General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 3608 Views
  • 0 replies
  • 0 Likes

GP VPN causing slowness

recently pushed out always-on vpn, but one site/office is reporting slowness when connected to it. The office is a managed office, so i have no control over their internal network.

 

When VPN is disabled they are able to hit 600mb download/upload. As s

...

welly_59 by L3 Networker
  • 2681 Views
  • 3 replies
  • 0 Likes

Relevant Zone for an IP address in Vwire

Hi Experts,

 

Could you please suggest how to find Relevant Zone for an IP addresses in V Wire mode.  When configuring security policy, we need to mention the source and destination zone.

 

 We've PA firewalls only configured in Vwire with multiple zones

...

PBF not working when ECMP is configured

HI 

 

I have two internet links and configured ECMP to do load balacing based on weight,

 

Here I want to allow few users from my internal to specific desired destination based on my PBF to take my ISP2 path.

 

But it is sometimes taking ISP 1 and sometime

...

Multiple GlobalProtect Gateways on same interface?

We recently (today) configured pre-logon VPN, but have come across what could be a show stopper. As its currently configured we have configured:

 

Gateway > (gateway name) > Authentication > Certificate Profile > (a client cert signed by our infrastruc

...

welly_59 by L3 Networker
  • 6142 Views
  • 3 replies
  • 1 Likes

USERS WEB Surfing

Hello all

There is a task.The Management want to see what employers do during work time.Which sites they surf and so on

We have Palo Alto PA-850

Is it possible to show them in real time which user surfing which web site.I mean real time surfing?

I know t

...

Radmin_85 by L4 Transporter
  • 2200 Views
  • 2 replies
  • 0 Likes

Traps false positive

Hi,

 

Our traps solution is detecting malware when it shouldnt happen. This hash have been checked as benign,

 

 

Within Security Events we are repeated alerts in Malware Modules due to the protection of processes that refer to executable parents and chil

...

1.jpg
2.jpg
3.jpg
BigPalo by L4 Transporter
  • 2055 Views
  • 2 replies
  • 0 Likes

Load Config Partial for Panorama Firewall Import

If anyone used it before, can you please share “load config partial” commands to import all configuration items from saved firewall xml config (fw1.xml) file into new Panorama template (e.g. template1) and new device group (e.g. dgropup1).

I can work

...

BatD by L4 Transporter
  • 3957 Views
  • 6 replies
  • 0 Likes

Failed to add imported nodes from device to Panorama

I am trying to import firewall to Panorama using “Import named Panorama configuration snapshot” option. However when I select the device, I get the following error message, with no indication of why it is failing:

 

“Failed to add imported nodes from d

...

BatD by L4 Transporter
  • 2412 Views
  • 1 replies
  • 0 Likes

Authentication policy for RDP

I have succesfuly implemented auth policy for http and https (with decryption).

But I can't get it to work for RDP. Yes, I know I need GP client for non-browser protocols.

 

Customer is using MS MFA server. As it's not supported by PA as MFA server we c

...

santonic by L6 Presenter
  • 4209 Views
  • 2 replies
  • 0 Likes

Packet flow for Hardware Offload

Dear Experts,

 

Was wondering regarding packet flow in terms of hardware offload. Is it like below or somethingelse?

 

Ingress Stage > Session table/flow lookup> Offloaded

 

or 

 

Ingress Stage > Session table/flow lookup > App-ID/Content-ID inspection is do

...

fozail by L3 Networker
  • 4641 Views
  • 4 replies
  • 0 Likes

Resolved! panorama and user-id agent connections

Hi

 

I have a A/P clusert and I have panorama talking to it and also other PA's to distribute userid info.

 

Now I have agent configured from panorama to each of the management ports on the A/P cluster.

 

But 1 is always failing - as its the passive one,

 

I

...

Resolved! attacker and victim who is impacted?

under threat logs i see attacker and victim and also i see spyware signature

 

attacker is source -  dns server---

 

victim is --  appliance 

 

how can i verify who is impacted with this spyware?

 

Mike

MP18 by Cyber Elite
  • 3331 Views
  • 4 replies
  • 0 Likes

Resolved! Pre-Logon GP VPN

Ive read a number of guides, but for the life of me i cannot get pre-logon working. Is there an idiots guide to the required certs i need? Our clients already have a machine cert which we use for wifi authentication

welly_59 by L3 Networker
  • 2530 Views
  • 1 replies
  • 0 Likes
  • 24313 Posts
  • 122 Subscriptions
Labels