General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 56 Views
  • 0 replies
  • 0 Likes

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 785 Views
  • 0 replies
  • 0 Likes

Windows 10 Release Cycle and Global Protect Client

Hi All,

 

I'm currently working in an environment which is trying to keep up with the latest Windows 10 release cycles with their Windows as a Service model which brings out releases every 6 months.  We have found that with our AV products, our vendor 

...

NQ1234 by L0 Member
  • 5438 Views
  • 3 replies
  • 0 Likes

Firewall migration, testing rules

Is there a way to test the rules on a new Palo alto vs the existing firewall it will be replacing without affecting traffic? Something like TAP mode but that can block traffic like an in production firewall?

gonzox98 by L0 Member
  • 2351 Views
  • 2 replies
  • 0 Likes

VPN site-2-site configuration and OSPF

Hello forum members,

 

I have been testing the VPN site-2-site configurations on my Palo Alto VM lab, prior to deploying on our production environment. I have successfully set up a VPN connection where both firewalls use static routing. Trouble I'm hav

...

topology.PNG
interfaces.PNG
tunnel.PNG
VR.PNG
rchung54 by L2 Linker
  • 7446 Views
  • 10 replies
  • 0 Likes

Resolved! ping from vr

All, is there an easy way to designate a vr as aq source when pinging ? Like ping host a.b.c.d virtual-router myvr ?

So far I only found a way to specify a source interface but the I need first look up a source interface in the specific VR. Any easier

...

lafrank by L0 Member
  • 7880 Views
  • 5 replies
  • 0 Likes

A few questions

I am planning to install another vsys in the 7080 firewall 

 

my queries 

 

how many max vsys can be created for the 7080 firewall 

How may Site2Site tunnels it supports for each Vsys

How many RAVPNs it supports for each Vsys

How many connections it can han

...

HemanthV by L2 Linker
  • 2045 Views
  • 1 replies
  • 0 Likes

Virtual Wire migration

Hi All.

I am in a postion that we would like to migrate our current cconfiguration of multiple trunk 10g links supporting a vlan with subinterfaces and vsys's to virtual wire mode on the existing chassis, (i.e. 7050, or 5060). 

As I understand it, we w

...

dwmaas by L2 Linker
  • 2582 Views
  • 2 replies
  • 0 Likes

Resolved! Multiple routes to a destination-

I think I know the answer for this question but would like to confirm with anyone who actually imoplemented this. I have a static route with destination 10.237.102.143/32 going through tunnel 10 . Now, I would like to have a staic route to 10.224.0.0

...

LACP Pre-Negotiation 3260

Is this supported or not?

It can be configured, but rumors floading around the internet says that there is a part in the panos 9 that says support for pre-negotiation will be added for some models, among those 3200

hbalzac by L3 Networker
  • 2996 Views
  • 2 replies
  • 0 Likes

Palo Alto with Ansible

Hi, I am trying to configure palo alto with ansible. the normal ping and ssh connection is fine but the "ansible -m ping all" command is returning error that the "ssh authentication failed". How is that possible, if the normal ssh is working fine. Pl...

suny211 by L0 Member
  • 3649 Views
  • 2 replies
  • 0 Likes

Resolved! Security policy not working with Group Mapping

I have configured LDAP group under Group Map settings.

I have added the ldap group there.

 

Then under security policy source user is any and under user i added that group name.

 

When i do sh user group list i see the group name and user ids under it.

 

wh

...

MP18 by Cyber Elite
  • 10885 Views
  • 8 replies
  • 0 Likes

Resolved! Active Passive and Active Active PA and Web Gui Cert

 

I have created CSR and exported that to our Server team as they would generate the cert based off of that.

PA is in active passive mode.

 

Do webgui cert of Active PA will syn with Passive PA?

Do I need to create separte CSR for the passive PA?

 

We also

...

MP18 by Cyber Elite
  • 4328 Views
  • 7 replies
  • 0 Likes
  • 23992 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Authors
Labels