General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

PA is dropping SYN packet with ECN and CWR

Hi Team, @reaper , @BPry 

 

Recently I have come across a scenario that palo alto was dropping TCP SYN packets which have ECN and CWR bits set. upon checking the global counter, i have seen that the drop reason was 'process owner message err, no predic

...

Resolved! Agentless User-ID - change password

Hi 2 all

 

We have working Agentless User-ID and User-Based and Group-Based Policy

Special AD-account, "pauser" have necessary permissions.

 

I found, what its login and password is configured in 

Device > User Identification > User Mapping > WMI Autentica

...

aaobuhov by L2 Linker
  • 3018 Views
  • 1 replies
  • 0 Likes

Anti-Spam list for EDL

Hello.

 

A customer would like to add smo more anti-spam features to a Palo Alto FW setup and is intersted in using EDLs in connection with publicly available anti-spam lists. Anyone knows a good and free anyti-spam list I could use for that? I've chec

...

santonic by L6 Presenter
  • 4375 Views
  • 2 replies
  • 0 Likes

Resolved! Setting up a NAT pool with a PAT address for any spillover

We migrated from Cisco ASAs to PAN-3020 devices and I'm curious whether a feature from my ASAs exists in the PAN world. On our ASAs, we could create a pool of dynamic NAT addresses that would be matched 1-for-1 with inside hosts going to the Internet

...

LorenzoM by L1 Bithead
  • 5538 Views
  • 2 replies
  • 0 Likes

Remote Access on passive node of firewall ha cluster

Hello all,

 

I am currently configuring an HA cluster (active / passive) with the following configuration:

 

Primary (active) box: PA-820
ethernet1 / 1: 1.1.1.1/29 (external interface)
ethernet1 / 2: 192.168.0.1/24 (internal interface)
MGMT: 192.168.50.251/

...

Ipsec Proxy_id configuration issue

Hi Team,

 

 I'm not able to configure two separate proxy id in PA-3020 firewall. If I configure either the tunnel goes down or one of the proxy configured second is not working. 

 

Ipsec tunnel is IKEV2 between sonicwall and PA-3020.

I'm getting error "ik

...

vpn.JPG

Conditional NAT configuration request

Can you please guide me with this scenario and configuration.
 
I have multiple VPN clients who access two servers (A and B)  in DMZ (Outside to DMZ). The server A has evolved and the new replica of the server A now lies on the inside of the Firewall i
...

Resolved! Pushing config from Template stack

We have same template name  say corp 1 and corp 2

 

then we have template stack name dept and add these two templates corp 1 and 2 to this.

 

Now if we push config from template stack to PA will it be pushed from both corp 1 and 2 ???

 

say corp1  has sysl

...

MP18 by Cyber Elite
  • 2763 Views
  • 2 replies
  • 0 Likes

Resolved! Panos 8.1.9

Hi

 

Is this a recommend version to move to, currently on 8.1.5.

 

What about 9.x is it ready ?

Resolved! No deny or drop traffic appear on Panorama

Hi All,

 

We recently add palo alto firewall to the customer as 2nd layer firewall - 2PA820 and 1 Hyper-V panorama.

 

Panorama is in panorama mode and we use it for log collector and management the firewall. 

Now, we have a weird issue that in panorama, w

...

Resolved! DHCP Server and DHCP Relay

2 interfaces with DHCP server configure (interface ip 172.16.13.1) Scope 192.168.12.2-254 and (interface ip 172.16.33.1) scope 192.168.32.2-254
2 interfaces with DHCP relay to 172.16.13.1 and 172.16.33.1
all the interfaces are on the Palo Alto firewall

...

Yevgeni by L1 Bithead
  • 6192 Views
  • 3 replies
  • 0 Likes

Wildfire submission log

I don't understand wildfire work.

I have this example that Firewall had wildfire-virus signature but was created wildfire submission log before wildfire-virus identification

why?

 

wildfire log.png
hbshin by L2 Linker
  • 4571 Views
  • 4 replies
  • 0 Likes
  • 24008 Posts
  • 102 Subscriptions
This widget could not be displayed.
Top Liked Authors
Labels