General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 778 Views
  • 0 replies
  • 0 Likes

DHCP Relay with Source Nat blocked

Hi,

 

a customer has two PA VMs in the Azure cloud with internal loadbalancers configured. Unfortunately the DHCP server is also running there. In order to perform symmetric return a source nat is needed on the firewall. However this breaks the DHCP fl

...

DLP and PA-820

howdy all,

Is the PA-820 firewall capable of DLP? We have migrated from the 500 to the 800 to the 820.

Thank you

 

PA200-1 by L1 Bithead
  • 2207 Views
  • 1 replies
  • 0 Likes

Error: 'cannot start tunnel'

Hi all

my Name is Mario from Germany, i  new here, sorry for my english, i hope you can understand me.

i have a Problem with globalprotect . 

Version: 5.1.0-37
Download / Installation / Setup: ok
 
Connection error: 'cannot start tunnel'
 
i use win10 64bit
N
...

MBOTHGE by L1 Bithead
  • 5269 Views
  • 6 replies
  • 0 Likes

User-ID Verification Page for End Users

I'm wondering if anyone knows of a way, other than triggering a default URL block page, to display a User-ID association to an end user via a web page.  For example, have the user go to useridcheck.domain.local, and see a simple page that like this:

U

...

Resolved! URL Filter doesn't work in Deny rule

I have 2 rules for IT group: IT_Deny and IT_Allow as in the picture below. I'm using a same profile group for both rules, in profile group I have a URL_filter that block some websites like bbc.com, cnn.com

But when I access bbc/cnn, I get blocked by U

...

Capture.PNG
SeanBui by L1 Bithead
  • 8525 Views
  • 10 replies
  • 0 Likes

GlobalProtect 5 for IOS blocking network stack access

Just recently had a couple of instances where the GlobalProtect client was not allowing network access. ios 13.2.3 and GP 5.0.9-11

An established login to a mixed WPA home network would not connect, even though showing authenticated, no wifi bars. Sam

...

NeilR by L2 Linker
  • 4463 Views
  • 3 replies
  • 0 Likes

Need help with scripting to palo alto using ssh

Hi all!

I'm trying to creating a script for a customer i Windows Batch (*.bat) that needs to login to a Palo Alto Firewall, run a few commands and then login to another firewall and so on. 

 

This is a strict environment so no internet connection is ava

...

t.120 and Twitter-base

Hello all,

 

Looking for more information on these two applications if anyone can assist. We're deploying firewalls as an MSSP and some of the traffic we're seeing hit application-based policies doesn't seem to make sense. Some of the examples we've se

...

MathewRD by L0 Member
  • 3199 Views
  • 2 replies
  • 0 Likes

upgrade of PA-500

when in process of upgrading OS for pa-500 active/passive pair, on the passive devic i upgraded from 7.115 -- 8.0.0(download)-->8.0.20(install) -->8.1.0(download) -->8.1.12(install) 

now passive device is 2 major os version ahed , looking for ideas ho

...

Ritika by L0 Member
  • 2327 Views
  • 2 replies
  • 0 Likes

Resolved! Connect to Two Palo Alto VPNs

I have an employee who travels often with a need to simultaneously connect to two Global Protect VPNs, neither of which are clientless VPNs.

The first connection is to the main office.

The second connection is to another company, which has whitelisted

...

  • 23986 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Authors
Labels