General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4229 Views
  • 0 replies
  • 0 Likes

LSVPN Satellite Reconnection Time

Does anyone know how to decrease the time between LSVPN Satellite connection attempts? If one of our satellites drops off (e.g. reboot/power outage/etc), after it comes back up it will take up to an hour to connect to it's nominated Gateway. Also, if the Gateway is rebooted (e.g. after hours mainteance) it takes up to an hour before all of the s...

EDL- Predefined Paloalto IP Lists do not update

Hi guys, my PA is still with the initial set of roughly 500 IPs in the two predefined IP lists which do not update; it is said those lists are part of the AV signature updates which run well. I also have confirmed with the CLI that its is not a GUI problem. Am I missing something here? Can you take a look at your lists and the numbers of IPs wit...

pan219 by L2 Linker
  • 3530 Views
  • 2 replies
  • 0 Likes

Resolved! Getting error when committing more NAT rules "Total NAT DIPP rules 401 exceeds the capacity of 400"

https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat/nat-rule-capacitiesdescribes the NAT Rule capacities as follows:-----The number of NAT rules allowed is based on the firewall model. Individual rule limits are set for static, Dynamic IP (DIP), and Dynamic IP and Port (DIPP) NAT. The sum of the number of rules used for thes...

Panorama templates for an Active/Passive setup?

I'm in the process of setting up our new firewalls. I went ahead and set up management on each of them, got them updated, got them paired up into Active/Passive, and am now following the Palo Alto 8.1 guide to migrate an HA config over to Panorama. I'm almost to the end but I have a question concerning the templates. The instructions say to d...

jsalmans by L4 Transporter
  • 3849 Views
  • 2 replies
  • 0 Likes

Resolved! 5250 HSCI port compatibility?

Greetings all, I should be getting our new 5250 firewalls in any day now and I'm trying to get my cable shopping list together so we can start working on our install process. I noticed the HSCI port for the A/S config uses a 40/100 port and, giving the units will be close together, I was thinking I'd like to get a twinax style cable instead of ...

jsalmans by L4 Transporter
  • 3814 Views
  • 1 replies
  • 0 Likes

Behaviour of VPN tunnels in HA pair during the failover

HiCan anyone please explain the behaviour of VPN tunnels during the failover on PAN.Does the ISAKMP and IPSEC SA table gets passed on to the standby unit ?Does the VPN tunnels will re-estalish the session again on the new active unit after the failover? what would be the downtime that the users will experience for vpn tunnels? Regards,

R_Sharma by L2 Linker
  • 10822 Views
  • 3 replies
  • 0 Likes

Resolved! different wildfire version

Hello, We have a couple of PA3020 but only one of them have different wildfire version as currently installed once we saw failed wirdfire update messages. Is it normal behaivior to have a different wildfire verison instllaed even though it is the same model? what could be the reasons of failing update? devsrv.log2018-12-27 14:18:172018-12-27 14...

Panorama Templates and default vsys settings?

What is the purpose/consequence of a having a template with a default vsys set to either : vsys1 or None -This is found under: panorama/templates/(specific template name)/Default VSYS/(option of vsys1 OR None) I'm finding that our firewalls with multiple vsys defined, have the setting to "None". On our global templates (templates used across mu...

Sec101 by L4 Transporter
  • 7393 Views
  • 1 replies
  • 1 Likes

What the heck is in /pancfg?

Hi all, I'm trying to figure out what is taking up all the space in the /opt/pancfg filesystem on my Panorama appliance. I've deleted all the old saved configurations and lowered the number of config audit versions from 100 to 50. (Each of these versions is about 500K.) I've taken a look at what anti-virus, wildfire, and content updates are s...

Resolved! Global Protect with multiple portals and gateways.

I have a working portal and gateway on PA3020 running 8.0.12.I want to setup another portal and geteway and repliciate all the settings.Second GP will be used for testing purposes.Only changes would be to use another public ip ,create another tunnel and loopback interface and ip pool.Just want to make sure I dont break prod global protect while ...

Resolved! Is there any command to modify tls response version for ssl decryption forward proxy

When a client's browser disabled TLS1.0 and connect to a website which is only support TLS1.0.Is there any way to let PA firewall response TLS1.0 to user? Because before we replaced our customer's firewall, their firewall was CheckPoint CP5800.In same situation CP5800 responsed TLS1.2 to clients, so they browse the website works fine, but now t...

OVA file

pa-vm-esx-8.0.ova I need to download the OVA file for training purposes. How do I go about getting a file?

File Blocking - No URL?

Hi I have various response pages configured to allow the user to click and send an email when hitting a blocked site. The URL one works fine - user clicks continue, new email pops up with the following placed in the email : URL and user name. For File blocking, I cannot get the URL to go in to the email, it's always the IP address instead that...

Url blocking

Hi guys, surely a stupid question, but cannot find out.PA (a 5060 couple), as seen in the screenshot, allows the connection but blocks the corrispective URL.How can I allow the URL too? Thanks

Threat_small.png
Shye80 by L1 Bithead
  • 1989 Views
  • 1 replies
  • 0 Likes
  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels