General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! routing between 2 virtual router

hello,i have a setup like the image below.my goal is to allow internet throught interfaces 3 and 4 (i have a virtual router with these 2 interfaces, vr_l3) : this is workingi have an IPSEC tunnel on interface 1 (with another virtual router, vr1) to route 172.22.0.0/20 : this is workingi have a dhcp server on interface 3 if i put a route directly...

xxx.jpg

Compare the addressed issues list between 9.0.6 and 8.1.13

Hi, 9.0.6 was released on 1/27/2020 and 8.1.13 was released on 2/6/2020. While comparing addressed issues between the release notes, Many issued ids resolved in 8.1.13 are not listed in 9.0.6. Just a few examples, PAN-134678(PA-5200 Series firewalls only) Fixed an issue where the Quad Small Form-factor Pluggable (QSFP) 28 ports 21 and 22 did...

Resolved! dynamic address group in google cloud

has anyone used the dymanic address group objects in google cloud pan? is it supposed to pull all metadeta e.g. labels by itself. i am not seeing anything populated once i click the "Add March Criteria" button

josggf by L2 Linker
  • 3318 Views
  • 2 replies
  • 0 Likes

Resolved! File export issue

Hello, Whenever I export security rules or NAT rules from the firewall in PDF/CSV format, the file is not properly displayed my software version is 9.0.4example:-

clipboard_image_1.png

Resolved! Minemeld Feed Password OR api security

Hi we have used minemeld for some monthes and i figured out that i want to tighten the security even more.The question that then arose was the posibility to generate an api key or an user based authentication for my output indicators I don't know or think it matters but we run minemeld in two datacenters with mirroring and global loadbalancing.T...

m1.PNG
m2.PNG
Kimwii by L1 Bithead
  • 35915 Views
  • 15 replies
  • 2 Likes

Next-Gen VM-Series and Panorama generates "Invalid Opcode" VSCSI messages on VMware 6.0

We had an issue on our ESXi server and in looking through the logs found a large number of "Invalid Opcode" log messages related to the Panorama VM and Next Gen FW VM trying to access features of the VSCSIFs made available by VMware 6.0. These do not appear to affect the performance of either product, but it does indicate a disconnect between Pa...

kielecm by L0 Member
  • 3972 Views
  • 2 replies
  • 0 Likes

URL Access Error

Hi all,I have setup MineMeld on a VM and it seems to be working correctly but, when I setup the EDL on a PAN firewall and test it, I get a "URL access error" message on the firewallI have generated CA from Palo alto and i have created a certificate signed by this CA (with CN same of minemeld's hostename).After that, I have uploaded the certifica...

clipboard_image_0.png

Resolved! *Urgent* Global Protect.

Hi Team, We require to download the Global protect VPN client updates on our repository. So that users can direct update their existing Global Protect Client VPN software when connected to LAN network.Is there any way of downloading these updated version files from the firewall & sharing it across.

Panorama Unresponsive

Our client has noticed their Panorama VM becomes occasionally unresponsive after upgrade from 8.1.3 to 9.0.6. Has anyone experienced this issue? Is there a known bug?

Source address of PBF Monitor heartbeat ICMPs

I have a Policy Based Forwarding related question. If we have a PBF rule, with Monitoring enabled, and the "disable this rule if next-hop/monitor ip is unreachable" also enabled. So Palo Alto sends ICMPs to the monitored IP address out of the egress interface defined on the same page. However, what is the source-ip of these ICMP requests? Is it ...

*URGENT* URL Filtering

Hi folks, Is there a way to block the entire sub-domains but to allow a particular sub-domain and its related subs ?? For Ex:Domain : *.cloudinary.com/* ( Which covers *.Cloudinary.com/blog/* , *.Cloudinary.com/about/* , *.Cloudinary.com/contact/* ) To block: ( *.Cloudinary.com/about/* , *.Cloudinary.com/contact/* )To Allow: *....

Resolved! Layer 2 Palo Alto to 802.1q subinterface on Cisco ISR

I am thinking to put a small pan between an Internet connected Cisco 4331 ISR and a Meraki switch. Will the PAN just pass all the tagged frames along and will the PAN be able to process the traffic from all those VLANs/tagged frames? Or would I need to configure VLANs on the PAN? [Cisco ISR 4331]-Int Gi0/0 0/0.1 0/0.2 0/0/3------[L2 PAN]-------...

Resolved! GlobalProtect gateway client configuration failed

Hello, We are using PAN-OS 8.0.0 and GP agent version 4.0.2 We cannot set any IP address for the Gateway. If we try then it auto changes to 'None'.The output from the show global-protect-gateway gateway command shows there are two gateways.But according to the WEB GUI, there is only one. show global-protect-gateway gateway GlobalProtect Gateway:...

GW.png
Systemlog.png
Farzana by L4 Transporter
  • 8252 Views
  • 2 replies
  • 0 Likes
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels