General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

OSPF with Active/Passive HA

Hi, I came across this design guide and looking at labbing this up for testing, as the design could be a good fit for our production environment, with a few tweaks. In my case, I'll be using OSPF between the firewalls and internal routers A and B. The connections to the edge routers A and B will be the provider routers, so they will be outside ...

OSPF HA.PNG
rchung54 by L2 Linker
  • 12427 Views
  • 8 replies
  • 0 Likes

Clear DF bit for VPN

We have recently migrated our site-to-site VPN so it is now running between a PA-3020 > Cisco ASA 5510. After the migration we discovered that one of our cross-site applications broke and the vendor determined it was because their application communicates in 1472 byte packets with the DF bit set. On our old VPN this was not an issue because...

Service Accounts and GP

Situation is this, a normal user logs into a PC and GP auto connects. User logs out and back in as a service account and GP does not auto login. Any ideas?

Resolved! SAML login remove lock (superuser?)

When I am logged in via SAML, I noticed that I was not able to remove other users' locks. Seems like this may be because I am not a superuser? Is there any way to make a SAML-authed user be a superuser?

Resolved! Zone Capacities per PA model

Looking to understand the maximum number of zones which can be used in a given firewall based on model. Is there a document out there which shows the maximum number of zones? Specifically these models:PA-445, PA460, PA1410, PA3420 If based on OS - I would be interested in 11.1.x

clewis1 by L3 Networker
  • 2236 Views
  • 2 replies
  • 0 Likes

VOICE Issues

I got a PA-1410 ,it has IP telephony, and their server is in the cloud. The phones have an address 10.200.x.x/24 and make the registration request through ports 5060 or 5075 to a server in the cloud with IP 148.235.12x.x through the SIP application.The phones do not register, using the initial port, no matter which of the mentioned, for the exam...

F.Pinar by L3 Networker
  • 933 Views
  • 2 replies
  • 0 Likes

Resolved! Tufin

Does anyone have experience using this in a larger environment? Multi vsys? Panorama? HA Clusters and so on. Are there better options available? Thanks in advance for your time.

After software upgrade firewall stopped to sending syslog

We upgraded PA-1410 from sofware release 11.0.2.-5 to 11.1.6-h3. The upgrade itself went well, but a few days later firewall stopped to send syslog messages. Executed tcpdump on the management port, but there is no syslog traffic at all. Checked the system resources, logrcvr servcie seems to be running. I tried to restart the service, and realiz...

Resolved! TCP MSS Physical interface settings understanding?

Hi, Can someone confirm if my Understanding for PA "Adjust the TCP MSS" is correct? Reference to this link this is how PA Firewall "Adjust the TCP MSS" value in the physical interface. In other Vendor when we configured the TCP-MSS value we usually set the "Actual bytes" Example for cisco: "ip tcp adjust-mss 1390"In PA firewall, it looks l...

Silvs13_0-1743481280686.png
Silvs13 by L0 Member
  • 3646 Views
  • 1 replies
  • 0 Likes

PA460 issues

Hi, We have two FW PA460 in HA, one active and another one passive. We have several issues related to configuration synchronization and HA: 1- Synchronization before a commit can take us up to 8 minutes. With the old FW the commit was in less than a minute and with these newer models we have gotten worse. It wouldn't affect us if it wasn't tha...

BigPalo by L4 Transporter
  • 3987 Views
  • 7 replies
  • 0 Likes

Resolved! IP Sec VPN Paloalto - Starlink

I'm testing Starlink business and having issues passing traffic over my tunnel. This remote site connects to our data center via an IPsec tunnel. I can get the tunnel up and traceroute to the remote side of the tunnel, but I'm unable to pass traffic. I have "Enable NAT Traversal" selected on my IKE Gateway. The Starlink is set to IP passthrough....

The PA-VM eval is crashing after minutes since reboot

Hello, I've created this discussion because I've downloaded PA-VM eval for ESXi [.ova] and tried to launch this using VMware workstation PRO [latest version]. I found on the LIVEcommunity some threads like so: https://live.paloaltonetworks.com/t5/general-topics/pa-vm-10-0-4-trial-gets-shutdown-after-a-minute/td-p/501973 however, once I followed...

Adam_D by L1 Bithead
  • 2952 Views
  • 6 replies
  • 0 Likes
  • 24442 Posts
  • 125 Subscriptions
Labels