General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 330 Views
  • 0 replies
  • 2 Likes

EDLs

Can we group EDLs?

Once the url is fetched and content is read by the firewall and later the url is deleted, does firewall keep the cache of contents?

can firewall detect redundant entries?

Manage client SSL VPN use

Hi PAN Community,

 

I work for a school and we have issues with student VPN use - specifically x-vpn, hotspot shield etc. We have rules in place that take care of the proxies and standard VPN applications and have SSL decryption and URL blocks in place

...

New VM-100 throws error at commit

Hi

We have imported a config from a PA500 into a newly installed VM-100 v8.1 (under vmware).  After having done some VLAN changes to interfaces, we suddenly started to get the below error message when committing:

 

 

Can someone point us in the correct d

...

Commit.jpg

Resolved! content update

I have this question and cannot find the answer from the online training:

 

Which type of content update does NOT have to be scheduled for download on the firewall?

 

I think it is PAN-DB updates but I just need to make sure.

Resolved! Where do you track your certification progress?

Hi all,

 

I thought you'd want to be able to list your certifications and their expiry dates and any relevant announcements, so you could plan your further study, re-certification...

Also, employers ask about cert updates.

Couldn't find it myself.

Other t

...

GAleksic by L1 Bithead
  • 3496 Views
  • 3 replies
  • 0 Likes

Resolved! To drop or deny

I found some best practices documentation on the fuel group site and they recommend drop over deny.  So I would be interested to see how people are configuring their fire wall more drops or denies and why?

jdprovine by L4 Transporter
  • 38663 Views
  • 6 replies
  • 1 Likes

MAC OS Decryption Issues

Hello All,

 

I was just curious if anyone has encountered issues with Apple Mac devices and SSL decryption? We have users that are unable to perform an Internet Recovery over the network, but when they are off the network it works for them. This has on

...

Resolved! How to manage 140+ Firewalls with their certificates...

Hello Community,

 

I was wondering how in a "larger scale" environement (140+ branche offices) people are generally managing their certificates?

  • Take the scenario of Panorama managing thoses 140+ PA firewalls with their corresponding 140+ templates...
  • Th
...

Rievax by L2 Linker
  • 3207 Views
  • 5 replies
  • 0 Likes

Dual ISP scenario

Hi,

 

I need to create a dual ISP scenario. This FW has 2 interface with differents ISP. (ppoe)

eth1/2 (1.1.1.1/32)

eth1/3 (2.2.2.2/32)

 

We would like to balance both ISPs and in the case one of this ISP goes down, all traffic takes the ISP up in that mom

...

Config, System, Supervisor timing out

I cloned few output prototypes and created my own miner -> ipv4 agg -> output config. I logged off for some reason and now that I login, I am getting timeout error for config, system, supervisor etc. I dont see any config info or indicaters in System

...

Doubt about 8.1 version source-user logs

Hi,

 

I just upgraded my firewall to 8.1.0. I was checking the log and i see that now the "source user" in log traffic is the full name machine with $, not the AD user. 

Before 8.1 was: domain/john.english

Now is: xxxx.dom\PCfullname$

 

Why??? how can we c

...

Resolved! autocommit fail : Total NAT DIPP exceed

Hi all, I found the issue after upgrade Palo alto from PAN-OS 5.0-6.1.0  when to 6.1.0 auto-commit faile and show messages "Total NAT DIPP translated IP 804 exceeds the capacity of 800 " My model PA-5050 so, I would like to know this issue occur? 

  • 23670 Posts
  • 108 Subscriptions
Top Liked Authors
Labels