General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 2058 Views
  • 0 replies
  • 0 Likes

DHCP Relay with Source Nat blocked

Hi,

 

a customer has two PA VMs in the Azure cloud with internal loadbalancers configured. Unfortunately the DHCP server is also running there. In order to perform symmetric return a source nat is needed on the firewall. However this breaks the DHCP fl

...

DLP and PA-820

howdy all,

Is the PA-820 firewall capable of DLP? We have migrated from the 500 to the 800 to the 820.

Thank you

 

PA200-1 by L1 Bithead
  • 2376 Views
  • 1 replies
  • 0 Likes

Error: 'cannot start tunnel'

Hi all

my Name is Mario from Germany, i  new here, sorry for my english, i hope you can understand me.

i have a Problem with globalprotect . 

Version: 5.1.0-37
Download / Installation / Setup: ok
 
Connection error: 'cannot start tunnel'
 
i use win10 64bit
N
...

MBOTHGE by L1 Bithead
  • 5765 Views
  • 6 replies
  • 0 Likes

User-ID Verification Page for End Users

I'm wondering if anyone knows of a way, other than triggering a default URL block page, to display a User-ID association to an end user via a web page.  For example, have the user go to useridcheck.domain.local, and see a simple page that like this:

U

...

Resolved! URL Filter doesn't work in Deny rule

I have 2 rules for IT group: IT_Deny and IT_Allow as in the picture below. I'm using a same profile group for both rules, in profile group I have a URL_filter that block some websites like bbc.com, cnn.com

But when I access bbc/cnn, I get blocked by U

...

Capture.PNG
SeanBui by L1 Bithead
  • 9499 Views
  • 10 replies
  • 0 Likes

GlobalProtect 5 for IOS blocking network stack access

Just recently had a couple of instances where the GlobalProtect client was not allowing network access. ios 13.2.3 and GP 5.0.9-11

An established login to a mixed WPA home network would not connect, even though showing authenticated, no wifi bars. Sam

...

NeilR by L2 Linker
  • 4742 Views
  • 3 replies
  • 0 Likes

Need help with scripting to palo alto using ssh

Hi all!

I'm trying to creating a script for a customer i Windows Batch (*.bat) that needs to login to a Palo Alto Firewall, run a few commands and then login to another firewall and so on. 

 

This is a strict environment so no internet connection is ava

...

t.120 and Twitter-base

Hello all,

 

Looking for more information on these two applications if anyone can assist. We're deploying firewalls as an MSSP and some of the traffic we're seeing hit application-based policies doesn't seem to make sense. Some of the examples we've se

...

MathewRD by L0 Member
  • 3581 Views
  • 2 replies
  • 0 Likes

upgrade of PA-500

when in process of upgrading OS for pa-500 active/passive pair, on the passive devic i upgraded from 7.115 -- 8.0.0(download)-->8.0.20(install) -->8.1.0(download) -->8.1.12(install) 

now passive device is 2 major os version ahed , looking for ideas ho

...

Ritika by L0 Member
  • 2579 Views
  • 2 replies
  • 0 Likes

Resolved! Connect to Two Palo Alto VPNs

I have an employee who travels often with a need to simultaneously connect to two Global Protect VPNs, neither of which are clientless VPNs.

The first connection is to the main office.

The second connection is to another company, which has whitelisted

...

SSL VPN REDUNDANCY

Hello everyone,

 

I want to make redundancy ssl vpn for two ISP.I have two ISP.I will use DNS failover.And write nat rule for two publıc to loopback interface.(I use loopback interface for globalprotect).I write symmetric return for two external interf

...

  • 24230 Posts
  • 117 Subscriptions
Top Solution Authors
Top Liked Authors
Labels