General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

App id “Non-syn-tcp”

I see a lot of non- syn-tcp from from few specific zone. I am sure that there is no asymmetric routing. If that has to be the case how to determine exact causing factor.

Thanks

Sanssj by L2 Linker
  • 4899 Views
  • 3 replies
  • 0 Likes

Resolved! OSPF Inbound Route Filter

Hi,

I see in the admin guide that it is possible to filter the default route so that it is not learnt by the OSPF process.

Is there any way of applying a more granular filter so that I can restrict the Palo Alto OSPF process to only learn 10.0.0.0/8 ro

...

adevine by L1 Bithead
  • 8530 Views
  • 7 replies
  • 0 Likes

Resolved! Qos on application and class 1 and 4

I have created qos policy for application http-video and is defined in class 1

 

However when i run below commands

show session all filter application http-video qos-class 1

 

show session all filter application http-video qos-classs 4

 

I see the applicati

...

MP18 by Cyber Elite
  • 2307 Views
  • 3 replies
  • 0 Likes

leaf and spine and security

Hi,

In a spine and leaf ( vpc ) ,where we should place the firewall  to protect the data center ? 

If  we use layer 3 firewall  all routing  process will be shifted to the fw, spending huge amount on spine won't be beneficial ? 

Layer 3 or layer 2  reco

...

sib2017 by L4 Transporter
  • 3741 Views
  • 1 replies
  • 1 Likes

Route & Path Selection

I have a Cisco backround & I am currently studying Virtual Routers & Static Routes in the PA 8.0 admin guide.  I am trying to understand how Metrics are used in the firewall because it sounds like Administrative Distance does the same thing.  Can som

...

Resolved! Global Protect - Linux Fedora , CA trusted cert error

Hi There,

I'm having the same issue but not on self signed certificate and on linux ( Fedora 29) 

Global Protect is configured with the certificate signed by the Authorized CA.

The Chain is:

DigiCert Global Root CA
DigiCert SHA2 Secure Server CA

Server cer

...

Resolved! qos traffic stats - regular traffic and default group

created qos for application and apply it to class 1

 

it is applied to the interface with 10Gig lan connection.

 

traffic stats shows default group====regular traffic==40 --- assume 

 

does it mean that total traffic going via interface is  40?

 

also defaul

...

Capture1.PNG
MP18 by Cyber Elite
  • 4580 Views
  • 5 replies
  • 0 Likes

Global Protect Certificate

Hi

 

I configured global protect, but when clients try to connect through the agent, they got "Gateway "name":The server certificate is invalid, please contact your IT administrator".

 

For the configured certificates, I configured self-signed certificat

...

myasin by L2 Linker
  • 4575 Views
  • 3 replies
  • 0 Likes

Change Management IPs

Hi

 

We have Panorama managing 6 PA FWs (3 HA Clusters). We want to change the management net of Panorama and Firewalls.

Now logically we will change management IP of Panorama first. Then the Firewalls will lose connectivity and probably logs will be lo

...

PA-200 HA Sync

Hi,

I have a message when I attempt to run a commit:

 

"The running configuration is not currently synchronized to the HA peer, and therefore, this commit will only be applied to the local device.

Please synchronize the peers by going to the dashboard an

...

sync.jpg
s_quasar by L3 Networker
  • 4677 Views
  • 15 replies
  • 0 Likes

FQDN refresh problems

Hell guys,

We have a problem that the FQDN refresh fails nearly everytime. What I mean with "nearly" everytime is, that there are periods in which the FQDN refresh is running smoothly, and then suddenly it fails again.

Example: A few days ago the FQDN

...

Resolved! user if agent and switching between ids

we have configured rules with group mapping using LDAP.

We have one user where he switch between user ids and when he trieds to login to server with user id not allowed in list he gets

denied.

 

should he log off and log on as best practice when he switc

...

MP18 by Cyber Elite
  • 3071 Views
  • 5 replies
  • 0 Likes
  • 23713 Posts
  • 104 Subscriptions
Top Solution Authors
Top Liked Authors
Labels