General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4128 Views
  • 0 replies
  • 0 Likes

Auto switch between internal & external gateway

If I mix external and internal gateways in the same portal.Does GlobalProtect automatically switch gateways when users work in the office or work outside? In the current situation, when I use GlobalProtect in my office or office, I need to manually switch portals.It does not automatically switch.

Resolved! Pending changes are not coming up in “Preview Changes” Tab

Hi Team, pending changes are not coming up in “Preview Changes” Tab.This is seen every time we try to commit changes and multiple Palo Alto firewalls are showing same behavior.A blank page is coming up when there should me details displayed regarding the changes made from last saved configuration state. Note:Model: PA-3050PAN-OS: 8.0.9 Does any...

123.png

Policy Optimizer Additional Apps

Hi, we have Policy Optimizer enabled and looking at the data there appears to be 'seen' apps that are not actually allowed by the rule: I'm thinking someone edited the rule (from perhaps 'any' to 'sip') but cannot confirm in the logs (rule is also set to application-default). Can anyone otherwise explain this? cheers, Simon

spi.PNG

Understanding AppId Dependency Implications

I've run in to a few instances where I need/want to allow a specific App with a specific policy, but it has a dependency I don't want to include with the same policy. I'm wondering if I need to rethink how I arrange these rules. The most recent example is actually Palo Alto Traps. There is a traps-management-service AppID. I've setup a rule for ...

PANORAMA PA Firewall Management -> entire backup of the Firewall Running Config

Hi, we are managing a pool of PA Firewalls using Panorama. Some of the settings are pushed to the managed devices via Templates (i.e. several additional users, shared objects, etc.). Device Config is saved on a regular basis on the device itself as well as on the Panorama. However what I do not understand is that, if I save and export the device...

Resolved! SFP Compatibility PA3050

Hi We have a PA3050, and we have 4 SFP like this: SFP HP X121 1G SPF LC LX So we would like to use 2 SFP to do a aggreagete link in PA. Is this SFP compatible with PA3050? thanks a lot

SFP + modules for PA 5220

Hello we have PA 5220and we need to connect SFP+ modules.We have Finisar SFP plus module but it does not workCan you recommendme any third party SFP+ module which is sure to work

Radmin_85 by L4 Transporter
  • 13563 Views
  • 9 replies
  • 0 Likes

Resolved! Palo Alto is not reading full URL

We have an in house mail server which have different URLs to access its web mail and administration center. We want to block administration center access from Internet. I tried using URL Filtering but Palo Alto is not reading full URL and only showing host name in URL Filtering logs, I have also imported the the email server ssl certificate on P...

Filter default route

WE have configured OSPF between a Palo Alto firewall and the CORE to which it is physically connected, within this CORE there are several VRFs that interconnect with the firewall (VRF1, VRF2, VRF3). Is there a way to filter the default route in the Palo Alto firewall so that it is only sent to the interface that interconnects with the VRF2 in th...

BigPalo by L4 Transporter
  • 3249 Views
  • 2 replies
  • 0 Likes

why policy for captive portal redirection has no hit counts

We are using MFP for port 22.we have CP configured and also we have rule in PA to allow traffic for CP url on specific port.But we see no hit counts on this rule If i remove the rule then CP redirection does not work? Can someone please explain this behavior?

MP18 by Cyber Elite
  • 3327 Views
  • 4 replies
  • 0 Likes

Resolved! Restrict Amazon-Cloud-Drive-Upload

Is there any way to restrict amazon-cloud-drive-upload for certain websites? For example, say the website is www.mywebsite.com (public IP 1.1.1.1) and has an applet that allows users to upload files. When the user attempts to upload the files, the firewall detects this as application "amazon-cloud-drive-upload". You can't create a firewall r...

MikeC by L3 Networker
  • 4219 Views
  • 2 replies
  • 0 Likes

Traffic showing from same zone

This is not a new setup. It was working fine before.No change was made recently.Firewall logs show traffic hitting the right policy, however from the same zone (NET to NET) instead of SZ104-ITSupport to LAN.How to fix this issue?

Rule.jpg

Resolved! [BUG] EDL using wrong Service Route

Hello everybody!PAN OS build 9.0.3-h3. According to the PAN documentation the "External Dynamic Lists" (Object-> External Dynamic Lists) )are supposed to use "External Dynamic Lists Service Route" (Device-> Setup -> Services -> 'Service Route Configuration'). This doen't seem to be the case since any changes in that area have no effe...

PA_ServiceRoute_EDL.PNG
PA_ServiceRoute_URL_Updates.PNG
PA_ExternalListsO365.PNG
husetech by L2 Linker
  • 7309 Views
  • 5 replies
  • 0 Likes

Communication performance issues between zones

HiI have a firewall configured with different zones (users, servers-prod, servers-dev). At network configuration level, 4 network interfaces are linked to 1 aggregate group and under this aggreate group, I have on subinterface linked with each secuirty zone (ae1.1 for users, ae1.2 for servers-prod, ae1.3 for servers-dev). The 4 interfaces of th...

Global protect VPN

Hi,We are using Global protect VPN. Whenever we connect the VPN with office network the system gets slow and we run any command it takes a lot of time to run.Whenever we connect the VPN with an open network the commands and the websites are working fast. We checked the tracert with office network and home network and the in-office network it r...

Giri512 by L1 Bithead
  • 3996 Views
  • 4 replies
  • 0 Likes
  • 24336 Posts
  • 124 Subscriptions
Labels