General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4223 Views
  • 0 replies
  • 0 Likes

user-id

Hi Community, I am running PA local user-id agent in PAN os 8.1.3i am facing an issue that my server monitoring is shows as 'not-connected', i am able to test the authentication and proper service account is configured. it was working fine for long time and hope ther was some windows patch in AD server recently.when i capture in AD server, i am ...

Resolved! Server with public IP behind the firewall without Natting

We need to have a 1 server behind the firewall with public ip address.We do not want private ip on the server. Firewall - outside zoneServer is behind the DMZ_Zone. Currently DMZ has sub interface with private ip address so when traffic comes from internet it will hit he firewall and hit should redirect that to DMZ zone where server has public...

MP18 by Cyber Elite
  • 9099 Views
  • 3 replies
  • 0 Likes

Resolved! Panorama 8.1 in VM question

Hi I was just checking out my VMWare vm setup for my Panorama VM. and it has 2 interfaces on it. how does that match up to the setup interfaces page so 1 is management and 1 is eth1 ? how can i tell and why have 2 ?

Resolved! GlobalProtect Client Profile Question

As the title my question in my mind is relatively straight forward.. when a globalprotect client sucesffuly makes a vpn connection... is there any local profile settings saved to a file on the pc / mac? If so, where are these logs saved / folder path? On Macos...On Windows...

carterg by L2 Linker
  • 4216 Views
  • 1 replies
  • 0 Likes

Can we export Security Policies and Service Objects to from Firewall to Panorama?

Hi All, I have configured some security policies and service objects on my lab environment which consists of VM-100 Firewall for ESXi running PAN OS 8.1.0. Can I export my settings to production environment which consists of 8 ESXi hosts, Panorama and VM-500 for NSX per host. Would I be able to export securuty policies from VM-100 for ESXi to Pa...

Universal policy Implicit Deny blocking Intrazone Traffic

Hi All, I configured the implicit deny (Universal Policy) policy at the bottom of security policies but after that, I could see that some of the Intrazone access got denied by the implicitly deny policy. How we can achieve the Implicit deny policy without affecting the intrazone connections ?? Thanks in Advance...

gpsriram by L0 Member
  • 3115 Views
  • 2 replies
  • 0 Likes

Do not see deny in traffic logs for traffic to internal server accessible via Public IP

We have server reachable via Public IP say on port 13001 and 13002 We have Security rule Source any Zone outside Destination 173.82.x.x IP of server Zone inside port 13001 Here i have not included the port 13002. I have correct NAT policy for this. When i see traffic logs i see Source any destination server public ip address port 13002 a...

MP18 by Cyber Elite
  • 3182 Views
  • 3 replies
  • 0 Likes

Migrating multiple HA pairs to Panorama

Hello, We need to migrate multiple firewall clusters to Panorama. I read the guides but there are still some questions about objects and IP addresses, certificates, etc... Once I have migrated one cluster, what about the other ones if they have some objects with the same IP addresses (local networks, DMZ, etc..). Will they be imported ? Do I nee...

Hurtolak by L0 Member
  • 2122 Views
  • 1 replies
  • 0 Likes

Session Ownership in Active/Active HA scenario

Hi There, I will be greatful if anyone can please help me to understand the below which is taken from https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/high-availability/session-owner.html "You configure the session owner of sessions to be either the firewall that receives the First Packet of a new session from the end host or the fire...

Configuring OSPF & Multicast in Palo Alto firewall sub-interface

We have a requirement to configure OSPF & multicast in a sub-interface of Palo Alto for one of our customers. I would like to understand how it would impact the CPU, memory and throughput and the guidelines and best practices to be followed while configuring OSPF. A comparison against having static routes vs processing OSPF routes. Please su...

MGRashmi by L2 Linker
  • 3987 Views
  • 2 replies
  • 0 Likes

Resolved! HA link port failures and failover

I have a pair of 5220s configured with HA1, HA1 Backup, HA2, and HA2 Backup links in use. All HA links show to be up and running. I have left all of the other knobs for tuning link and path monitoring off, taking all of the defaults. No preemption, etc. I am running in an Active/Passive configuration. When I disconnect HA1 and HA1 Backup, at n...

Global Protect client for linux

Hey all,I've just updated the global protect version to 4.1.8In the docs, it says that the client supports linux.I've followed that doc:https://docs.paloaltonetworks.com/globalprotect/4-1/globalprotect-app-user-guide/globalprotect-app-for-linux/download-and-install-the-globalprotect-app-for-linux#It says I should download the package "PanGPLinux...

MPI-AE by L4 Transporter
  • 11344 Views
  • 9 replies
  • 0 Likes
  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels