General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Paloalto home lab

Hi community,I want to create Palo alto home lab i have PA installed to VMware workstation on laptop. now I want to connect one interface of Palo alto to wifi and one interface to my local laptop on which Palo alto image is running so I can filter Traffic going towards internet.

Refund request for VM-Series Next-Generation Firewall Bundle 1 (sold by Palo Alto Networks Inc.)

I have used VM-Series Next-Generation Firewall Bundle 1 (sold by Palo Alto Networks Inc.) in AWS for learning purpose . But its charged me $320 that I can't afford. amount automatically deducted. I contacted with AWS and they waived off their billing part. But, they suggested to get in touch with Palo Alto so that PA can approve and send the for...

PMANDAL by L0 Member
  • 2664 Views
  • 2 replies
  • 0 Likes

Resolved! AAA Server Limit

Hi all, Do we have a similar limitation with Palo Alto Networks? If so, where can I find this information? Increased limits for AAA server groups and servers per group.9.13(1)You can configure more AAA server groups. In single context mode, you can configure 200 AAA server groups (the former limit was 100). In multiple context mode, you can conf...

Resolved! Using LDAP groups with GlobalProtect

What's the magic incantation needed to use LDAP groups in the GlobalProtect Portal user/group list? Instead of listing all umpteen dozen individual users. I have a working GP Portal and multiple Gateway setup, using LDAP for authentication. I have a working Group Mapping setup using groups from LDAP. I can use "show user group list" and see al...

fjwcash by L4 Transporter
  • 9352 Views
  • 4 replies
  • 0 Likes

Virtual wire with Vlan trunking and vlan mapping

Hi all, I currently have a palo alto that is connected to my switches.The palo alto is configured as a virtual wire, and the WAN side of the palo alto is connected to VLAN 10, the LAN side is connected to VLAN11This allows me to quickly move customers in that VLAN in front of or behind the firewall by just changing their access port on the switc...

Panorama/GP questions

- Being in different versions of Panorama (9.0.4) and PaloAlto (8.1.13), is it possible to deploy GlobalProtect clients? It does not work and I wanted to confirm this information- Is it possible to publish the linux version in the global protect portal? In the panorama these versions appear but not in the nodes?

BigPalo by L4 Transporter
  • 3663 Views
  • 4 replies
  • 0 Likes

GlobalProtect Windows Client Persistent Breaks

Hi!We have on ongoing issue with Windows users trying to use the Globalprotect client (up to 5.0.3 now) resulting in up to 30% of the clients persistently breaking with a driver issue[0] which has gone on long enough that we're considering using another VPN gateway. Yes it's been raised (nearly a year ago now).Some questions :-a) Are others seei...

Does changing GlobalProtect VPN to Always On require reinstalling?

I have about a hundred users remote but they don't always need to VPN. However depending on how long WFH goes, I may need them to VPN for things like WSUS windows updates.Rather than assume everyone will follow instructions to connect to VPN (I still will), is there a way to force their connection to always connect, even if our current setup req...

Change Global Protect Config when users are connected

Hi Guys, We have global protect deployed. Portal and Gateway are the same firewall. Now if I do any changes on the Gateway, are those changes immediately effective for the connected users as well?Is there any "profile" that is being pushed to clients/GP agent and if yes, when is it pushed? Are the changes immediately synced? Thanks!

Globalprotect: gateways or satellites?

I'd like to setup a GP environment with a single portal, but two different locations (gateways?) where clients can connect. The documentation talks of gateways and satellites. I'm uncertain of the differences and when you would choose one or the other.Can someone clarify? Thanks.

Global Protect fails after some time

GlobalProtect fails mid way after connecting, remote sessions are opened and then suddenly everything stops working. On checking route table though it seems routes get removed. We have tried installing latest version global protect version 5.0 or 5.1. Host system is Windows 10 Home edition

raji_toor by L4 Transporter
  • 2584 Views
  • 1 replies
  • 0 Likes

Ipsec proxy id has exceded

We are getting error when configured ipsec tunnel and the error is that "number of entry has exceeded" in proxy id.PA-5220OS-9.0.5 For your information please find attached screenshot.

proxyid1.png

Missing Zone Assignment

I have an issue where traffic coming in one zone is not being forwarded to the right zone. It seems the destination zone is not being assigned right when the session is setup. It seems to be matching the predefined intrazone policy trust-trust. Has anyone seen this before? 10.46.36.11 should be part of a zone called KNAPP, but it is not assi...

eridavis by L1 Bithead
  • 3029 Views
  • 2 replies
  • 0 Likes
  • 24443 Posts
  • 125 Subscriptions
Top Solution Authors
Labels