General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

SSL VPN USERS LIMIT

Hi Team, May I know, what users limit in Palo Alto PA-220, Currently VPN connection is maximum 21 (from 10.0.0.100 – 10.0.0.120). But now, users request need more SSL VPN users. What need to do is buy a license or what.? Thanks

application override VS service

I have new application.I need to know what is the difference between application override policy and the security policy by using the service port number both are stateful inspection firewall at Layer-4? Service:Allows you to select a Layer 4 (TCP or UDP) port for the application. You can choose any, specify a port, or use application-default to...

Application Override Video & Voice

We have Palo Alto firewalls, version 8.1.x. We heavily use Webex (application and physical boards), Jabber, and MS Teams both in the Corporate office and by GlobalProtect VPN users. I'm considering using Application Override for many of these Voice and Video applications, especially I see a large amount of cisco-spark-audio-video App-ID traffic ...

How to physical link down when rollback

Hi, I am using the 5.x version of paloalto.HA is Actvie(FW1) - Passive(FW2) configuration and use link group.For example, failover occurs when the wan link goes down. (FW2 / Actvie)When the wan link is up rollback.(FW1/ Actvie) At that time, the entire physical link down fw2 was about 1 minute.I was using it this way.but I am working on changin...

Upgrade Palo Alto via Panorama

Hello, We have 100 Palo altos firewall that we would like to upgrade via Panorama to 9.0.7, I am trying to create a group based on the prisority of upgrade to push the device>deployment >software package. Is there a way from Panorama 9.0.7 to create a groups a populate the firewall we want to upgrade? instead of selecting each one individu...

Hani2903 by L0 Member
  • 2796 Views
  • 2 replies
  • 0 Likes

Paloalto home lab

Hi community,I want to create Palo alto home lab i have PA installed to VMware workstation on laptop. now I want to connect one interface of Palo alto to wifi and one interface to my local laptop on which Palo alto image is running so I can filter Traffic going towards internet.

Refund request for VM-Series Next-Generation Firewall Bundle 1 (sold by Palo Alto Networks Inc.)

I have used VM-Series Next-Generation Firewall Bundle 1 (sold by Palo Alto Networks Inc.) in AWS for learning purpose . But its charged me $320 that I can't afford. amount automatically deducted. I contacted with AWS and they waived off their billing part. But, they suggested to get in touch with Palo Alto so that PA can approve and send the for...

PMANDAL by L0 Member
  • 2640 Views
  • 2 replies
  • 0 Likes

Resolved! AAA Server Limit

Hi all, Do we have a similar limitation with Palo Alto Networks? If so, where can I find this information? Increased limits for AAA server groups and servers per group.9.13(1)You can configure more AAA server groups. In single context mode, you can configure 200 AAA server groups (the former limit was 100). In multiple context mode, you can conf...

Resolved! Using LDAP groups with GlobalProtect

What's the magic incantation needed to use LDAP groups in the GlobalProtect Portal user/group list? Instead of listing all umpteen dozen individual users. I have a working GP Portal and multiple Gateway setup, using LDAP for authentication. I have a working Group Mapping setup using groups from LDAP. I can use "show user group list" and see al...

fjwcash by L4 Transporter
  • 9248 Views
  • 4 replies
  • 0 Likes

Virtual wire with Vlan trunking and vlan mapping

Hi all, I currently have a palo alto that is connected to my switches.The palo alto is configured as a virtual wire, and the WAN side of the palo alto is connected to VLAN 10, the LAN side is connected to VLAN11This allows me to quickly move customers in that VLAN in front of or behind the firewall by just changing their access port on the switc...

Panorama/GP questions

- Being in different versions of Panorama (9.0.4) and PaloAlto (8.1.13), is it possible to deploy GlobalProtect clients? It does not work and I wanted to confirm this information- Is it possible to publish the linux version in the global protect portal? In the panorama these versions appear but not in the nodes?

BigPalo by L4 Transporter
  • 3618 Views
  • 4 replies
  • 0 Likes

GlobalProtect Windows Client Persistent Breaks

Hi!We have on ongoing issue with Windows users trying to use the Globalprotect client (up to 5.0.3 now) resulting in up to 30% of the clients persistently breaking with a driver issue[0] which has gone on long enough that we're considering using another VPN gateway. Yes it's been raised (nearly a year ago now).Some questions :-a) Are others seei...

Does changing GlobalProtect VPN to Always On require reinstalling?

I have about a hundred users remote but they don't always need to VPN. However depending on how long WFH goes, I may need them to VPN for things like WSUS windows updates.Rather than assume everyone will follow instructions to connect to VPN (I still will), is there a way to force their connection to always connect, even if our current setup req...

  • 24419 Posts
  • 125 Subscriptions
Top Solution Authors
Labels