General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Can a NAT IP be in my DMZ subnet

So I'm working through an IP migration when I thought of this question that I don't know the answer to and can't find an answer to with my Google skills.  Is it possible to assign an IP from the DMZ subnet as a destination NAT?  For example, if my DM

...

Lcroce by L1 Bithead
  • 2245 Views
  • 5 replies
  • 0 Likes

Resolved! 2 different portal configs on a single GP portal

Hello,

 

I currently have external contractors using on-demand globalprotect to remotely connect into the network. I have a new request to enable handful of internal users to access a specific server on mobile phones remotely.

if bought a GP gateway lic

...

Source User Information from Syslog push to PA

Hi we use Aerohive AP and from there i get syslogs at my Kiwi Syslog Server. Like this one:

ah_auth: add new RT sta: MAC=xxxxxxxx, IP=10.100.100.20, hostname=xxxxx, username=xxxxxx on wifi0.7

And now i need this information in the PA because there i on

...

Resolved! NAT order in PA

Hi Experts,

 

 Can someone please assist on the NAT order considers in PA firewalls. Is it considered from top-down architecture or Twice NAT (NAT'ing both source and dest) takes precedence over source or dest NAT.

 

 

Thanks

Srinivasan

HD queries

Hi community,

 

Which partitions are used to store the PAN-OS files?

    fw> show system disk-space

 

Can unused PAN-OS files be removed from the CLI?

 

Is there a KB available with information on how these partitions work, and what they are used for?

 

Is th

...

ash83 by L2 Linker
  • 1722 Views
  • 2 replies
  • 0 Likes

Error getting VM license key values

Hi All,

 

Some knows what this error is linked to when you upload a licence on PAN-PA-VM ?

 

 

"Error getting VM license key values"

 

Those licence has been generated trought the rest API https://api.paloaltonetworks.com/api/license/activate

 

Thanks

2018-12-05 15_48_40-gdcchbifa01-c003-fw01.png

Resolved! SSL Forward Proxy Edge Browser problems

Hello,

We have a problem at one of our new locations with the Edge Browser when using SSL Forward Proxy (PA-220).

The problem is as following: When we activate the SSL Forward Proxy, the Edge browser takes very long and sometimes even disconnects when

...

grafik.png

Configure carrier data feed without dedicated router?

We are opening a new branch office and recieved notice that the carrier will not be providing a router and that it was our responsibility to perform the WAN to LAN routing.

The carrier provided a layer 3 WAN block and a Customer Useable block containi

...

App-ID export from Expedition

We use Expedition to look at logs for layer 4 rules and tell us which apps are hitting, is there a way to export that data and import it into a Tufin workflow to migrate the rule to an App-ID rule?

IanHowe by L0 Member
  • 1045 Views
  • 0 replies
  • 0 Likes

Network Activity "Report Error"

Hi all,

 

I am new to the community and I was interested in learning more about Palo Alto.

 

I wanted to ask about a Palo Alto 5250, PAN-OS 8.1.3 In the ACC section, tab "Network Activity" I do not receive information Only one "Report Error" message ap

...

Capture.PNG

Resolved! Specific Functions of each Cores in the PA

Curious to know when we run the show running resource-monitor

 

we see below output 

 

core 0 1 2 3 4 5 6 7 8 9 10 11

 

As per my understanding cires do the packet handling as common thing among all

do they also have some specfic functions also?

 

 

MP18 by Cyber Elite
  • 1349 Views
  • 2 replies
  • 0 Likes

Vwire inbetween Cisco Asr router and Nexus 9K Switch

I am having trouble with the following. 

 

Cisco ASR router with IP of 10.1.1.5 plugs into Cisco 9K switch into port eth 1/3, eth 1/3 is configured the follwoing way.

 

interface TenGigabitEthernet0/0/1
 description LAS-9K-2
 ip address 10.1.1.5
 no ip redi

...

markk96 by L3 Networker
  • 2242 Views
  • 3 replies
  • 0 Likes

Resolved! Block Skype File Transfer

Hi All,

 

We want to block skype file transfer from our users. Checking on the application-list, I can only see Skype and Skype-probe.
Here are my questions:

1. Is there a future plan to add additional skype sub-applications (skype-video-call, skype-file

...

Miner for google ASN

Hello all,

 

Has anybody created or know a way to mine the IPs published by a ASN, f.i. Google ASN?'

 

BR,

igarcia by L1 Bithead
  • 4491 Views
  • 3 replies
  • 0 Likes