General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

TCP TimeOut caused by the PA?

We have a video app that is streaming through our Palo Alto firewall on port 80. Everyone once in a while the session fails and can only be revived by hitting refresh in the browser. I am dealing with a network manager that's convinced the PAs are Resetting the session.Before I go through the hassle of creating override policies for port 80 with...

jhickey by • L3 Networker
  • 24798 Views
  • 15 replies
  • 0 Likes

Resolved! How to configure Juniper SRX firewall services in Palo Alto 3220

root@srx# show groups junos-defaults applications application junos-ms-rpc-uuid-any-tcp term t1 protocol tcp uuid ffffffff-ffff-ffff-ffff-ffffffffffff; [edit] root@srx# show groups junos-defaults applications application junos-ms-rpc-uuid-any-udp term t1 protocol udp uuid ffffffff-ffff-ffff-ffff-ffffffffffff;Juniper SRX is haveing in-built serv...

Resolved! Query About Policies Security Rulebase Report

Hi Team, When we export a "policies security rulebase report" which shows unknown format like below, Note: Current firmware version is PAN-OS 8.1.10 when on PAN-OS 8.1.9 we could view correct values! Did anyone faced this issue? please let us know whether its because of bug? please advise us whether we need to upgrade or downgrade the PAN-OS or...

policies security rulebase.PNG

Global protect app transparent update issue

Hi Team, I have an issue, where customer is not able to update global protect app using transparent option. I'm explaining the issue in very detail to avoid confusion. User machine is installed with client version 2.3.1. During the time of deployment portal app setting was configured to upgrade "allow user to upgrade with prompt" Now global prot...

Windows, Kerberos, LDAP, RADIUS

Hi! My company is rolling out a small pile of Palo Alto firewall models and I'm trying to learn the nuances and best practices of these devices. Initial implementation and basic functionality has been pretty straightforward. Now we are trying more advanced things. My current issue is user authentication. I have a scenario that I feel must be ver...

Resolved! PAN Syslog: Verifying the device is sending to all the configured

I added an additional syslog destination on three of my PANs but I'm only seeing that traffic at an intervening PAN for two of the sources. I've used the troubleshooting methods noted here: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClqICAS - but those are only showing me one syslog destination when four are config...

palomed by • L3 Networker
  • 33968 Views
  • 8 replies
  • 0 Likes

GlobalProtect not working if laptop has no internet at boot

I have prelogon setup for globalprotect using machine certificates, so that when a laptop boots up with internet is automatically connects to globalprotect. This works perfectly fine, except for when a laptop does not have internet access. If a laptop does not have internet access, then globalprotect just errors out and does not try to reconne...

How to identify app data vs differen in traffic recieved on app data

Hi Guys, Lets say I have application SAP that allows port 8443 but looks like APP-ID is not getting matched and we are getting insufficent data followed by deny rule , question is how can we look for difference between expected application data and difference we are seeing. Just to approve application owners this is pattern we are looking for bu...

Resolved! V-Wire in VMware.

I am trying to trial V-Wire for an upcoming requirement . The final goal is to secure a number of VMware VM's on their original IP's [differing subnets ] behind a v-wire. So I have a VM100 which I have assigned 2 interfacesone to a vswitch connected to a virtual PC 192.x.x.5 other to a vswtich connected to a virtual server 192.x.x.10 there's ...

Resolved! Can PA firewalls run multiple OSPF Processes?

Replacing a Cisco ASA fw with a Palo Alto and there is 2 OSPF processes running on the ASA ( 1 & 2 ). Can I run 2 process on a Palo Alto firewall? I've had a look and tried with running seperate VR's but I cant see how I can advertise the OSPF 2 process subnets into OSPF 1. It's really simple on a router -router ospf 1rtr#redistribute ospf...

Global Protect : Authentication Profile based on source IP

Hi,I would like to accomplish the following I have an always on VPN configured to use user-id password at logon.When the user is on one of our remote sites with know public IP's I want to use only LDAP in all other situation when he is external I want RADIUS(MFA). Can I make an authentication profile and link it to source IP? Kind regards, Fre...

GOMEZZZ by • L2 Linker
  • 5807 Views
  • 4 replies
  • 0 Likes

External Dynamic List Issue OS 9.0.4

Dear Friend, I have configured external dynamic list on PAN OS 9.0.4. When I add new URL selecting IP List like http://panwdbl.appspot.com/lists/bruteforceblocker.txt it's no't adding. Given the error as follows. But if i change it's to URL List its working.But in PAN OS 7.1.14 its capable to add. please support ASAP. ThanksLakshitha. Not Wor...

Capture1.JPG
clipboard_image_0.png

Regarding application traffic passing through the PA, the mobilephone cannot be accessed, and the co

Hi support, The situation is this. After the normal traffic passes through the PA, it goes to the nginx proxy server in the DMZ. The nginx then sends the traffic to the back-end server, and finally the server sends the traffic to the nginx proxy server. The nginx then sends the traffic to the PA, and the PA is finally given to the user. Howe...

Minemeld install on Ubuntu 18.04 issue

Hi All, I have installed minemeld on Ubuntu 18.04 using Ansible Playbook. I have followed the instuctions on https://github.com/PaloAltoNetworks/minemeld-ansible#howto-on-ubuntu-1804 and rebooted the device but I get the Error Checking Credentials: Bad Gateway error. Looking at the supervisorrd.conf status I see minemeld-web in a fatal statu...

a.jones by • L3 Networker
  • 4482 Views
  • 1 replies
  • 1 Likes
  • 24463 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels