General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4112 Views
  • 0 replies
  • 0 Likes

Resolved! Replace passive member in HA (A/P)

Hi, We need to replace the passive member in a cluster. So in the HA preempt is not enabled. And priority in the active member is 100. So i understand that we can directly connect all the cables for new devices and this new member will take passive role since there isnt preempt enable, right???should i connect first of all HA cables in order to ...

BigPalo by L4 Transporter
  • 2887 Views
  • 1 replies
  • 0 Likes

Stuck in Failsafe Bootloader. what now?

My PA-820 is stuck in failsafe bootloader mode. what are my options now? I am no longer getting the option for MAINT mode either. If I let the system boot on it's own I get the below and it just keeps rebooting. Welcome to the PanOS Failsafe Bootloader.U-Boot 8.0.6.0-29 (Build time: Oct 13 2017 - 12:13:40)Octeon unique ID: 044000214719f31e0...

GPL-DDay by L0 Member
  • 8932 Views
  • 4 replies
  • 0 Likes

Resolved! No source user in logs post 8.1.2 upgrade

At the weekend I upgraded all our boxes from 8.0.9 to 8.1.2 as we need to make use of the new GP - Split Tunnel by URL features & Enhanced UserId coolness. Yes, I know - this was brave 🙂 Everything seems to be working as expected & as it was pre-upgrade with the exception of logging, where we no longer get the SourceUser in the logs for...

SimmSimm by L2 Linker
  • 3958 Views
  • 2 replies
  • 0 Likes

Asymmetric routing with the same interface

I have to deploy the WAN firewall which have 2 WAN link. The requirement was egress traffic from the firewall to WAN will be send to Link A but the response traffic will be ingress from the Link B. If I've set both of these interface in the same zone, untrust zone, does the firewall will be dropped because of asymmetric routing?? Or firewall wii...

Site to site VPN help :(

Unable to make VPN work. Both "IKE Info" and "Tunnel Info" are red light in IPSec Tunnel.The peer is a Juniper vSRX.Normal configuration with trust, untrust and VPN zone in both firewall. Each zone has its own subnet.Both firewall can ping each other untrust interface.Workstations behind the firewalls can ping firewall's untrust interface too (d...

jeremylo by L3 Networker
  • 8148 Views
  • 5 replies
  • 0 Likes

VM-Series firewall on VirtualBox

Hi,I know that VM-Series firewall requires VMware ESXi running vSphere 4.1 or 5.0.But I don't have VMware right now on my laptop and only I have is Oracle VirtualBox 4.2.6 - just for tests and presentations (not for commercial purpose)On VirtualBox I've already imported vmdk file but when I launch PA-VM I see: 'Welcome to the PanOS Bootloader. ...

Clientless VPN

Hi All, can someone provide configuration example for Clientless VPN access through GP portal...I was already used configuration steps explained on this page, but seem that it not helped in my case. I'm able to authenticate and open portal landing page with published app, but there is no response of it. I'm pretty sure that all steps of configur...

Tician by L3 Networker
  • 6497 Views
  • 5 replies
  • 1 Likes

Dynamic Routing on MPLS network with IPSEC VPN as backup route

We are new to the Palo Alto community and are looking for some advice as the best way to accomplish our networking end-goal. We have several remote offices that are currently connected to corporate using an IPSEC VPN over the internet. Each site has a PAN device. We are looking to add an MPLS network to act as the primary route between each ...

Delete inherited zones

Hello, I'm creating locally a lot of new zones on a 3020 firewall, but committing it says the hardware limit is 40.Currently I inherit 9 zones from a Global Template from Panorama, but I don't need that zones.I cannot modify the Global Template. There's a way I can simply delete the zones from the local firewall?If I select a zone, the delete bu...

Application match... Sophos-live-protection to 8.8.8.8

Our logs show a numebr of connections from our DC's to port "53" application sophos-live-protection... That's fair enough, I understand the concept of what sophos are tryign to do with this. What I don't understand is why the destination is 8.8.8.8 and not one of the sophos listening addresses... I don't suppose anyone sees this? Rob

Resolved! Create VPN Profile or Group for a vendor to access specific internal server

Hello all, We snagged a PA820 to replace an old ASA 5510. I think I have everything set and I am almost ready to cut over to the new PA firewall, with one exception: I am drawing a blank on the best way to setup VPN access for a support vendor. With our current Cisco solution, the vendor starts up Cisco AnyConnect, and selects a group from a dr...

colesch by L2 Linker
  • 11069 Views
  • 8 replies
  • 0 Likes

mgmtsrvr - virtual memory limit exceeded, restarting

Has anyone seen this before? I'm looking for feedback on whether or not this is directly related to the VM Panorama sits on? This was the decription of an alert I received at 12:30EST today. Sure enough, Pano was rebooting. Any information provided is greatly appreciated!Thanks,Erich

ejm by Not applicable
  • 9126 Views
  • 4 replies
  • 0 Likes

Resolved! Dynamic Destination Routing

Hello All,i have a senarion in which a user vlan routed to internet link1 thorugh policy baseed routing now i have a one destination which has dymaic IPs and only can open with internet link 2 i want this destinatioon to be opend for the user vlan, how can i achieve this?

FShabbir by L1 Bithead
  • 4305 Views
  • 5 replies
  • 0 Likes

Email attachment

Hi EveryOne How i can block the email attachment (RAR ,EXE) file What the proper way to check to fake email are incoming in a local network

MFayez by L2 Linker
  • 2009 Views
  • 1 replies
  • 0 Likes

Resolved! unknown-tcp when tls decryption is enabled

I have a VM-100 in my lab. I haven't used it in while but recently booted it up and upgraded to 8.0.12. I noticed a lot of unknown-tcp traffic for mostly any site when I enabled tls decryption. If i disabled tls decryption, the traffic is all ssl. I have never seen this before. I'm running it on esxi 5.5

ce1028 by L4 Transporter
  • 3408 Views
  • 2 replies
  • 0 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels