. Is it possible to set up Palo Alto like this? Pls, give me details, I can't find any use cases with the similar configuration. Thank you in advance.

PA_NX.JPG
  • 24463 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels