General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! LACP question

I was given this design to implement on our PA 5050's. This would be to segregate a user segment (4500x-VSS) from the data center (7K's vpc). Can anyone tell me if this is a valid LACP connection? I have never seen it done without a Stacking or VPC link on the other end of the port-channel connections, in this case the Palo 5050's. I am going to...

Capture.JPG
jstalone by L0 Member
  • 2277 Views
  • 1 replies
  • 0 Likes

H323 Gatekeeper Question

Hello everyone, The agency I work for is experiencing H323 call drops. After some research I found documentation here that Palos do not support H323 signaling when a gatekeeper is in call routed mode. The gatekeeper is currently in call routed mode. My question is, does this affect all versions of Palos or only certain versions? Also, what would...

VTCguy by L0 Member
  • 2735 Views
  • 1 replies
  • 0 Likes

Resolved! What is best way to provision Global Protect and LSVPN portal and gateway on one device?

This is for a lab at the moment, but want real-world advice in case I attempt it. I had a portal and gateway setup for client SSL VPN and wanted to add LSVPN. Due to complete documents for each type of GP feature, but none combining the two, I went through many iterations of mixing the two, but always having some kind of error with needed profi...

Create User based Internet access rule

Hi, Could someone please advise how I can limit internet access by user? I would like the below Block level 1 - blocks the bad stuff but allows everything else Block level 2 - blocks everything apart from an allow list I believe I have set Enable User-ID up and I have set 2 groups within AD and attached the users to those groups. I seem to b...

SSL Decryption not working with Policy based forwarding

I have configured SSL decryption with one ISP which is configured via default route and it is working fine. I have another ISP and I configured to forward internet traffic from particular endpoints (same trust zone) to 2nd ISP, for this purpose i created NAT and a PBF rule for those particular endpoints, scenario was working fine till now. I wa...

8.0.15 How is it running

Hello Community,How is it running for those that have already upgraded? I would wait but the release of the recent vulnerabilities have pushed this forward for me. https://securityadvisories.paloaltonetworks.com/ Thanks in advance!

Template not showing up in Device Groups

Created template I have Templates showing up over Network and Device tabs. But when I commit there isn't a radio button for templates and when you look under Device Groups and click the group I created it in, the template does not show up. Panorama 8.1.4

ccall678 by L0 Member
  • 3197 Views
  • 1 replies
  • 0 Likes

QOS Policy config with Destination NAT Traffic

Hi, allHow can i set to config QoS Policy for Destination NAT Traffic from untrust to untrust zone.I searched for related knowledge but could not find it.which one is right?untrust to untrust (Public IP)untrust to trust (Public IP)untrust to trust (Private IP)Thanks.

hbshin by L2 Linker
  • 2829 Views
  • 2 replies
  • 0 Likes

Resolved! Security rules on middle level DGs

I have three templates in a stack and three levels of device groups. I want to create a leveled policies based on security zones. Let's say I have a secuity zone called GlobalProtect. Let's say I have:DG-Standard|-------DG-Management |-------------DG-ISOC I want to create GlobalProtect rules on level 2 of device groups. The problem i...

Resolved! Template stack and referencing security zones

Settings in a template cannot reference to another template even if in the same template stack. I want to simplify management of security policies based on security zones. Let say I have Template-Standard and then templates for each PA like Template-PL.I create a security zones LAN, Internet, GP, S2SVPN in Template-Standard and create necesary ...

Resolved! Putting a PA-4060 back into service

I recently aquired a PA-4060 from a recycling center. It appears to be fully functional without issue. It's currently on PAN-OS 4.1.12. How can I go about updating this device? I'd like to try and use it in my homelab for learning about Palo Alto products.

Resolved! External Email Server Filtering

We have a ListServ server which needs to accept email from a user hosted in Office 365. I would like to limit the security rule allowing the inbound traffic to only accept SMTP connections from the O365 mail servers. I know the list of those servers can be dynamic, so I was wondering if this is even possible, or if there is a more effective me...

  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels