General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

unknown-tcp for Exchange 2016 when decrypted

Hi, I'm doing decryption for Exchange 2013 OWA web part and it was doing good - was seeing mostly applications like ms-exchange, activesync, outlook-web which makes sense.Customer upgraded their infrastructure to Exchange 2016 and after trying to decryot that I'm getting a bunch of unknown-tcp traffic after decryption instead of ms-exchange and/...

nikoo by L3 Networker
  • 3098 Views
  • 2 replies
  • 0 Likes

Configuring ldap for mgmt.

I have customer firewall running 8.0.x . I have AD configured for customer using service route going into trust zone as required.But I would like to manage the firewall at the moment managed wth single local superuser. Is it possible to use AD auth for this as well.

Connecting to mapped shares - most of the time very, very slow

I work with a company that uses Global Protect as their VPN solution. When I work from my offsite office, I'll fire up the VPN, login and get to work. For the past year, I've suffered from very long connection times re-establishing access to an important shared folder. In mapping this share, I usually go through Windows Explorer and just clic...

CharlieG by L1 Bithead
  • 7325 Views
  • 7 replies
  • 0 Likes

Resolved! M500 Change Log Collection Interface from the Management to the Dedicated Eth 1 and 12

Currently we have 2 M500 running in log collector mode. All the Firewalls are sending logs to M500 on its Management interface .Panorama M100 also talk to M500 via its Management interface. Currenly seems our traffic has increased and we are send lot of logs to M500 on its Management Interface. So I need to use Eth1 and Eth2 on each M500 for lo...

MP18 by Cyber Elite
  • 3125 Views
  • 2 replies
  • 0 Likes

Resolved! Disconnected from Log collector Server

Tonight we got email alerts that our firewalls are disonncted from the log collecors-M500 Below is ms log from the PA 2019-04-05 01:38:55.024 -0600 MS: disconnected from log-collector. waitcount=12019-04-05 01:38:55.024 -0600 lcs agent: channel teardown (to 10.7.1.139) complete.2019-04-05 01:38:55.035 -0600 Error: pan_conn_ext_send_base(cs_conn....

MP18 by Cyber Elite
  • 13227 Views
  • 6 replies
  • 0 Likes

Resolved! Suspending Passive PA to fix the connection to uplink when link monitoring is enabled

We have PA 3020 in Active PAssive mode.We have link monitoring enabled on both PA for uplink and downlink. For some reason I need to change the uplink connection from passive PA to the uplink switch. Need to know if we unplug the fiber connection from PAssive PA and replace it with new fiber connection before doing this 1>Should I suspend th...

MP18 by Cyber Elite
  • 3575 Views
  • 2 replies
  • 0 Likes

Resolved! VPN remote peer with a LAN address

I need to create a VPN tunnel between my PA firewall with a regular external IP address and a remote non-PA peer that is behind some equipment (no details) and only has a local 172.17.x.x address. Is this possible? If it is possible, do I use the external IP of the remote site even though the VPN connection will not be with that IP address? I'm ...

mike406 by L2 Linker
  • 5577 Views
  • 4 replies
  • 0 Likes

Resolved! the show interface command

Hello!I have a question regarding the show interface command.When you enter for example "show interface ethernet1/3" to see the information of that interface, you can eventually see counters for receive errors or drops. Are these errors counted from the last time data plane was restarted?And is there an option similar to "filter delta yes" for p...

Panorama

Hi Everyone,Is anyone aware of any plans by Palo to introduce a Cloud based version of Panorama?Devices could be licensed in a similar way to the update subscriptions annually? Ideally if this were integrated into the Customer Portal management of Assets/Licenses/Panorama etc could all be done in one place? What would be the "Pro's/Cons"? Welcom...

Resolved! Dynamic Object Sourced from Physical Interface

Is it possible to create an object in panorama that can be reused in multiple templates that is literally just tied to the ip of an interface on that device? For example, eth1/1 has address 1.1.1.1Object should just reference eth1/1Object can be used in template that can be reused for multiple devices.

Rule with Deny action Allowing traffic

Hi, We facing an strange issue regarding filtering to some destinations. We have a rule with 2 kinds of destination address:1. Static Group Address defined in Palo Alto2. External dynamic list (2 of them)Those address are attached to a deny rule because are malicious url. When take a look to the traffic log, we see that traffic hits the rule but...

nanukanu by L2 Linker
  • 9932 Views
  • 10 replies
  • 0 Likes
  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels