General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Indicator Duplication in Output

Hi.

 

We are having an issue where we are seeing duplicated indicators in output feeds.  This is a problem for us as the feeds are fed into a SIEM as a lookup table, and when there are duplicates it causes a import failure.

 

The duplicates seems to

...

apackard by L4 Transporter
  • 1984 Views
  • 0 replies
  • 0 Likes

Configuring ldap for mgmt.

I have customer firewall running 8.0.x . I have AD configured for customer using service route going into trust zone as required.

But I would like to manage the firewall at the moment managed wth single local superuser. Is it possible to use AD auth f

...

Resolved! Disconnected from Log collector Server

 

Tonight we got email alerts that our firewalls are disonncted from the log collecors-M500

 

Below is ms log from the PA

 

2019-04-05 01:38:55.024 -0600 MS: disconnected from log-collector. waitcount=1
2019-04-05 01:38:55.024 -0600 lcs agent: channel tear

...

MP18 by Cyber Elite
  • 10366 Views
  • 6 replies
  • 0 Likes

Resolved! VPN remote peer with a LAN address

I need to create a VPN tunnel between my PA firewall with a regular external IP address and a remote non-PA peer that is behind some equipment (no details) and only has a local 172.17.x.x address. Is this possible?

 

If it is possible, do I use the ext

...

mike406 by L2 Linker
  • 4045 Views
  • 4 replies
  • 0 Likes

Resolved! the show interface command

Hello!

I have a question regarding the show interface command.

When you enter for example "show interface ethernet1/3" to see the information of that interface, you can eventually see counters for receive errors or drops. Are these errors counted from ...

Panorama

Hi Everyone,

Is anyone aware of any plans by Palo to introduce a Cloud based version of Panorama?

Devices could be licensed in a similar way to the update subscriptions annually?

 

Ideally if this were integrated into the Customer Portal management of As

...

Resolved! Dynamic Object Sourced from Physical Interface

Is it possible to  create an object in panorama that can be reused in multiple templates that is literally just tied to the ip of an interface on that device?

 

For example, eth1/1 has address 1.1.1.1

Object should just reference eth1/1

Object can be use

...

Globalprotect with DUO MFA and 3rd party iDP SAML Auth

Just a question regarding MFA for Globalprotect portal as well as the client.

I am using Jumpcloud configured as my SAML iDP, when I use the native MFA for Duo captive portal returns the MFA prompt and send me a push message.

 

If I configure the same i

...

Marc_T by L2 Linker
  • 2268 Views
  • 0 replies
  • 0 Likes

Rule with Deny action Allowing traffic

Hi,

 

We facing an strange issue regarding filtering to some destinations.

 

We have a rule with 2 kinds of destination address:

1. Static Group Address defined in Palo Alto

2. External dynamic list (2 of them)

Those address are attached to a deny rule beca

...

nanukanu by L2 Linker
  • 6472 Views
  • 10 replies
  • 0 Likes
  • 24016 Posts
  • 102 Subscriptions
Labels