General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1812 Views
  • 0 replies
  • 0 Likes

Resolved! MineMeld can not get O 365 JSON format list

Hello

 

[Failure event]
In the case of O365 's xml format, when MineMeld received traffic after ClientHello, I got a list but if I set config for JSON support I can not get a list.

 

[Prerequisites]
MineMeld will go through Paloalto and do Internet com

...

OSPF, VPN, routing and distribution

I'm trying to solve a routing conundrum to improve a remote site and provide redundancy, and hoping others may have some solutions. The short version is that we have the remote site with basic commodity internet using VPN to connect back to two datac

...

PAN OSPF.PNG

Resolved! 802.1x wired authenicaton with MS CA and paloalto

Dear Sir,

I am beginner in 802.1x authenication and paloalto.So please help explained and guide.

I want to use 802.1x with MS CA.Can i use paloalto firewall as a policy enforcer for 802.1x authenication ?

can use PA as a radius server for user log and m

...

crypto by L2 Linker
  • 5247 Views
  • 1 replies
  • 0 Likes

Resolved! MFA "SSL Connect Error"

I am testing Multi Factor Authentication with Okta. I have configured everything (including certificate profile) as per the guide as well as Okta specific YouTube video, The first factor (active directory auth) is working fine, however, I am getting

...

Arris (AT&T Fiber) to PA-220

All,

 

I have an Arris (BGW210-700) set up as 192.168.2/24 (DHCPed) and have successfully configured the IP Passthrough to the PA-220. However, I am unable to get outbound from the PA-220. 

 

Has anyone run across this? I have the Arris going into 1/1 (a

...

ckg1999 by L1 Bithead
  • 3043 Views
  • 2 replies
  • 0 Likes

Resolved! Allow internet only after HIP fail

We are looking to configure the firewall rules where if a known user fails the HIP check, the user has access to only the internet, and not the intranet.

 

I currently have the rules configured such that failing the HIP check allows the user to access

...

mikembau by L0 Member
  • 2247 Views
  • 1 replies
  • 0 Likes

Pan-configurator predefined.xml

Hello,

 

I am using Pan-configurator to create some scripts, and i am wondering how to update predefined.xml file.

 

Can we update this file manually or automatically?

 

Kind regards.

Resolved! Hardware Requirements to PA - 5050

 

Hi, i need Hardware Capabilities ( type of Cable, Chassis Height , Data Ports , managment ports ... ) of Palo alto PA-5050 to install in Data center of our customer in cluster with two WLC.

 

Thanks,

RosVerde by L0 Member
  • 2747 Views
  • 2 replies
  • 0 Likes

IP pool problem

Hello,

I have an IP pool for GP users  and IP are no being clearing when users disconnect the VPN, to clear this IPs we have to reboot the FW,

Is there other way to clear this addres ? 

this must be cleared automatically after disconnect?

 

Regards

 

Marivi by L2 Linker
  • 6295 Views
  • 9 replies
  • 0 Likes

Resolved! AWS Multi-VPN Tunnel with Palo Alto NGFW - Flow Issue

My PA NGFW managed to setup VPN tunnels with AWS VGW. AWS given 2 sets of VGW where each of the VGW comes with 2 links that will connect to NGFW 2 ISP link respectively with different set of public IP Address.. Below are the setup flow:

NGFW ISP1 -> A...

Resolved! Migrate config from Panorama template to local device

Just getting my head around the ins and outs of Palos, and some initial lab setup we had leveraged a couple of PA-220s and a virtual instance of Panorama. 

 

Using that config, I'm building a standalone PA-220 and want to recycle the bulk of the config

...

cdawson by L0 Member
  • 3127 Views
  • 2 replies
  • 0 Likes

CRL revocation traffic identified as ms-update

Is this an expected behaviour? We where somewhat surprised that the application included this traffic. It includes all SSL CRL traffic (like establishing remote desktop or visiting websites), independent if its related to Windows Update.

Resolved! PA220 as a router?

Hi,

We are planning to have paloalto PA220 firewall in our new sites and instead of purchasing new cisco routers (ISR 4000 series), we will just use the PA220 as a router.

Our link is via ipvpn (not IPSec) with GRE tunneling. And we will be using EIGRP

...

bentot by L0 Member
  • 3815 Views
  • 2 replies
  • 0 Likes
  • 24241 Posts
  • 117 Subscriptions
Top Solution Authors
Top Liked Authors
Labels