General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1693 Views
  • 0 replies
  • 0 Likes

show counter global filter delta yes -----drops

when i run command

 

show counter global filter delta yes

 

i see below counters incrementing  need to understand which are these drops and why PA is dropping these packets?

do they impact the performance of the PA?

 

flow_tcp_non_syn_drop    

 

flow_fpga_egr

...

MP18 by Cyber Elite
  • 5688 Views
  • 2 replies
  • 0 Likes

Resolved! logical int counters - packets dropped

 

 

Logical interface counters read from CPU:
--------------------------------------------------------------------------------
bytes received 21513660
bytes transmitted 2835
packets received 358561
packets transmitted 21
receive errors 0
packets dropped 35853

...

MP18 by Cyber Elite
  • 4743 Views
  • 4 replies
  • 0 Likes

Palo alto HTTPS decryption?

Hi all,

 

I am using PA-850. I configure to decrypt HTTPS, and use AD group policy to install certificates on client, it works well with AD users. but we have other situation that client is not AD users. do we have any ways to redirect client to the UR

...

Chivas by L2 Linker
  • 5286 Views
  • 6 replies
  • 0 Likes

Resolved! Wildcard certificate on PA firewalls

Hi Team,

 

I'm trying to create a CSR in Panorama in order to get a wildcard certificate from our third party CA.

 

In order platforms, I define as common name the format *.mydomain.com but in Palo Alto I'm getting an error: Failed to generate certificat

...

Stickied post for recommended versions?

Just wondering since this is a topic that comes up often and I actually just asked TAC about it myself, should we maybe have a stickied post on here that documents the recommended versions for each software track?  I realize Palo Alto doesn't publish

...

jsalmans by L4 Transporter
  • 3383 Views
  • 3 replies
  • 3 Likes

Resolved! Real time alerts for threats?

Is there such a thing with PAN?  IE if the logs generate a critical alert can is there some logic to fire an email or generate a report with the relevant information? 

drewdown by L4 Transporter
  • 7307 Views
  • 10 replies
  • 0 Likes

App id “Non-syn-tcp”

I see a lot of non- syn-tcp from from few specific zone. I am sure that there is no asymmetric routing. If that has to be the case how to determine exact causing factor.

Thanks

Sanssj by L2 Linker
  • 6388 Views
  • 3 replies
  • 0 Likes

Resolved! OSPF Inbound Route Filter

Hi,

I see in the admin guide that it is possible to filter the default route so that it is not learnt by the OSPF process.

Is there any way of applying a more granular filter so that I can restrict the Palo Alto OSPF process to only learn 10.0.0.0/8 ro

...

adevine by L1 Bithead
  • 9618 Views
  • 7 replies
  • 0 Likes

Resolved! Qos on application and class 1 and 4

I have created qos policy for application http-video and is defined in class 1

 

However when i run below commands

show session all filter application http-video qos-class 1

 

show session all filter application http-video qos-classs 4

 

I see the applicati

...

MP18 by Cyber Elite
  • 2847 Views
  • 3 replies
  • 0 Likes

leaf and spine and security

Hi,

In a spine and leaf ( vpc ) ,where we should place the firewall  to protect the data center ? 

If  we use layer 3 firewall  all routing  process will be shifted to the fw, spending huge amount on spine won't be beneficial ? 

Layer 3 or layer 2  reco

...

sib2017 by L4 Transporter
  • 4675 Views
  • 1 replies
  • 1 Likes

Route & Path Selection

I have a Cisco backround & I am currently studying Virtual Routers & Static Routes in the PA 8.0 admin guide.  I am trying to understand how Metrics are used in the firewall because it sounds like Administrative Distance does the same thing.  Can som

...

  • 24216 Posts
  • 117 Subscriptions
Top Liked Authors
Labels