General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

A very weird Behavior on SIP traffic traffic reversing back to the same egress interface

Hello everyone , im seeing a very strange behaviour in my pa-445 version 11.1.4-h7 firewall , where i have an interface on the firewall which is a gateway to my voip devices , the same firewall connects to the voice server through an ipsec tunnel interface , so the traffic flow is like this , voice subnet to firewall and then from firewall to vo...

How to create ACLs for access to AWS workspaces (EDLs don't cover all IPs)

I need to create ACLs for outbound access to AWS workspaces using the destination IPs / subnets / FQDNs shown on AWS publication https://docs.aws.amazon.com/workspaces/latest/adminguide/workspaces-port-requirements.html#ip-address-regions. PAN publishes an EDL for AWS workspace, but it only contains a handful of IPs. Some of the IPs listed ...

PaloAlto Passive Firewall Monitoring in HA Setup

Hi everyone,Greetings! I’m currently using OpManager to monitor a Palo Alto firewall in an HA Active/Passive setup, and the Link State of the interfaces on the passive device is set to auto. While OpManager is able to correctly pull interface details from the active firewall, I am experiencing issues with the interface status of the passive fire...

USER111 by L0 Member
  • 1610 Views
  • 1 replies
  • 0 Likes

Resolved! PA-1420 QinQ

Does the PA-1420 support QinQ tagging terminating at the Firewall? We have a L2 connection with an ISP to Azure and they require QinQ tagging. We do not have an ISR or other router to do it for us at this time. Thanks, Steve

smzr34 by L0 Member
  • 2056 Views
  • 1 replies
  • 0 Likes

Resolved! OS Upgrade path to 10.2.10-h9

Hello.I am currently using PAN-820. The OS is 10.1.9-h3. What is the correct way to upgrade? (I will upgrade to 10.2.10-h9.) 1. Upgrade to 10.1.14-h6, then upload 10.2.0, then upgrade to 10.2.10-h92. Upload 10.1.14-h6 and 10.2.0, then upgrade to 10.2.10-h93. Upload 10.2.0, then upgrade to 10.2.10-h9 What is the correct way? I cannot receive ...

danudan by L0 Member
  • 2027 Views
  • 1 replies
  • 0 Likes

GlobalProtect Portal require :443

Hi All, I have an issue where we need to input <firewall IP Address>:443 in order to connect. But some of my users does not require the :443 to connect to the VPN. Screenshot as shown below, Any way that i dont even require :443 to be connected to the VPN?

KevinNg_0-1726118355889.png
Kevin-Ng by L2 Linker
  • 5029 Views
  • 7 replies
  • 0 Likes

Resolved! My PA-1410 logs for single day, why? how to solve?

Hello Team, My new PA-1410 logging is not more than a single day when checking the traffic logs. Previously I had PA-3220 I could checked months of logs. whats wrong here in the PA-1410 loggin settings? manager@PA-1410-Main(active)> show system logdb-quota Quotas: system: 4.00%, 0.726 GB Expiration-period: 0...

Inbound TLS/SMTP inspection (to FortiMail)

Hi,I'm wondering if anyone happens to be doing successful inbound inspection of SMTP/TLS to a FortiMail appliance? Or any other mail server for that matter. I've run in to a brick wall when it comes to renegotiation. The Palo is serving the correct certificate and a manual connections using openssl (openssl s_client -debug -connect mx1.XXXXX.co...

Screenshot 2021-02-04 at 14.43.04.png
pkaren by L1 Bithead
  • 4229 Views
  • 2 replies
  • 0 Likes

I’m facing an issue with L3 int which is configured on Palo Alto firewall

Hi Team, I’m encountering an issue with Poly devices on VLAN 20, which is routed through the firewall with its L3 interface configured. The devices successfully pair at first time with Teams but after a reboot they fail to maintain pairing afterward, despite having a rule that allows all traffic from the VLAN 20 . Interestingly, when these de...

upgrading PAN-OS

Hi I want to upgrade the 8.1.x to the latest version , after two upgrade stay on 8.1.24. I tried to move to 9.0.X but failed. Could you please let me know how I can upgrade to 9.x? (As information that I have find need the Preferred release It means 8.1.25, but I cann't find it) Thanks

Resolved! Are there signature release for following vulnerabilities?

Hi,I'm Tomoyuki Nakamura. Are there any plans to release signature for the vulnerabilities below?.These were not listed in THREAT VAULT or Security Advisory. CVE-2024-11639CVE-2024-11772CVE-2024-11773CVE-2024-37377CVE-2024-9844CVE-2024-37401CVE-2024-11633CVE-2024-11634CVE-2024-47578CVE-2024-47590CVE-2024-54198CVE-2024-47586CVE-2024-54197 B...

Resolved! using Subinterfaces in different Vsys inder same phy interfa

Hello Team, We are implementing a physical interface under vsys Data-center , with subinterface (Eth1/200 --> Data-center) and other subinterface (Eth1/300--DeptA) is assigned to other vsys called DeptA. knowing that the physical interface is without zone . How does the communication will be authorized in the security policies and with the ...

Support wait times and SLAs

I am in the call queue since 3 hours. Called in yesterday and left a call back number, but never received a call back. Does anybody have a similar experience lately?

uvolk707 by L1 Bithead
  • 1976 Views
  • 4 replies
  • 0 Likes
  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels