General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4127 Views
  • 0 replies
  • 0 Likes

Why viruses/spywares passes PA device unblocked?

HelloUntil now I trusted that default configuration for most purposes is OK.Today I discovered that few viruses passes in smtp traffic to my email server. I'm curious why?when in web-broswing traffic the same type of aplication "virus" was denied.My security rule:it using profile "servers". This profile looks like:so it's using antyvirus profile...

_slv_ by L4 Transporter
  • 14136 Views
  • 12 replies
  • 0 Likes

IPv6 over backup interface

I have IPv6 over my backup ISP (dual PA 3020s). I am trying to route all IPv6 traffic over that interface but not having much luck passing any IPv6 through the PA. If I ping6 internal and external hosts from the PA itself it works. If I try to ping/traceroute from behind the PAN at the core or from outside the PAN it doesn't work. I have polici...

drewdown by L4 Transporter
  • 3524 Views
  • 2 replies
  • 0 Likes

Resolved! IPSEC tunnel is up but can not ping through

I have IPSEc ikev1 tunnel with vendor.Phase 1 and 2 are up and green. From PA from my Lan interface when I ping remote lan subnet ping does not work.I see no return traffic from vendor to PA. IS this normal behaviour to have Phase 1 and 2 up but routing does nor work both way?

MP18 by Cyber Elite
  • 12644 Views
  • 2 replies
  • 0 Likes

Issue with PBF rule

Hello, We added a new VDSL Link on port 1/4 and created the PBF rule so that if the primary goes down, it will switch over to the backup. PBF rule is working fine and internet failover works okay. However, customer accesses an internal Server across the client VPN, and when we enable the PBF rule, all access to that server is blocked via the VPN...

Resolved! Palo Alto Updates Issue on Multi VSYS system

Hi All, Hoping an answer can be provided to this multi vsys Palo Alto I am deploying. I enabled the operational status of one of the virtual firewalls I am providing making it fully internet facing with Globalprotect operating on the outside interface. This is operating without issue. When I enabled this VSYS to an operational status I had to ma...

a.jones by L3 Networker
  • 5222 Views
  • 4 replies
  • 0 Likes

Resolved! Error reading last checkpoint

Hi guys I started experiencing this problem in MM 0.9.52, my MM engine was restarting continuously. I tought it was some bug related with this version so, with a little bit of stress, I updated to 0.9.60 (I'm using CentOs), but I still get the same behavior. I even changed the config to the default one (few nodes - spamhaus etc.) but I'm getting...

Screenshot_2019-04-23 Problems with CentOs 7 and MM 0 9 52.png

Resolved! Best practice for OSPF

So i have a Pa850, it has lots of vlans off it. 1 vlan connect to the other OSPF routers. I have OSPF on there. But what about the other interface - is it better to add them as passive OSPF or redistribute connected ?

palo alto website outages

Hi all, Look, I don't want to tell the good people at Palo Alto how to do their jobs, but it would be great if they could push https://knowledgebase.paloaltonetworks.com/ back online. I've been on hold for over an hour for basic information available (or not in this instance) from https://knowledgebase.paloaltonetworks.com/. The big take away fr...

  • 24336 Posts
  • 124 Subscriptions
Top Liked Authors
Labels