General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 198 Views
  • 0 replies
  • 0 Likes

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 880 Views
  • 0 replies
  • 0 Likes

FTP Data Transfer very slow through Palo Alto

Dears

 

I created Local ftp over Tls through Palo alto . I published this server and create both nat rule and security policy rule and i am connecting from internet using filezilla but the transfer rate is very slow 25KB/Sec . I have dedicated leased l

...

How to configure QoS with a limit per user

I am looking to configure our Palo Alto firewall to limit every user on our network (approx 5,000) to 10Mbs or less. I have a 1Gbit pipe. The documentation I have seen so far has shown how to do this for 1 person.

 

How do I set it up so that 1 rule co

...

ggranular sharepoint filtering

I am trying to implement granular url filtering within sharepoint site but firewall is considering it as a generic. Eg: https://xyz.sharepoint.com/pages/department/* is the url I want to allow and block rest of sharepoint. Whenever I try this link,Fi

...

DMZ with multiple VLANs, multiple Zones?

If you have a DMZ behind the Palo and it contains multiple VLANs or sub-interfaces, would you create multiple Zones(one for each VLAN)? Or create a single "DMZ" zone and apply that to all of the VLANs?

jambulo by L4 Transporter
  • 4616 Views
  • 4 replies
  • 0 Likes

Disk quotas can not be computed due to disk

Hello Team,

We have seen in the PA 5200 series that the following log appears: "Disk quotas can not be computed due to disk" It appears just after the boot in the system logs. Have you ever seen this log? What it means? Is dangerous for the firewall?

P

...

ccoquis by L0 Member
  • 3117 Views
  • 3 replies
  • 0 Likes

Resolved! Upgrade PAN500 from 7.0.2 to 8.0

HI All

 

I am wanting to upgrade the PAN 500 currently on 7.0.2 to 8.0

 

Is there a good read what major release version I have to follow to do the step upgrade?

 

What major release i have to follow if anyone can guide me.

 

Regards

R_Sharma by L2 Linker
  • 4934 Views
  • 6 replies
  • 0 Likes

Resolved! Blank GUI Logs

Hello,

I'm running Minemeld 0.9.46 on RHEL 7.4 installed via Ansible.  Everything appears to be working correctly except I'm not seeing any logs in the Logs tab or the logs page of each individual node.  
I am getting updated statistics for each for ea

...

jt1025 by L2 Linker
  • 3171 Views
  • 1 replies
  • 0 Likes

Resolved! Blocking Access for a User in a Specific AD Group

So I'm looking for the best way to block a user in a specific AD group but get them a response page while I do it.  These users are going to be students who violated network policy and are being blocked to everything except some of the educational/ho

...

jsalmans by L4 Transporter
  • 6990 Views
  • 10 replies
  • 0 Likes

Resolved! DHCP lease assignment order

While configuring the PAN firewall as a DHCP server, is it possible to assign lease to a client starting from the highest to the lowest range? Meaning if the DHCP range for the subnet 10.10.10.0/24, is from (10.10.10.100-10.10.10.254), can the lease

...

Birajan by L1 Bithead
  • 2427 Views
  • 2 replies
  • 0 Likes

ACC - session number meaning

Hi,

  Does anyone know what exactly session number indicates under ACC? For example, we have a specific app

which has constantly around 250K sessions on the firewall. However when I click ACC and set time as "last 15 minutes"

for this specific APP, I se

...

Resolved! SSL Decryption & URL Filtering License

Hi All,

To enable SSL Decryption  and to make use of URL categories to allow or block traffic based on the URL categoy , does URL filreting license is required or SSL Decryption can be used fully without URL filtering.


Regards
Sam

snasheet by L0 Member
  • 4950 Views
  • 3 replies
  • 0 Likes

so TLS 1.3 got IETF branded

hey there,

 

since tls 1.3 is now a ietf standard, is there any use running ssl-decryption in the close future?

as far i understand 1.3 documents, it "looks like" 1.2 for the firewall, so there's no way to just block 1.3 and force both parties to downgr

...

ADK999 by L1 Bithead
  • 7002 Views
  • 6 replies
  • 0 Likes

Resolved! HA Active/Passive MAC address

Hello - In PaloAlto 5220 appliance configured in Active/Passive mode, both the Firewalls do have the same MAC address on interfaces. For example ETH 1/1 of active and standby Firewall have the same MAC address after cluster/HA was created.

 

These the

...

  • 24013 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Authors
Labels