General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 193 Views
  • 0 replies
  • 0 Likes

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 875 Views
  • 0 replies
  • 0 Likes

Resolved! Unable to view Global Protect Authentication Logs

Logged into Panorama CLI and typed this is:

show log system eventid equal globalprotectportal-auth-succ

 

No logs showed up.  Also tried from the gui:

Monitor > Logs > System and filter using (eventid eq globalprotectportal-auth-succ)

 

Still nothing...is

...

Resolved! IPSEC VPN NAT issue

I have a VPN request where  peer's IP range is conflicting with one of my internal IP range. 

They are asking me if I can do a NAT on my end to resolve it but based on my experience it must be them who should do a NAT. 

please correct me if I'm wrong.

Not able to introduce "?" in log-link

Hi,

 

Im trying to configure a log-link web with the character "?" in the middle but the PA is deleting this character "?"

Do you know if there is any way to put the question mark character "?" in the URL

 

for example this:

set deviceconfig system log-lin

...

BigPalo by L4 Transporter
  • 6330 Views
  • 7 replies
  • 0 Likes

Auto switch between internal & external gateway

If I mix external and internal gateways in the same portal.

Does GlobalProtect automatically switch gateways when users work in the office or work outside?

 

In the current situation, when I use GlobalProtect in my office or office, I need to manually s

...

Policy Optimizer Additional Apps

Hi, we have Policy Optimizer enabled and looking at the data there appears to be 'seen' apps that are not actually allowed by the rule:

 

 

I'm thinking someone edited the rule (from perhaps 'any' to 'sip') but cannot confirm in the logs (rule is also s

...

spi.PNG

Understanding AppId Dependency Implications

I've run in to a few instances where I need/want to allow a specific App with a specific policy, but it has a dependency I don't want to include with the same policy. I'm wondering if I need to rethink how I arrange these rules.

 

The most recent examp

...

Resolved! SFP Compatibility PA3050

Hi

 

We have a PA3050, and we have 4 SFP like this: SFP HP X121 1G SPF LC LX 

So we would like to use 2 SFP to do a aggreagete link in PA.

 

Is this SFP compatible with PA3050?

 

thanks a lot

SFP + modules for PA 5220

Hello we have PA 5220

and we need to connect SFP+ modules.We have Finisar SFP plus module but it does not work

Can you recommendme any third party SFP+ module which is sure to work

Radmin_85 by L4 Transporter
  • 11839 Views
  • 9 replies
  • 0 Likes

Resolved! Palo Alto is not reading full URL

We have an in house mail server which have different URLs to access its web mail and administration center. We want to block administration center access from Internet. I tried using URL Filtering but Palo Alto is not reading full URL and only showin

...

Filter default route

WE have configured OSPF between a Palo Alto firewall and the CORE to which it is physically connected, within this CORE there are several VRFs that interconnect with the firewall (VRF1, VRF2, VRF3). Is there a way to filter the default route in the P

...

BigPalo by L4 Transporter
  • 2821 Views
  • 2 replies
  • 0 Likes

why policy for captive portal redirection has no hit counts

We are using MFP for port 22.

we have CP configured and also we have rule in PA to allow traffic for CP url on specific port.

But we see no hit counts on this rule

 

If i remove the rule then CP redirection does  not work?

 

Can someone please explain this

...

MP18 by Cyber Elite
  • 2958 Views
  • 4 replies
  • 0 Likes

Resolved! Restrict Amazon-Cloud-Drive-Upload

Is there any way to restrict amazon-cloud-drive-upload for certain websites? 

 

For example, say the website is www.mywebsite.com  (public IP 1.1.1.1) and has an applet that allows users to upload files.  When the user attempts to upload the files, the

...

MikeC by L3 Networker
  • 3758 Views
  • 2 replies
  • 0 Likes

Traffic showing from same zone

This is not a new setup. It was working fine before.
No change was made recently.
Firewall logs show traffic hitting the right policy, however from the same zone (NET to NET) instead of  SZ104-ITSupport to LAN.
How to fix this issue?
 
 
 

Rule.jpg
  • 24009 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Posts
Top Liked Authors
Labels