General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

remove disk fromPAN 3220

I need the process of how to remove the hard drive from a PAN 3220 since I cannot enter maintenance mode and before doing the RMA for the firewall, I must clean the disk

Panorama: config output on CLI

Hi,I would like to backup and restore a panorama like I can with the firewall, on the firewall i set "set cli op-command-xml-output on" and get the config via the console, then bootstrap the firewall to restore the config...now i am wondering how I can do the same with panorama...it seems that i can neither set operational output to xml, nor res...

CLIq by L3 Networker
  • 13187 Views
  • 11 replies
  • 1 Likes

Resolved! PA-220 Strange IP Spoofing Behaviour

Hi,My colleague and myself are complete Palo newbies so apologies as this is probably covered elsewhere but I don't know what to search for as I've never seen a firewall do this. We bought a PA-220 for evaluation intending to possibly move away from Cisco.My colleague configured it in a basic way and the box has completely disrupted the test su...

Resolved! Navigation Permits Expire - AD Groups

I recently implemented a policy that allows certain users who belong to a group in my Active Directory to go online. It seems to work well but after a while users report not being able to browse even if the LAN connection is maintained. The funny thing is that if you reboot the PC or simply block and unblock using the AD account the permissions ...

Resolved! Connecting FW on PAN-OS 9.0.1 to Cortex Data Lake (logging Services)

I've sucesfully connected FW 8.1.x to Data lake but am having issues connecting one on 9.0.1. Both are managed by the same Panorama (PAN-OS 9.0.1). The difference is that on non-working one I have disabled Panorma Policy and Objects. But logging service setting is under template setting anyway. License seems to be ok. First error says "No cer...

santonic by L6 Presenter
  • 34772 Views
  • 3 replies
  • 1 Likes

Resolved! PANOS 9.0 DDNS PPPoE

Hi. Can anyone tell me if they have had any sucess using the DDNS feature in PAN OS v 9.0 when using a PPPoE connection.The only option I have is DHCP and this throws an error when commiting the rule base to the firewall, looking at the runtime stats there is no ip information. /M

Marc_T by L2 Linker
  • 9858 Views
  • 6 replies
  • 0 Likes

sensitive information in PA 3200

I have a firewall PA 3220 to send by RMA to Palo ALto , but first, the client wants to make sure that he has no sensitive information inside, can someone tell me if this is the case or what should be done for the return of the equipment without exposing sensitive customer information?

Help needed with pruning ikemgr.log outputs to show only interesting traffic log entries

On Palo Alto CLI the only way I know of to see the logs of VPN tunnel Phase I errors etc is this command from inside the vsys via CLI where the VPN tunnel is built: less mp-log ikemgr.log 1) Are there commands for CLI where I can show just outputs for ONLY certain tunnel information that I'm seeking from the above log command? I've tried stuff ...

Can PAN-OS 9.0 prevent user upload file size?

I want to limit the file size user can upload,for example prevent user from upload file larger than 100MB ,Less than 100MB can upload. Tried but failed.https://live.paloaltonetworks.com/t5/Management-Articles/Limiting-File-Size-Upload-using-Custom-Signature/ta-p/69156 Not sure if it is a version issue, currently it is PAN OS 9.0 and perform encr...

Houran by L0 Member
  • 3112 Views
  • 2 replies
  • 0 Likes

tunnel monitor with VPN tunnel in passive mode

Hello community, Do you think if having tunnel monitor for an IPSec tunnel in passive mode makes any benefit? When tunnel monitor detects tunnel down, the firewall would attempt to accelerate the recovery by negotiating new IPSec keys. If firewall in passive node it wouldn´t be able to initiate the negotiations from its side in order to reestabl...

Carracido by L4 Transporter
  • 7476 Views
  • 4 replies
  • 0 Likes

Traffic over IPSEC slower than usual

Hello, Recently we have been facing issues where traffic over IPSEC tunnel towards AWS is very slow. when downloading a file ( over SCP) getting less than 100KB/s from a resource in AWS over ipsec tunnel. Didn't had this issues for months but it started recently. Phase1 and 2 are established. Tunnel interface MTUs are also same. Any idea where ...

Why can't I connect to Palo Alto Firewall VM on Debian?

So I am trying to setup a connection on my Debian host to a Palo Alto Firewall VM on VirtualBox.I have four adapters: one host-only, one bridged, and two internal. I am trying to connect to the host-only adapter through my host OS's FF browser.All I am getting right now when I change my IP to same management subnet and try to connect with HTTPS ...

P2P2 links to be connected on PA220

Hello, I have 2 pairs of palo alto, one pair at one site and the second is at another site, I got 2 p2p links between these two locations, I want to configure those links in faliover between these locations. How can I do this.

  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels