General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

VPN site-2-site configuration and OSPF

Hello forum members, I have been testing the VPN site-2-site configurations on my Palo Alto VM lab, prior to deploying on our production environment. I have successfully set up a VPN connection where both firewalls use static routing. Trouble I'm having now is setting up the VPN connection where the 3rd party site uses static routing and my corp...

topology.PNG
interfaces.PNG
tunnel.PNG
VR.PNG
rchung54 by L2 Linker
  • 9667 Views
  • 10 replies
  • 0 Likes

Resolved! ping from vr

All, is there an easy way to designate a vr as aq source when pinging ? Like ping host a.b.c.d virtual-router myvr ?So far I only found a way to specify a source interface but the I need first look up a source interface in the specific VR. Any easier way ?

lafrank by L0 Member
  • 9676 Views
  • 5 replies
  • 0 Likes

A few questions

I am planning to install another vsys in the 7080 firewall my queries how many max vsys can be created for the 7080 firewall How may Site2Site tunnels it supports for each VsysHow many RAVPNs it supports for each VsysHow many connections it can handle for each Vsys ( in respective to RAM and CPU )\ is there any downtime required for creating t...

HemanthV by L2 Linker
  • 2394 Views
  • 1 replies
  • 0 Likes

Virtual Wire migration

Hi All.I am in a postion that we would like to migrate our current cconfiguration of multiple trunk 10g links supporting a vlan with subinterfaces and vsys's to virtual wire mode on the existing chassis, (i.e. 7050, or 5060). As I understand it, we would need at least 2 interfaces for each trunk for both sides of the vwire, and then have matchin...

dwmaas by L2 Linker
  • 3273 Views
  • 2 replies
  • 0 Likes

Resolved! Multiple routes to a destination-

I think I know the answer for this question but would like to confirm with anyone who actually imoplemented this. I have a static route with destination 10.237.102.143/32 going through tunnel 10 . Now, I would like to have a staic route to 10.224.0.0/12 through tunnel 20. As per my understanding, any traffic destined to 10.237.102.143 will take ...

LACP Pre-Negotiation 3260

Is this supported or not?It can be configured, but rumors floading around the internet says that there is a part in the panos 9 that says support for pre-negotiation will be added for some models, among those 3200

hbalzac by L3 Networker
  • 3447 Views
  • 2 replies
  • 0 Likes

Palo Alto with Ansible

Hi, I am trying to configure palo alto with ansible. the normal ping and ssh connection is fine but the "ansible -m ping all" command is returning error that the "ssh authentication failed". How is that possible, if the normal ssh is working fine. Please tell the steps to configure ansible with palo alto or any supporting docs. Thanks

suny211 by L0 Member
  • 4380 Views
  • 2 replies
  • 0 Likes

Resolved! Routing Traffic between two VR's and Bytes Send and Receive info in GUI

I was Testing the Connectivity between two end points for Testing Purpose only Server(10.50.50.1)--------Sw1---------eth1/8----- PA-------------eth1/7-----------------Sw2-----------User PC(10.7.7.6) PA VR1 has interface Eth1/7PA VR2 has interface Eth1/8 Server IP 10.50.50.1PC IP 10.7.7.6 Sw1 and Sw2 has point to point connections with PA. 1>...

MP18 by Cyber Elite
  • 3848 Views
  • 5 replies
  • 0 Likes

Resolved! Security policy not working with Group Mapping

I have configured LDAP group under Group Map settings.I have added the ldap group there. Then under security policy source user is any and under user i added that group name. When i do sh user group list i see the group name and user ids under it. when i try to reach the destination ip under that rule firewall denies that traffic. Security ru...

MP18 by Cyber Elite
  • 12371 Views
  • 8 replies
  • 0 Likes

Resolved! Active Passive and Active Active PA and Web Gui Cert

I have created CSR and exported that to our Server team as they would generate the cert based off of that.PA is in active passive mode. Do webgui cert of Active PA will syn with Passive PA?Do I need to create separte CSR for the passive PA? We also have PA in Active Active mode.Does A/P Webgui Cert process is same as Active Active PA?

MP18 by Cyber Elite
  • 5354 Views
  • 7 replies
  • 0 Likes

ShareFile upload 'blob'

Hi, I was wondering if anyone have been succesful in getting the actual file names of what is being up/downloaded to ShareFile? All I get is file name 'blob'. We do decrypt the traffic but my guess is citrix encapsulates the files making the names unreadable. Anyone? Thanks, Mikael

mgusta by L2 Linker
  • 4022 Views
  • 2 replies
  • 0 Likes

HA and Device Priority

HA active deviceUpon initial configuration the device with the lowest priority, value close to zero, becomes the active unit (default priority is 100). If two devices have the same priority value, the device with the lowest MAC address of the HA1 link becomes the active unit.Can someone give me real world example of when both FWs would have same...

scantwell by L4 Transporter
  • 11920 Views
  • 14 replies
  • 0 Likes
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels