General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Sharefile custom URL site allow

We block access to sharefile.com as a whole.  But we do have a sharefile.com company site which we allow access to.  The problem that I am running into is this, when a user attempts to download a file from our sharefile site a random number will be g

...

Self-signed Root CA Certificate FQDN?

I’m planning a test deployment of a globalprotect vpn, so currently going through the guides to see what’s needed. Part of the requirements if not using a trusted CA is to generate a self-signed root CA.

What should the FQDN be on this cert? The deplo...

welly_59 by L3 Networker
  • 1116 Views
  • 1 replies
  • 0 Likes

Resolved! Valid Object Name Requirements Documentation Wrong

When creating an Address Object (as well as other object types) the documentation for Palo Alto 8.1 says this, "The name is case-sensitive, must be unique, and can contain only letters, numbers, spaces, hyphens, and underscores."

 

The popup that appea

...

JasonKC by L1 Bithead
  • 2151 Views
  • 2 replies
  • 0 Likes

Confused about zones

I'm currently migrating from a pair of Cisco ASAs and the zones have me a little confused.

 

Right now I have interfaces on the ASAs of inside, wireless, outside, dmz-private-web, dmz-private-db, dmz-public-web, dmz-public-db, dmz-dev-web, dmz-dev-db.

 

...

HA sync times

Recently I have noticed that it is taking longer to commit and sync the changes from my active PA to my passive PA and the management plane ramps up to 38%. any suggestions

jdprovine by L4 Transporter
  • 2072 Views
  • 7 replies
  • 0 Likes

Resolved! Minemeld on CentOS

I have seen a few older threads referencing minemeld on CentOS using ansible or docker etc, Does anyone have it running on CentOS natively without the use of other 3rd party tools? or an up to date walkthrough? The Ubuntu 14.04 setup is quick, simple

...

hshawn by L4 Transporter
  • 4831 Views
  • 5 replies
  • 0 Likes

Resolved! Stop routing if PBF monotoring is down PA-500

 

 First post to this forum!

 

I have a PA-500 and 3 ISPs. 2 of the 3 VLANs are forwarded using PBF (VLANs 10 & 30 ) and the third uses the default route (VLAN 20).

 

My (simplified) configuration is as follows;

 

 VLAN10 - PBF to ISP 1 fail-over to default

...

James_D by L0 Member
  • 1941 Views
  • 2 replies
  • 0 Likes

Resolved! how interpret MAC in pcap

Hello,

I have a doubt about how to interpret macs in rx pcap and tx pcap. I thought that:
when the traffic enter a layer 3 interface:

the mac destination addres in rx file must be the mac of  ingress interface?
and in tx the source mac, must be the mac o

...

Marivi by L3 Networker
  • 2024 Views
  • 2 replies
  • 0 Likes

Management CPU Utilization is 100%

Our PA-500 management utlization reaches 100% sometimes...according to PA support, There's a process called 'gdindex.sh' runs every 15 minutes for log indexing.

We need to reduce the management plane traffic for better performance. Any suggestions?

Resolved! Change ISP

we're upgrading the internet link in one of our offices...so qwe purchased a new link from a different provider...and I was thinking of unplugging the old link, plugin the new link, remove the old public IP address and then add the IP address of the

...