General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1826 Views
  • 0 replies
  • 0 Likes

Resolved! Use Domain EDL for purposes other than DNS sinkholing?

 Can you use a domain EDL for other purposes or only for DNS sinkholing?

 

In other words, can you use a domain EDL in any policy rule in the same way an FQDN object can be used?

 

I would expect that you can, but wanted to ask.

RISI by L2 Linker
  • 4071 Views
  • 4 replies
  • 0 Likes

Linux and TCP keepalive

Hi

 

Is there some reason that PA have a 1 hour keepalive value, where linux has a 2 hour timeout value.

 

Whats considered best practices ... reset the PA to 2 hours or bring down the linux keepalive value to say 1800

 

A

Resolved! No devices in deploy content window

I am having a problem trying to push Apps&Threats or AV from the panorama to the firewalls. We have a Panorama M100 at 8.0.5 (recently upgraded from 6.1.10) with 5020 FW's at same release. We are NOT able to do the reachback to Palo Alto servers sinc

...

Trouble installing manually or from ISO on ESX

Have followed all the articles I can find.  Trying the ISO, I can login and basically gets stuck right after login at "initializing minemeld, this can take some minutes......", and left it for minutes/hours/days, just never finishes.  Tried canceling

...

Spetka by L1 Bithead
  • 7713 Views
  • 7 replies
  • 0 Likes

Palo Alto firewall does not display traffic log

I've just installed Palo Alto firewall VM version in virtual box.

I was able to access it via WEB (https) and SSH.

However, when I check traffic log it was empty.

 

 

I generated a few traffic such as ping and nmap scan against firewall IP, but still no t

...

PA traffic log.jpg
prenatip by L1 Bithead
  • 7248 Views
  • 7 replies
  • 0 Likes

Intermittent firewall/application issue

Hello,

 

I apologized if i posted i the wrong area.  To start off with, we just got our PA-820 recently.  We have a weird issue, where one day an application will work without problems and another day the Instant Messaging part of the app fails to conn

...

Exporting Application Groups

Is there a way of exporting Application groups from one Panorama and importing to a different Panorama? I am trying to move my groups over for a GPCS POC.

 

NOTE: GlobalProtect Cloud Service has changed to Prisma Access.

kamorris by L1 Bithead
  • 3856 Views
  • 2 replies
  • 0 Likes

IPSec Tunnel Question

I have a IPSec tunnel up where the Peer IP is the same as the Remote IP (Proxy ID - Remote).  The Tunnel is up, but traffic destined for that Remote IP isn't traversing the tunnel.  Typically, there is a Private IP as the Remote and a static route co

...

Packet flow not properly defined

Hi Team,

 

i have seen two diagrams of packet flow from palo alto website. in Below NAT Policy evaluated is shown in first step. which is part of Network processor (slow path) and NAT applied after  Application  and security Policy it means from securi

...

PA Small PF.PNG
PA large PF.jpg
ss198939 by L1 Bithead
  • 3583 Views
  • 3 replies
  • 0 Likes

Agentless vs Agent based User-ID

Hello,

 

We have 500 users on site and currently using Agentless User-ID with PANOS 7.1.7

 

We are thinking of scaling up to Agent based. 

 

Can someone please guide me to a link/article that discusses the Pros and Cons of both? 

What are the common issues

...

Farzana by L4 Transporter
  • 6339 Views
  • 5 replies
  • 0 Likes

MineMeld engine:fatal message

I'm getting the below message in my minemeld logs and not sure what is causing it  

 

2018-07-11T00:30:28 (16652)config._destroy_old_nodes INFO: Destroyed nodes: [_ConfigChange(nodename=u'Amazon_IPv4_Agg_General', nodeclass=u'minemeld.ft.ipop.Aggrega

...

  • 24246 Posts
  • 117 Subscriptions
Top Solution Authors
Top Liked Authors
Labels