General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 777 Views
  • 0 replies
  • 0 Likes

Panorama 8.0.2 - Buggy???

We have multiple models of FW hardware running primarliy 7.1.9 and it seems like since upgrading to Panorama 8.0.2 from Panorama 7.1.9 that it is almost painful to make changes. It seems everytime we push to devices something fails. Today specificall

...

Wald by L2 Linker
  • 2358 Views
  • 1 replies
  • 0 Likes

Shared Objects in Panorama

Is there a concept of shared objects at multiple levels in Panorama ?  For example, I can have a top level setting at the shared level which says password length is 15 characters and I want that to go to all firewalls.  What I need, is a second share

...

Cisco WLC integration problem with PA.

I have Cisco WLC 5508 , kiwi syslogd and PA.I can see snmp traps in Syslogd but only username is visible , ip address of the client is missing.Can anybody help how to parse it in Palo alto Firewall.

 

Regards,

IPSec VPN with cert authentication: RSA_verify failed

Hello community!

 

Created a VPN Palo Alto - Cisco Asa with certificates for Ikev2 gateway authentication.

 

Cannot establish the VPN. Did a debug and get the following error when the palo alto is trying to validate the ASA´s certificate

 

[PERR]: RSA_veri

...

Carracido by L3 Networker
  • 6644 Views
  • 3 replies
  • 0 Likes

session time-out need some understanding

We hare seeing some oracle session being aged-out. When i checked session info tim-out it says 120sec. But the application time-out itself is for 14400 sec . Where does this value of 120 sec come from.

 

 

Session 2071980 c2s flow: ...

raji_toor by L4 Transporter
  • 2217 Views
  • 1 replies
  • 0 Likes

mtr

 

Hi,

 

 

from the above output the second hope is the pa firewall , the loss is 98.2% , What does it mean ,
I dont have traffic shaping in firewall 
 
Thanks

Screen Shot 2019-09-12 at 10.17.31 PM.png
simsim by L4 Transporter
  • 3871 Views
  • 1 replies
  • 0 Likes

Resolved! PA-820 & LACP

Hi

Just wondering if anyone here has successfully gotten LACP to work on a PA-800 series FW (set to passive) and Cisco Switch (set as 'channel-group X mode active')?

No matter what I try (fast/slow/active/passive/1 eth/2 eth) I always get "LACP current

...

ShaiW by L4 Transporter
  • 6984 Views
  • 2 replies
  • 0 Likes

Resolved! Changing the /

We currently have one outside interface on the firewall and is connected to our Edge Router. The interface has the IP address of 10.10.10.10.5/24 (for example). This is the only port available for inbound and outbound data to the internet. We would l

...

Shawverr by L3 Networker
  • 3971 Views
  • 5 replies
  • 0 Likes

GP RDP and User-id

Hi

 

I recently upgrade to GP client 5.x.

 

now when i login into my laptop say 10.10.10.10 as alex.samad GP logs me in as well and the PA's know 10.10.10.10 as alex.samad

 

when i rdp to 20.20.20.20. and login as peter pan.. the PA assign peter pan to 10.

...

User-ID LDAP syntax in rule

In the group mapping UserID template, we use LDAP syntax (CN=...., OU=...), but in rules, I have always seen Source User expressed  in lanman syntax, Domain\User or ...\Group.  Is it possible to use the LDAP syntax in the rule as well, and is there a

...

BoDollis by L1 Bithead
  • 3047 Views
  • 2 replies
  • 0 Likes

Resolved! Need to understand session time-outs

We hare seeing some oracle session being aged-out. When i checked session info tim-out it says 120sec. But the application time-out itself is for 14400 sec . Where does this value of 120 sec come from.

 

 

Session 2071980 c2s flow: ...

raji_toor by L4 Transporter
  • 5406 Views
  • 3 replies
  • 0 Likes
  • 23985 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Authors
Labels