General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Global Protect client for linux

Hey all,I've just updated the global protect version to 4.1.8In the docs, it says that the client supports linux.I've followed that doc:https://docs.paloaltonetworks.com/globalprotect/4-1/globalprotect-app-user-guide/globalprotect-app-for-linux/download-and-install-the-globalprotect-app-for-linux#It says I should download the package "PanGPLinux...

MPI-AE by L4 Transporter
  • 11623 Views
  • 9 replies
  • 0 Likes

Resolved! PA 3050 PAN-OS Upgrade Path

I am currently looking to upgrade my HA pair of 3050s from 7.1.10 to 8.1.6 and per Palo Alto's best practices guide, it is recommended to upgrade to the latest maintenance release prior going to the next major one. As it stands per that best practice guide, I would be to going to 7.1.22, 8.0, 8.0.16, 8.1, 8.1.6 and I am wondering if anyone has d...

PAN OS 8.1.5 - Thoughts?

Hi there! Has anybody had the chance to play with PAN OS 8.1.5 yet in Production? Are there any noticable issues? I've been locked into this killchain of bugs ever since we made the leap to 8.1.0, and I'm just wondering if this build will be the "stable" release.

Fr4nk4 by L2 Linker
  • 17030 Views
  • 18 replies
  • 0 Likes

Resolved! Unallowed to apply NAT rule

Hello, I'm trying to configure double NAT rule (SNAT + DNAT) using Panorama 8.1.4 managing PA 5220 devices running PanOS 8.0.14. I can valid / commit configuration on Panorama, but when pushing config to devices I get following error message : vsys -> vsys4 -> rulebase -> nat -> rules -> Exchange-vers-SMTP -> dynamic-destinatio...

Feature Request: Do Not Require Machine Certs to be Imported on the Firewall

For some background: We recently impelmented a data protection strategy within our organization and would like to restrict the Global Protect remote access VPN service only to domain-joined laptops. Since all our endpoints within our environment receive a machine certificate signed by our Internal PKI Root CA, we wanted to leverage those certif...

Resolved! Export Qos Interface Statistics

Hi just wandering if you can export QOS interface statistics once you have configured your specific interface profiles.. You can view these statistics in realtime but l can only seem to export to PDF/CSV the configuration ? Unless there is another way of exporting interface throughput/bandwidth statistics over a certain period of time.. Thanks SG

acmi by L1 Bithead
  • 4431 Views
  • 2 replies
  • 0 Likes

Resolved! Security Policy Best Practice

Hello all,I've read multiple documents from PA and read some on the forums here, but cannot find anything definitive on this. What I'm trying to find out is what is the best practice/most effective way to configure a Security Policy for filtering. I understand there are several ways to do this, but I've found that the way I've been doing it does...

GCSS-RT by L2 Linker
  • 3533 Views
  • 2 replies
  • 0 Likes

CheckPoint / Migration Tool / Panorama

I have been through the process of getting the files from CheckPoint, going through the migration tool to eliminate unused address, services, etc. I have completed the merge, generated the XML & SET files. I want to get these configuration files into Panorama so we can manage the firewall cluster from Panorama. Can someone tell me or point...

Resolved! Query on Log Forwarding

Hello, We would like to send traffic logs to both Panorama and OpManager (Syslog Server). How can get this configured? We followed the link below but when we go to Policy>Action to forward the log we are not able to select both Panorama and OpManager Syslog. https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-web-interface-help/device/device...

Actiontab.jpg

Resolved! Query on URL filtering

I found this article on URL filtering.My question is how is *.baidu.com not allowing mp3.baidu.com or news.baidu.com as wellWhat does *. signify or equate to this scenario. ALso is there is any need or scenario in which we would need to add www.baidu.com*.baidu.com as rules in Custom URL category. Any Help would be appreciated. HOW TO ALLOW ONE...

Is the PA-3020 adequate for SSL Decryption (and other features)?

My company has 2 PA-3020 firewalls in Active/Passive configuration. They were purchased way before I started working here, so I had no input on the model that was selected. We have about 500 users in our network, and about 800 devices. In our environment, these firewalls sit at the perimeter edge, and there are no internal firewalls (for network...

Fr4nk4 by L2 Linker
  • 7694 Views
  • 5 replies
  • 0 Likes

Resolved! Custom Prototype for 'basic' weblist mining

Hi, I'm trying to create a new custom prototype to ingest a list of URL's that is hosted on a simple webserver. badman.one/1/2/3 badman.two/ badman.three/2/3/4/5.exe The list is published as above, and it works perfectly when I use as an EDL source, but I cannot ingest into MineMeld (as I want to mux it with my other lists to reduce overlap ...

apackard by L4 Transporter
  • 4456 Views
  • 2 replies
  • 0 Likes

Resolved! Site to Site tunnel

Hello I have a question about the configuration of the ipsec tunnel, in the article when the tunnel interface is created "Optional) If you want to assign an IPv4 address to the tunnel interface, select the IPv4 tab, and Add the IP address and network mask, for example 10.31.32.1/32." That "Optional" address, what should it be? from my network...

  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels