General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 442 Views
  • 0 replies
  • 2 Likes

Destination nat not working.

I have security policy untrust -trust(webserver publicip) and nat policy - untrust -untrust.

Wheni try to access web server public ip it is not hitting the security policy and is considering the destination in untrust zone

and denies the traffic.

Pa200

...

Resolved! Enabling OCSP in mgmt profile also allows http management

PA-220, 9.0.0, AV2899-3409, Content 8127- 5316

 

I've enabled HTTP OCSP on the management profile attached to a loopback interface.   HTTP and HTTPS are NOT enabled under Administrative Management Services (in fact, none are checked).

 

Nonetheless, the

...

bperez1 by L0 Member
  • 2516 Views
  • 2 replies
  • 0 Likes

Default Application ID change in 8.0?

We are migrating from some 200's running 7.1.x code to 220's running 8.0.x code. We had a rule that was working fine, allowing any traffic from a server to another server. We didn't define any apps or tcp ports. We have that rule in the new firewall,

...

Split DNS

Hello

 

We would really like to see a "split DNS" configuration for Global Protect, where you can specify certain domains that are sent to the internal DNS Server (or DNS Proxy), and all other domains get handled by the user's normal DNS servers.

 

Thank

...

MichelZ by L1 Bithead
  • 2836 Views
  • 1 replies
  • 0 Likes

Issue with WLC Radius request to NPS Server

Hi all,

I have an issue with the radius request through the firewall,

The radius request come from an cisco 1852-ME WLC and goes to an Windows 2016 NPS Server, both in different zones.

An simular setup with an firewall works fine.

The NPS Server does not

...

Resolved! Running config not synchronized problem

Hey all!

there are two pa 3020 with 8.0.7 in HA active passive.

Three days ago, I switched the passive fw to active.

Yesterday I switched back. I stated that the running config isn't synchronized, but I switched nevertheless.

So I think I should "sync to

...

MPI-AE by L4 Transporter
  • 19038 Views
  • 4 replies
  • 0 Likes

Resolved! Proxy Configuration

Hello,

 

Before switching to Palo FW from Cisco one of our customers could use proxy (http://10.x.x.x/optusproxy.pac).

 

Can you please confirm how can we set this proxy setting in Palo because couldn't find any option on GP to put proxy?

 

I tried using i

...

ecmp

Hi community,

 

Does anybody clarify my following doubts about preferred path in ECMP.

 

I am able to see * mark in one of ECMP route ?. what is that means?.

I have balanced round robin, so that each new sessions should take one path alternatively right ?

...

Resolved! show deviceconfig setting url - dynamic url filtering

 

When i run below command 

 

show deviceconfig setting url
[edit]

 

 

i see no  output.

I read that if above output is blank then we are not doing the dynamic url filtering on the PA?

 

Need to know should i enable this and how it can effect the performance o

...

MP18 by Cyber Elite
  • 3341 Views
  • 4 replies
  • 0 Likes

Resolved! Merlin board mode?

Hello, everybody,

 

I have come across a Palo Alto firewall that cannot normally boot up and remains in "Merlin board mode". I cannot find much information on the internet regarding this. Can someone clarify what this "Merlin board mode" is? And what i

...

Resolved! Block Wetransfer Upload

I was doing a test on allowing wetransfer download, but not allowing upload. Ran into some issues. I have TLS decryption enabled. I have removed the *.wetransfer.com decryption exclusion.

 

My security policy is looking for applications "wetransfer" an

...

ce1028 by L4 Transporter
  • 21642 Views
  • 16 replies
  • 0 Likes

5000 Series not supported on PanOS 9

I'm quite disappointed in Palo Alto's approch to not make 9.0 supported on the 5000 (i.e 5020, 5060, etc.)  For a customer that purchased their equipment right before th 5200s came out it seems we (and probably many others) were screwed over on this

...

NickThen by L2 Linker
  • 8644 Views
  • 10 replies
  • 0 Likes

Response Page working or not for url filtering

We have configured the url filtering response page for one of our sites.

Is there any way from CLI or GUI i can confirm that users when they go to blocked site are actuall getting response page?

 

I see on GUI  url filtering logs that they are blocked.

 

...

MP18 by Cyber Elite
  • 3377 Views
  • 2 replies
  • 0 Likes

IPv6 & User-ID

Hi guys, can anyone point me in the right direction to find out if User-ID supports IPV6 address and if so how does that work.

I assume that the only the primary IP address which gets authenticated on the domain gets logged and therefore reported to t

...

JohnP by L1 Bithead
  • 5324 Views
  • 4 replies
  • 0 Likes
  • 23702 Posts
  • 110 Subscriptions
Top Solution Authors
Labels