General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Vwire connection between edge and distribution switch

We have stack of 2 edge switch and stack of 2 distribution switches.We have linkagg containing 2 ports running between them.IT is layer 2 connection only between edge and distro.Also we have MAnagement vlan on switch so that users can access it remotely Need to put PA in vwire mode.So for vwire I will have two pair of vwires and i will need to h...

vwire.png
MP18 by Cyber Elite
  • 4452 Views
  • 4 replies
  • 0 Likes

Not able to normalize UPN name retrieved from SAML assertion

Hi Team, We have configured SAML SSO authentication for Global protect. Microsoft Azure has the active directory we have configured it as identity provider and service provider as Palo alto global protect. Trust established between Idp and SP and we are able to authenticate portal using microsoft azure. But the problem in allowing list in authe...

Restrict GlobalProtect connection from a single Linux computer

Hi everyone, I must to implement some VPN access control based on computers. By this way, a user will only be able to connect to VPN if agent is executed from a specific computer. I have read the documentation but I don't find if I can restrict the computer from where a user connects to VPN. All VPN clients are Linux and the control can be based...

Resolved! "Wrong" IP netmask object definition

Hi,I am a new bee in PA. Can any answer very basic question.I have seen IP Netmask object defined with non-zero host portion and mask smaller then /32 in some firewall configurations..Like this: 192.168.1.1/24 . How does this work. Is that host object 192.168.1.1 or network object 192.168.1.0/24 . RegardsRoman

mikesr by L0 Member
  • 4564 Views
  • 3 replies
  • 0 Likes

Https traffic to http

Hi Guys, I have a webserver hosted for public access using http. Now I want to know is it possible to NAT traffic entering to palo alto as https from outside to http as inside. So user will try to connect server using public IP on port 443 their port would get transalated to port 80 and go to internal destination server using destination NAT. IN...

User-ID in multiple vsys failing for vsys2

Both vsys1 and vsys2 are using same agentless settings and are accessing same DC servers. While vsys1 shows as connected vsys2 shows nothing under status and system logs show 'connect-server-monitor-failure'. I have rechecked password in both vsys but that doesn't seem to be the issue. or is the issue just cosmetic in GUI. Server: dc(vsys: vsys2...

raji_toor by L4 Transporter
  • 3232 Views
  • 1 replies
  • 0 Likes

Resolved! What traffic will be generated when select "Collector Group communication" on ethernet1/1 on panoram

Hello Everyone, I deploy two VM Panoramas for ha, and checked the setting "Enable log redancy across collectors" under Collector Group. Because of the both two log-colllector can copy logs each other, so I would like to separate function "Collector Group communication" to ethernet1/1, and use a cablle to connect directly for two vm panorama. My ...

Cisco Policy Based VPN - ProxyID Query

Hi everyone, I am receiving the below error on a Palo to Cisco policy-based VPN. 'IKE phase-2 negotiation failed when processing proxy ID. cannot find matching phase-2 tunnel for received proxy ID. received local id: 10.45.33.253/32 type IPv4_address protocol 0 port 0, received remote id: 10.104.58.0/24 type IPv4_subnet protocol 0 port 0.' Does ...

baz00r by L0 Member
  • 2953 Views
  • 2 replies
  • 0 Likes

Resolved! Security Policy destination and/or URL category clarification

Hello, can someone please tell me the best way to implement minemeld custom IP and URL blacklists? We have just built a minemeld server and have both a list of IPs and URLs. Currently have just one OUT rule like below but should we have 2 - 1 for IP destination and 1 for ANY destination but for particular URL category? We are unsure if the URL c...

michelle79_0-1575864515370.png

Generating SSL Decryption Forward Trust Cert for an HA Pair via Panorama?

I've successfully rolled out SSL Decryption on a bunch of non-HA firewalls via Panorama. Generating the .CSR, signing it with my CA, and then importing the .CER but I'm wondering if this is going to work with my HA Pair because I'm guessing that I'll have to have two different certs because there's two different physical boxes. Has anyone done t...

Resolved! Force Template Values

Hi If someone overrides a setting locally on firewall, can this be further overidden by Panorama using force template values? ... and is that instance what happens to the green and orange cogs? Thank you

nawaza by L2 Linker
  • 8806 Views
  • 2 replies
  • 0 Likes
  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels