General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1250 Views
  • 0 replies
  • 0 Likes

Query on HA pair upgrade

Hello,

 

We are using PAN-OS 7.0.2 which is end of life and wanting to upgrade to 7.1.17.
 
Can we upgrade one firewall through all the versions 7.0.2-->7.0.19-->7.1.0-->7.1.17 before moving on to another in the pair or do we have to bring both firewalls
...

Farzana by L4 Transporter
  • 3125 Views
  • 4 replies
  • 0 Likes

Miner shows 422 Unprocessable Entity

 

 

 

 

Hi,  I am trying to configure a miner that downlods a stream of IP addresses via HTTPS request.  Data stream looks like this

1.1.1.1

2.2.2.2

2.2.2.3

3.3.3.3

etc.

 

I created the following protype

 

NSFOCUS_ip-v2: class: minemeld.ft.http.HttpFT ...

otto38dd by L0 Member
  • 4118 Views
  • 3 replies
  • 0 Likes

SSL Decryption breaks certain website functionality

So I’ve enabled SSL decryption and as expected some sites or applications fail when it’s turned on. No problem I can exclude the domain from decryption.

I have a special case though, in the fact that one of these web applications is a service that my ...

welly_59 by L3 Networker
  • 4860 Views
  • 3 replies
  • 0 Likes

Resolved! Route specific traffic out backup ISP?

We have dual ISP (ISP-A and ISP-B) and utilizting PBR which works just fine.  Now I have use case whereas I have a NAT configured on ISP-B (1 to 1) and I want to force traffic to a specific destination out the backup interface.  I want to do this to

...

drewdown by L4 Transporter
  • 12636 Views
  • 13 replies
  • 0 Likes

Resolved! Upgrading GlobalProtect while on corp network

Hi everyone,

 

I have a client who said every time they try to upgrade globalprotect, they have mixed results. The issue seems to be that they'll set the GP App to "Allow with prompt". However, the users will never get the prompt while they are on the

...

ce1028 by L4 Transporter
  • 5209 Views
  • 9 replies
  • 0 Likes

Resolved! Adding app depencendies

This might be a dumb question, but I visited 3 clients in the past 2 weeks that did not include application depenendcies in their policy rules

 

For example, they'll have a rule allowing webex-base, but don't add rtcp, rtp-base, or stun.  To be fair, a

...

ce1028 by L4 Transporter
  • 2703 Views
  • 2 replies
  • 0 Likes

SSL Version

Is there any way for the traffic logs to display the SSL/TLS version that's in use for a particular flow? I don't see the data in the traffic logs or in the session info at the CLI.

Resolved! HTTPS URL Filtering without decryption

Hello all,

 

I am trying to implement URL Filtering for HTTPS websites but without decryption. I found a post on how to deliver response pages to Users. (https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Serve-a-URL-Response-Page-Over-

...

Resolved! Untrust to Untrust - Allow

I was working at a customer site and noticed the customer's last rule before their "Catch-All - Deny" rule was  "Untrust - Untrust Allow". It was a universal rule with source zone untrust  destination zone untrust set to allow. When I asked why they

...

ce1028 by L4 Transporter
  • 15338 Views
  • 11 replies
  • 0 Likes

Binding to AD with globalprotect

We have user accessing the globalprotect VPN using their AD account and we have userid enabled, but we do not see any evidence of the users in the AD domain controller, is that because GP is accessing the DC using a service account? Is there anyway t

...

jdprovine by L4 Transporter
  • 6257 Views
  • 13 replies
  • 0 Likes

Dual ISP IPSEC vpn tunnel monitor drops the connection

Hi all,

 

I added second ISP to firewall and created ECMP for dual ISP followed those guides:

 

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Implement-ECMP-Load-Balancing-on-the-Firewall/ta-p/110339#

 

https://live.paloaltonetworks.co

...

SShnap by L3 Networker
  • 3596 Views
  • 3 replies
  • 0 Likes

GRE support on PAN-OS 8.0

Hi,

is it possible to terminate a GRE tunnel on a PaloAlto? Parhaps there is something new in 8.0

 

Best regrads,

Sebastian

sst by L0 Member
  • 5143 Views
  • 5 replies
  • 0 Likes

Resolved! Log forwarding - Local on Gateway or Panorama

Hello - I have Firewalls configured with Log Forwarding to Panorama. The question is, do the traffic logs of the Firewall Gateway keeps the copy of the logs and send another copy to Panorama or does it have only one copy forwarded to Panorama

 

Can i c

...

  • 24175 Posts
  • 117 Subscriptions
Top Solution Authors
Top Liked Authors
Labels