General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Security Based EDLs

I am trying out a PoC for Palo for a specific threat purpose. The box came with some EDLs that I didn't expect and figured I'd share here. They seem to cover a wide range of threats that would be really benefical for others to have deployed. I'd just caution to take extra care in your production enviornment when implementing these blocks look...

EDLs.PNG

Resolved! 5260 Experience

Looking for some realworld deployment experience. Anyone that's deployed a 5260 how much data have you guys pushed through it. Anyone pushing 20-30Gbps+? How does it perform? I'm thinking about getting one and putting it off our tapping infrastructure for IPS/IDS functionality.

ETA for UserID support for Windows Server 2019

Hi,My Server team are asking when the PaloAlto UserID will support being installed onr Windows Server 2019, as they are planning on upgrading the current server it runs on. Is ther any road map or ETA when we can expect this?Don't need 2019 AD support yet, just installing on Windows Server 2019.Many Thanks,Mike

Global Protect Next TokenCode Mode

Hi all, Just wondering what I am missing in terms of getting the GlobalProtect Portal and Gateway to show next token prompts etc.I have a fairly straightforward ISE RADIUS setup that talks to RSA AM. The authentication and authorization works except when next tokencode mode is invoked as no prompts are seen to indicate the next token is required...

Presales question: External IP address assigned through DHCP and /29 routed to this IP, possible?

Hi all, I am considering to replace my Cisco ASA 5505 by a PA-220.My situation is as follows:The external interface is part of a trunk where internet connectivity is delivered on a specific VLAN.The IP address on the external interface is assigned by DHCP which unfortunately is mandatory.A public /29 subnet is routed to that DHCP assigned IP add...

HaVaNL by L0 Member
  • 2945 Views
  • 1 replies
  • 0 Likes

BGP - TCP/179

Hello Folks, I have a simple BGP question. I'm going to be creating a BGP peer between a Palo Alto firewall and a Cisco router. Do I need to create a security policy allowing TCP/179 between my Palo Alto firewall and the router. They are directly connected. I cant find any examples of that.... so hopeing some can advise.thank you.

Jedi_D by L2 Linker
  • 3729 Views
  • 1 replies
  • 0 Likes

Resolved! NAT - with URL for NAT policy

Hello Folks, I need some advice .... I want to create a NAT rule to allow traffic to NOT be NATTED if it is going to a particular website. e.g. if going to www.paloaltonetworks.com then dont NAT. Is it possible to use URL objects for in a NAT policy?? Please could someone suggest how this can be done, or send me some useful links for doing this...

Jedi_D by L2 Linker
  • 7401 Views
  • 6 replies
  • 0 Likes

Resolved! Proxy ID for IPSEC traffic going to Internet

We have IPSEC tunnel working fine with vendor device. Vendor Lan subnet is 192.168.80.xOur lan subnet is 10.10.x.x Proxy ID on PA is Local Remote 10.10.x.x 192.168.80.x Also Vendor has another Lan subnet 192.168.81.x that need to talk to internet IP say 23.x.x.xThis traffic need...

MP18 by Cyber Elite
  • 9594 Views
  • 8 replies
  • 0 Likes

Dual ISP with RIP

Dear Friends ! i am running RIP in entire Network with Dual ISPthe problem is that when 1 network part want to communicates with other part PBR just forward thier packets to Internethow can i solved this issue to prefere routing table first and forward the packet to internet then

Resolved! application any and service application default in policy

I have a Internet policy that permits application "any" with service "application-default". I just discovered that we can no longer use Ookla Speedtest since turning on the "application-default" service. Has anyone else experienced this and could you share how you resolved it? Thanks.

Trying to setup a virtual lab using VMWare Workstation

I am taking some Palo Alto Firewall training from CBTNuggets, in prepartion for the ACE Exam, I don't have enough spare equipment to setup a live lab, so I am trying to setup a virtual lab like they show in the CBTNuggets training. One of the steps they sugget using VMWare Workstation, which I have downloaded. There is a step tp use a PA-VM-ES...

TCGuy by L0 Member
  • 6607 Views
  • 4 replies
  • 0 Likes
  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels