General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Palo 5220 (8.1.6h2) Throughput

AllWe are pulling data from an a remote server to a SQL server, that sits behind the Palo, using SMB and FTP. The file size is 40G.ALL links between the 2 servers are verified at 10G.The transfer rate is being measured between 75MB and 120MB., apprx (1G)We tested this same type of transfer between servers behind the Palo and the rate was approx ...

mhs_coad by L0 Member
  • 2668 Views
  • 1 replies
  • 0 Likes

Netflow export into IPsec tunnel...

I'm trying to get netflow to export through a vpn tunnel on my PA-VM V9.1 firewall. My route and policy into the tunnel for the target collector is working because I can ping the collector through the tunnel. So I figure I need to change the default service route for netflow, but I'm unable to specify any of the dataplane interfaces/addresses ei...

megrez80 by L2 Linker
  • 6347 Views
  • 5 replies
  • 0 Likes

Layer 2 to Layer 3 Connection , but on same Subnet and IP range?

We have a PaloAlto PA220 at work what is used for telephony/SIP traffic that I set up several months ago. Upstream of the PaloAlto is a unmanaged L2 netgear switch what sits between the leased internet line, the PaloAlto , and a another non-PaloAlto firewall. I want to get rid of this unmanged L2 netgear switch and connect our other non-...

eveares by L1 Bithead
  • 14675 Views
  • 11 replies
  • 0 Likes

Troubleshooting GlobalProtect disconnects

I have a couple of users that say their active connections are suddenly disconnected. What is the best way to determnine the cause of the disconnection? Again this is an active session not a time out

jdprovine by L4 Transporter
  • 9148 Views
  • 3 replies
  • 1 Likes

Resolved! ZPA Minemeld feed from json source truncated to last record

Problem Summary: Trying to locally convey - as a feed - all subnet block ranges from https://ips.zscaler.net/zpa/json - but only getting the last presented. URL Being referenced: https://ips.zscaler.net/zpa/json Example Content: {"Cloud Name":"zscaler.net","Content":[{"IP Protocol":"TCP","Port":443,"Source":"Connector, Zscaler App","Domains":"*....

SSO authentication was solved through override, cause analysis request and Similars

Hi. I have a website that I access via sso authentication, but I can't connect through the firewall. After trying various things, I solved it through the override rule in the firewall The override policy cannot be removed at this time. I wonder why this is possible with an override. Does anyone have a similar case or guess? Tell me please.

jskang by L1 Bithead
  • 2569 Views
  • 1 replies
  • 0 Likes

Resolved! Captive Portal LDAP Authentication redundancy

Hello. I have a Captive Portal that uses next Authentication Profile:CP_AuthWhere:Authentication Sequence:CP_Auth - Auth_Mode_1, Auth_Mode_2Authentication Profile:Auth_Mode_1 - LDAP_1Auth_Mode_2 - LDAP_2LDAP Server Profile:LDAP_1: 10.10.1.101, 10.10.1.102LDAP_2: 10.10.2.103, 10.10.2.104 Base on our monitor logs, we noticed that all our authentic...

JuanAn by L1 Bithead
  • 5831 Views
  • 4 replies
  • 0 Likes

Resolved! Panorama IPsec tunnel to AWS

Need to create IPSec tunnel in Panorama hosted in Google Cloud that is managing our PAN-850 in customer datacenter to our cloud environment in AWS. FYI-we dont have Palo Alto in AWS.

Resolved! unsigned LDAP

Hi,As we know Microsoft is going to disable use of unsigned LDAP port 389 in March 2020.Fortunately I don't have LDAP profile on my PA firewall but I have Kerberos. Will there be any impact ? and do I have to change it ? Thank youKonrad

Resolved! CLI command for IPSEC tunnel info

Hello friends, I am looking for cli command to see all the details related to ipsec tunnels configured on the gateway. I need information related to tunnel id, peer ip and their status. Is there any command available ? I can see details under gui but i cant see tunnel id. Please help on this. Thank you.

Joshim by L1 Bithead
  • 49901 Views
  • 4 replies
  • 0 Likes

SSL test pages of urlfiltering.paloaltonetworks.com not blocked

Hi,If we test https://urlfiltering.paloaltonetworks.com/test-grayware there is no block page however if we test http://urlfiltering.paloaltonetworks.com/test-grayware we do get a block page. I cannot find urlfiltering.paloaltonetworks.com nor *.paloaltonetworks.com in a no ssl decryption profile nor the predefined exclusion list.In the traffic l...

tomdevos by L0 Member
  • 3429 Views
  • 1 replies
  • 0 Likes

Route between Subinterfaces with two VRs

Hello, I have a network with two WAN connections, i have assigned one of them for a vlan 10 and the other for vlan 20 using two VR and NATing also i created dhcp server for both vlan and for now every thing works fine, the problem is i can't access the resources in vlan 20 from vlan 10 and vise versa, what should i do also? should i create a sta...

Untitled.png

How to remove one BGP-RIB Out

Hi, We've configured BGP between Paloalto to Azure by using EBGP. The bgp is established but in RIB Out noticed that prefix 0.0.0.0/0 advertised to the peer respective azure. How to remove this, because due to this the users in bgp unable to access the internet. If I enable the "reject default route" option does this help? or cause any problem ...

bgp azure.JPG
bgp azure.JPG
bgp azure.JPG

RADIUS Authentication Still Prompts for Password Change

I have a stand-alone system which is utilizing two Palo Alto 220 Firewalls. As part of this system, I have RADIUS policies configured on a Windows server to provide domain-admin access to the device. On one PA220 I am able to login with my domain credentials and access the device without issue. On the other PA220 I am able to login with domain c...

  • 24443 Posts
  • 125 Subscriptions
Top Solution Authors
Labels