General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! HA Link and Path Monitoring

We've configured HA Active\Passive on a pair of 5250's running PAN-OS 8.1.5 and it works a treat and pre-emption also works as expected.

 

I've configured Link monitoring so if we get an HA failure if the trusted links fail which works and it fails ove

...

JonHill by L1 Bithead
  • 7403 Views
  • 11 replies
  • 0 Likes

Use XML API users in policies

Hallo,

I successfully configured an WLAN-Accesspoint to send users via the xml api.
I can see the users in the log entries but I cannot select the users in particular policies. Looks like the users are not known to the firewall.

Do I need to create loca...

tsauter by L0 Member
  • 2143 Views
  • 3 replies
  • 0 Likes

Resolved! Dedicated Logging Export Interface on PA 5220?

By default, I know that you can send all of your logging messages out the onboard management interface, on a platform like the 5220.  However, I would like to avoid the extra noise on my management network, by configuring separate, dedicated interfac

...

Static Route monitoring and NAT

I'm having an issue with my NAT policy. 
I've configured a backup ISP connection with a static route and a higher metric. When the primary ISP connection fails the routing portion works correctly and I can see the primary default route get removed fro

...

Modo2016 by L1 Bithead
  • 2256 Views
  • 2 replies
  • 0 Likes

Change interface virtual router cause network down

My network has 2 outgoing data lines. Using one virtual router and set static default route for the 2 interfaces. The 1st interface has its Metric set to higher priority. As I want to divide the traffic. Some zones were force to use the 2nd interface

...

jeremylo by L3 Networker
  • 2721 Views
  • 3 replies
  • 0 Likes

Force to Use Certificate

Dear Friends !

as i study PAN 7.0 if there is no Certificate installed in Client PC, PAN can not read https secure sites

in this is if i block youtube or other social websites and client uninstall CA from its browser he/she will be able to open blocked

...

Blocked WebSites

Dear Friends !

 

i am using PAN 7.0 and blocked some secure websites, but PAN is not able to block websites by name

for exmaple when i access 53.55.125.73 it is blocked succesfully but when i type https://www.mydomain.com Certificate is verfying by PAN

...

Upgrade 3020 to new version?

Hey guys,

There are two 3020s in HA that run 8.0.7

I'm wondering if I can upgrade to a new version in 8.1.X train? Or should I stay at 8.0.7?

 

Can someone share their experiences?

 

Thank you.

MPI-AE by L4 Transporter
  • 4139 Views
  • 10 replies
  • 0 Likes

Resolved! GlobalProtect when Palo behind ASA

Hi All

 

I've been tasked with getting GP working and as I'm not as skilled as many of you, I thought I'd ask the brains trust if this is possible.

We have a PA-3020 which sits behind a Cisco ASA. The ASA is the edge firewall and is a yes/no gateway, th

...

Log Forwarding / Dynamic Address List

Hi,

 

We are trying to use the cool new "built-in actions" / tagging feature available through Log Forwarding to tag source IP addresses that generate high/critical threat events to build a dynamic address list that will ultimately be used in a policy

...

SARowe_NZ by L3 Networker
  • 2798 Views
  • 2 replies
  • 0 Likes

VM-100 on VMware Worksataion 15

Hi there,

I have no issues spining up new VM-100s in my VMware Workstation 15.0.2, however, when I try to add a third vNIC to the VM, the VM will not boot any longer. I get an error on the CLI (VM console) indicating that the configuration is not supp

...

incorrect browse time-user activity report

I have a question regarding reporting.

When I generate user activity report, it is showing me browse times inaccurately. I have logging at the end of the session. if I enable log at start, will I address the issue?

 

TIA>

  • 23669 Posts
  • 104 Subscriptions
Top Solution Authors
Top Liked Authors
Labels