General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 656 Views
  • 0 replies
  • 0 Likes

DoS policy notify

Hi,

 

We have configured a DoS policy in order to limit the connections to several internal services.

So when we launch a test in order to check that the connections are being limit we dont see any logs or event reporting it.

But looking in policy statis

...

BigPalo by L4 Transporter
  • 9726 Views
  • 13 replies
  • 0 Likes

Comcast internet VPN disconnects

My company has not transitioned to GPCS yet and currently still uses Cisco AnyConnect. We have 10K+ remote users and 5weeks ago about 100+ users started getting random disconnects and they are all Comcast users with XB3 type modem. I wanted to ask th

...

BGP config same AS different locations

Hello,

 

We found some BGP routes with same AS we are using at our PA3020.

PA3020 AS 65400

 

 

BGP route (from Cisco Router)

 *   172.27.0.0/20    193.242.39.6                           0 65394 65390 8035 21302 65400 65316 64540 4755 4755 i

 

Usually with Cis

...

block all video streaming with palo alto PA-850??

Hello all,

 

I want to block all video treaming with palo alto. do do following this:

    1, go to Objects--> URL fitering--> add new URL fitering with name block_video.

    2, in categories, I check in streaming-media and choose block.

    3, I create th

...

Chivas by L2 Linker
  • 7098 Views
  • 7 replies
  • 0 Likes

Global Protect Client Bundles not installing. VM100

I am trying to install a client bundle for GP on out test VM-100

 

The VM has no internet connection so I downloaed the bundle from PA

 

PanGP-4.0.6

 

On "device > Global Protect Client " I upload the file, which works but nothign is displayed.

 

If i go to

...

Resolved! ICMP reply from the firewall instead of endpoint destination

Hello everybody,


What could cause ping to respond from a different IP?
When tested from source, the response message of the ping command is successful and it's coming from the PaloAlto firewall, not from the destination IP.
Where and how can I verify on

...

000000 by L1 Bithead
  • 3165 Views
  • 2 replies
  • 0 Likes

New Feature request or ?

Hi

 

I would like to have apolicy that just logs and does nothing else - ie the packet keeps getting evaluated.

 

some times I want to know there is packet there but not process it with that line.

 

Can this be done already ?

Azure Site Recovery Miner - XML source into Minemeld

I'm looking to do, what I believe, would be a simple minor for Azure Site Recovery IP list.  The list is located here and is in XML form.  

 

https://aka.ms/site-recovery-public-ips


I have bounced around on some articles and tried to follow a few, bu

...

Jmarx1 by L1 Bithead
  • 3699 Views
  • 1 replies
  • 0 Likes

Resolved! Moving Colo Datacenter

Hi folks,

 

We got some dreaded news that our colo vendor is not renewing lease and we are now moving.

We have two 3020 firewalls configured in HA.

 

I am looking for any general comments that could help in my direction.

 

One thought:

  • Break HA.
  • Take secondar
...

OMatlock by L4 Transporter
  • 5357 Views
  • 7 replies
  • 1 Likes

Palo Alto against spam

hello

İn the network users get many spams.We dont have any other anti-spam solution.Is it possible to stop spams by Palo Alto NGFW?

Radmin_85 by L4 Transporter
  • 9729 Views
  • 4 replies
  • 0 Likes

Resolved! Global Protect Migration Assistance

Hello!

 

So, we inheritted an infrastructure with a few hundred VPN users whose Global Protect clients were all deployed pointing to the IP address of the GP Portal (not an FQDN). And, of course, we are now in a position where that physical site (and i

...

locampo by L2 Linker
  • 7695 Views
  • 6 replies
  • 0 Likes

Aruba AP Tunnel Problem

Hello, I'm having problems with Aruba AP connection through a FW.

 

I got my APs in the inside zone, and the controller is in a DMZ. Previously I had a security rule that allowed aruba-papi and syslog app and the AP connected to the controller without

...

gmunoz by L1 Bithead
  • 6285 Views
  • 3 replies
  • 0 Likes
  • 23950 Posts
  • 113 Subscriptions
Top Liked Authors
Labels