General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Does Panorama send info to PA to send logs to which Log collector??

We have Panorama M100 and 2 M500 for logs.Under PAnorama GUI -- log collectors i have configured which PA will send logs to which log collector. Firewall does not have this info. Need to know how does Firewall know which log collector it needs to send logs to?is ths info comes from Panorama to firewall? if yes then how and when?

MP18 by Cyber Elite
  • 7877 Views
  • 9 replies
  • 0 Likes

SCOM port 1270 detected as SSL application

Hi, While I checking on my firewall, I found that SCOM port 1270 detected under SSL application.Can someone help me with this? Is there anything that I am missing or Is it issue from Palo Alto?Thanks in advance.

EDL Refresh fails but certificate is valid

I've got our wildcard certificate on our minemeld server, which shows up perfectly fine when i go to the web UI through Opera to manage the server. But, when I try to use the minemeld feeds in EDLs on my 5220s, I get an error that says certificate validation failed. Is it an issue with wildcard certificates, or is there something else I sho...

Resolved! Any pitfalls upgrading VM-100 to 9.0?

Hi, I have a VM-100 running the latest v8 under VMWare ESX 6.7. Should I expect any problems upgrading to v9? I have browsed the docs and found no red lights, but I just want to ask here in case I have overlooked something... regards Tor

PAN-OS recommendation

Dear All, Currently PA 5200 is running with PA-OS-8.0.13 and we are facing issues with the number of objects that we could create. Release notes of 9.0 provides a promising object count increase. Kindly provide a stable version of 9.0 and PoA to upgrade from 8.0 to the recommended version. https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-...

Resolved! Is higher latency normal on a VM compared to hardware?

Hi All At home I run a PA-200, but I've been toying with the idea of moving to a VM (both lab-licences).. But whilst the VM runs WebUI runs 100x quicker, MGT interface is fine, but on the actual FW interface it has a much higher ping latency. When pinging a FW interface on my PA-200, I get average of 1-2ms response times, but on the VM, I see an...

projxit by L1 Bithead
  • 6720 Views
  • 1 replies
  • 0 Likes

Resolved! when doing commit from PA i get error

i am doing temp override on the PA so that managenet interface ip permitted list is as per panorama but when i do validcommit etails:vsys1Error: No PROXY_OPTOUT notify page defined in vsys1.

MP18 by Cyber Elite
  • 15667 Views
  • 12 replies
  • 0 Likes

Resolved! QoS Guaranteed Bandwidth question

We have a couple of tenants in our building and I was wanting to insure a guaranteed bandwidth of our 100 Mbs circuit for us regardless of what the tenants are doing. I was looking at something like this: I set all of our traffic to class 1 and all tenant traffic to class 2; create a QoS profile that sets class 1 with guaranteed bandwidth to 75 ...

Bvance by L2 Linker
  • 8660 Views
  • 4 replies
  • 0 Likes

querying regarding URL filtering profile

I had created a custom URL category (for specific tiny url let say *.tinyurl.com/) & in the url filtering profile I had opted for option to continue for this custom url category to make user acknowledge the action & log the event. but the caveat here is I see the user being going to the palo alto continue page but sometimes he can seamle...

Sanssj by L2 Linker
  • 4028 Views
  • 2 replies
  • 0 Likes

Resolved! Dataplane Limitations - When to use a router for intrazone vlan routing?

Hi,This is a question about when to use the firewall or a seperate core router to route traffic vor vlans in the same zone (intrazone).As this traffic does not need to be inspected, it should only be using the network layer and cpu of the dataplane. I tend to use the FW (simpler, more secure) but at which point would you recommend using a seper...

Scruffy by L1 Bithead
  • 5554 Views
  • 6 replies
  • 0 Likes

New NG PA implementation path URL

Hi all, we are replacing our aging ASA VPN with the new PA GlobalProtect. ASA has a path of someurl.com/path rather than just a default someurl.com. Makes it a bit harder for the bad guys to guess. Is PA capable of creating a path, rather than a default url? thank you in advance for the helpRegards

au_igs by L1 Bithead
  • 5278 Views
  • 5 replies
  • 0 Likes

Resolved! Palo Alto - Dynamic Updates

Hi I'm new to Palo Alto alto. but my company have several diffrent versions of Palo alto firewalls, some with direct support via palo alto PA-3050 where i have access to download the Dynaic updates directly. Plus some that we have support through a reseller that they need to download the updates and send to us as the firewalls don't have access ...

kev91234 by L1 Bithead
  • 5634 Views
  • 4 replies
  • 0 Likes
  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels