General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! VRRP on switches connected to PA in active and passive mode

 

below we have setup

 

 

 

https://snag.gy/3kRV8C.jpg

 

Where switches and routers are running ospf.

PA has static route to the VRRP IP of the switch.

 

1>>Need to know is this good design to have the VRRP backup router connected to the PA active switch?

 

2>>A

...

MP18 by Cyber Elite
  • 4277 Views
  • 4 replies
  • 0 Likes

show user group list - Shows custom group only

Under group mappings of LDAP i have so many AD groups.

 

But when i run below command 

 

show user group list


Total: 1
1* : Custom Group

 

IT does not show me any group names from AD?

what is the reason for that?

 

Also what is difference between Custom group a

...

MP18 by Cyber Elite
  • 8139 Views
  • 30 replies
  • 0 Likes

Resolved! Global Protect issue with BGP routing configuration

Hi All,

 

I have configured Global Protect and I can successfully connect. My Palo Altos are configured to peer and route via BGP which is working without issue.

 

My problem is I cannot reach anything once I am connected. I need at access two address ra

...

a.jones by L3 Networker
  • 3011 Views
  • 2 replies
  • 0 Likes

Resolved! Basic GP routing/NAT/policy

The Gateway/Portal of my setup works fine.

It's routing I think that's not working.

 

I just want a client over GP to hit local networks off the PANOS. 

IP Pool and access routes that been defined, work just fine .. I can see client has been bestowed the

...

mpgioia by L1 Bithead
  • 5582 Views
  • 4 replies
  • 0 Likes

Resolved! Split tunnel greyed out

Hello,

 

We are using PANOS 8.1.7 and GP 4.1.8.

 

We have multi Vsys and one of our VSYS administrator account cannot access GP protect agent split tunnel setup.

 

It is greyed out.


Is this an account limit or something wrong?

 

Screenshot.jpg

threshold values for SNMP Monitoring PA-5250

Hi,

How much RAM does a PA-5250 have? And which threshold value should be defined for alarming in SNMP Monitoring?

And what other oid make sense to monitor and which hreshold value?

 

e.g. count of Sessions: Data Sheet 8.000.000, but what would be a appr

...

regioiT by L0 Member
  • 2459 Views
  • 2 replies
  • 0 Likes

Resolved! TS Agent no port mapping when using windows net use

Hey Guys

We have noticed a weird behaviour:

When I do a telnet to IP 1.1.1.1 Port 445 on our Terminal Server with the TS Agent installed, the associated Port Range will be used as expected and the source user-id will be mapped.

But when we do a net use

...

GlobalProtect Windows client - command line interface?

We're using the GlobalProtect Windows client application to connect to a customer’s VPN.

 

We’d like to automate this process, as right now our  only way to connect is to click on the tray icon ‘Connect’ option.

 

Is it posible to automate (e.g. via comm

...

Resolved! VPN IPSec gcm or cbc cypher types

When configuring VPN to a 3rd party vendor and you are given the required settings for IPsec profile as sha1 or sha256 only, however on the Palo Alto firewall we have the option to use cbc or gcm, e.g. aes-256-cbc and aes-256-gcm.

In the past I used t

...

BatD by L4 Transporter
  • 12401 Views
  • 6 replies
  • 0 Likes

DNS proxy rule

I have a DMZ zone for guest wireless users on Palo Alto. They use our internal server 192.168.10.10 for DNS. I am trying to configure the firewall to force them use 8.8.8.8 for a specific domain eg:*.amazon.com
Please let me know if configuring a DNS

...

  • 23712 Posts
  • 104 Subscriptions
Top Solution Authors
Top Liked Authors
Labels