General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4226 Views
  • 0 replies
  • 0 Likes

Signatures Minimum OS Version??

critical18754DemonBot Command and Control Trafficreset-both8.1.0 I noticed the above threat in releas 8096.. Which says minimum PAN-OS 8.1.0... We are on 8.0.x , does that mean the above would not be applicable? Thanks Rob

Resolved! Tunnels status VPN between Palo Alto-3260 and AWS VPC.

Folks,Typically when we build a IPSec tunnel from the AWS VPC to the on-prem Palo Alto box we get an option of 2 tunnel's from the AWS. I have options of configuring both the tunnels as UP/UP when the end point is something like a Juniper ISG-1000/ISG-2000 device. However, when I configured it on the PA-3260 only one of the tunnels is seen as up...

nson2139 by L3 Networker
  • 4531 Views
  • 2 replies
  • 0 Likes

Traffic Logs - Resolve Hostname - Micrsoft Public IPs

Dear Commuity,I am very new to Palo Alto Firewalls. I saw, that you can check the "Resolve hostname" checkbox when viewing Traffic Logs. Sadly a lot of IPs are not being resolved. I examed a few random samples and notices, the IPs mostly belong to Microsoft. I am now wondering, if there is some kind of way, that I could see this in Traffic Log d...

tpmeier by L0 Member
  • 4704 Views
  • 3 replies
  • 0 Likes

Resolved! Interface Monitoring / See if traffic gets send to interface

I am having a weired issue with a PaloAlto and a Telekom Router. I configured a specific client address to always use a second Router (with internet connection) to communicate to the WAN.Everything on the PaloAlto looks good to me but when I plug-in the Telekom Router into the configured interface port of the Paloalto I cannot access the Routers...

husetech by L2 Linker
  • 12433 Views
  • 4 replies
  • 0 Likes

Resolved! Firewall - Interface High availablity

Hi All,In my scenario, i have single PA-220 for guest access. In trusted zone i would like to keep the interface lelvel (active/standby) high availablity.Interface type as L2. I couldn't do aggregate interface since it's connected to two seperate switches. How we can achieve this.?? Thanks in Advance..

pa-220-ha.png
gpsriram by L1 Bithead
  • 2637 Views
  • 2 replies
  • 0 Likes

FQDN TTL shorter than refresh time

I have a problem with some sites that uses DNS round robin as loadballancer.As an examble:vs-ssh.visualstudio.com This has the TTL set to 300 sec, the PA's FQDN refresh is default 30 min.So the firewall won't cache all IP's used in the round robin, because when it does a refresh the old value has timed-outSo the rule where I use the FQDN object ...

Active/Standby network design and usage as network gateway?

I have some questions on the Active/Standby deployment model. Right now I'm on A/A which requires all network config between the two units to be different since they're both active at the same time. From looking at the documentation, it looks like in an A/S model the network config between the two units is identical which includes all of the s...

jsalmans by L4 Transporter
  • 2730 Views
  • 2 replies
  • 0 Likes

Resolved! Azure DC : Creating a MineMeld feed from an XML file

Hello I'm trying to create a mine meld feed that will somehow download and read an XML file (or just read and xml) which contains a list of Azure datacenter IP addresses , which I can use to apply to my PAN firewall. Any help/direction is appreciated. XML file can be downloaded from; https://www.microsoft.com/en-us/download/confirmation.aspx?...

carysoc by L1 Bithead
  • 5975 Views
  • 2 replies
  • 0 Likes

Resolved! Is it possible to skip 8.0 and go straight to 8.1

Good morning everyone we are running 7.1.x right now and are wanting to move to 8.1.x. Does anyone know if it is possible to install 8.0 dont reboot then install 8.1.x then reboot or do you have to reboot after 8.0 and then reboot after 8.1.x install.

Understanding Panorama & Firewall Configurations

Our Panorama server has 3 firewalls connected to it, all 3 are the same model. All 3 firewalls are linked to there own seperate template, template stack & device group. Each template, template stack & device group is linked to only one firewall. None of the 3 firewalls share the same template, template stack or device group. I am won...

  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels