General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 194 Views
  • 0 replies
  • 0 Likes

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 876 Views
  • 0 replies
  • 0 Likes

Resolved! MFA "SSL Connect Error"

I am testing Multi Factor Authentication with Okta. I have configured everything (including certificate profile) as per the guide as well as Okta specific YouTube video, The first factor (active directory auth) is working fine, however, I am getting

...

Arris (AT&T Fiber) to PA-220

All,

 

I have an Arris (BGW210-700) set up as 192.168.2/24 (DHCPed) and have successfully configured the IP Passthrough to the PA-220. However, I am unable to get outbound from the PA-220. 

 

Has anyone run across this? I have the Arris going into 1/1 (a

...

ckg1999 by L1 Bithead
  • 2807 Views
  • 2 replies
  • 0 Likes

Resolved! Allow internet only after HIP fail

We are looking to configure the firewall rules where if a known user fails the HIP check, the user has access to only the internet, and not the intranet.

 

I currently have the rules configured such that failing the HIP check allows the user to access

...

mikembau by L0 Member
  • 2078 Views
  • 1 replies
  • 0 Likes

Pan-configurator predefined.xml

Hello,

 

I am using Pan-configurator to create some scripts, and i am wondering how to update predefined.xml file.

 

Can we update this file manually or automatically?

 

Kind regards.

Resolved! Hardware Requirements to PA - 5050

 

Hi, i need Hardware Capabilities ( type of Cable, Chassis Height , Data Ports , managment ports ... ) of Palo alto PA-5050 to install in Data center of our customer in cluster with two WLC.

 

Thanks,

RosVerde by L0 Member
  • 2516 Views
  • 2 replies
  • 0 Likes

IP pool problem

Hello,

I have an IP pool for GP users  and IP are no being clearing when users disconnect the VPN, to clear this IPs we have to reboot the FW,

Is there other way to clear this addres ? 

this must be cleared automatically after disconnect?

 

Regards

 

Marivi by L2 Linker
  • 5903 Views
  • 9 replies
  • 0 Likes

Resolved! AWS Multi-VPN Tunnel with Palo Alto NGFW - Flow Issue

My PA NGFW managed to setup VPN tunnels with AWS VGW. AWS given 2 sets of VGW where each of the VGW comes with 2 links that will connect to NGFW 2 ISP link respectively with different set of public IP Address.. Below are the setup flow:

NGFW ISP1 -> A...

Resolved! Migrate config from Panorama template to local device

Just getting my head around the ins and outs of Palos, and some initial lab setup we had leveraged a couple of PA-220s and a virtual instance of Panorama. 

 

Using that config, I'm building a standalone PA-220 and want to recycle the bulk of the config

...

cdawson by L0 Member
  • 2777 Views
  • 2 replies
  • 0 Likes

CRL revocation traffic identified as ms-update

Is this an expected behaviour? We where somewhat surprised that the application included this traffic. It includes all SSL CRL traffic (like establishing remote desktop or visiting websites), independent if its related to Windows Update.

Resolved! PA220 as a router?

Hi,

We are planning to have paloalto PA220 firewall in our new sites and instead of purchasing new cisco routers (ISR 4000 series), we will just use the PA220 as a router.

Our link is via ipvpn (not IPSec) with GRE tunneling. And we will be using EIGRP

...

bentot by L0 Member
  • 3419 Views
  • 2 replies
  • 0 Likes

IPSEC VPN IKE Phase 1 Goes down after couple of hours

Hi Guys,

 

Got a quick query. We have implemetmented new pa 3050 firewall in our perimeter. Two IPSEC vpns configured and working fine. We notice, after couple of hours, the Status of first led goes red. but, the second status led stays green. During t

...

irshad.n by L1 Bithead
  • 4930 Views
  • 3 replies
  • 0 Likes

Decryption with Wildcard SSL-certificate?

Does Palo Alto support decryption with Wildcard SSL-cert?

Ref.:
In order to determine if a connection needs to be decrypted or not, the firewall relies on the (CN) common name configured within the certificate and compares that to the security policy.

...

pivvre by L2 Linker
  • 10176 Views
  • 12 replies
  • 0 Likes

Global Protect Auto Start

We are looking into adding Global Protect as part of our deployment of newly reimaged computers. Within my company's work environment, we want Global Protect to start up only when the user clicks on the shortcut icon for the application. We do not wa

...

  • 24011 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Posts
Top Liked Authors
Labels