General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1735 Views
  • 0 replies
  • 0 Likes

Resolved! how interpret MAC in pcap

Hello,

I have a doubt about how to interpret macs in rx pcap and tx pcap. I thought that:
when the traffic enter a layer 3 interface:

the mac destination addres in rx file must be the mac of  ingress interface?
and in tx the source mac, must be the mac o

...

Marivi by L2 Linker
  • 4108 Views
  • 2 replies
  • 0 Likes

Management CPU Utilization is 100%

Our PA-500 management utlization reaches 100% sometimes...according to PA support, There's a process called 'gdindex.sh' runs every 15 minutes for log indexing.

We need to reduce the management plane traffic for better performance. Any suggestions?

Can I block IP immediately using EBL?

Hello

 

I am using the Palo Alto Next Generation Firewall PA-3020 / PAN OS 7.02.

 

I use EBL to block IP.

 

After testing, it will take a long time for IP registered in the text file to be applied to the firewall.

 

Of course, i set "repeat" to 5 minutes in

...

ragonfly by L0 Member
  • 1775 Views
  • 1 replies
  • 0 Likes

Resolved! youtube application

Hello I have a doubt about applications:

If I search in my palo alto object>applications    search: youtube I obtain next output

I can add to a policy rule youtube but when I open I found that

 

don't have dependency, and implicitly application uses.

I s

...

youtube.JPG
youtube 2.JPG
Marivi by L2 Linker
  • 4436 Views
  • 3 replies
  • 1 Likes

Resolved! Split-Brain Enable HA Config Change

We are setup as active/passive and have intentionally caused a split-brain with our firewalls (5050's) by removing one from vwire mode and removing all cables except mgmt port to perform some migration activities.  We left the "Enable HA" checked on

...

Resolved! 3200 and 5200 Series New Interface Types

Can you please help us with the new 3200 and 5200 interface types, because it is not very clear in the hardware documentation?

 

  • The firewalls now have HA1 and HA1-Backup dedicated ports. The 5200 also have AUX-1 and AUX-2. Can we still use any other d
...

BatD by L4 Transporter
  • 2486 Views
  • 1 replies
  • 0 Likes

Resolved! Problem of PA-220 behind another router

Got a PA-220 to test.

Want to setup something like below:

Internet <-> Juniper SSG-140 (GW:192.168.1.1) <-> PA-220 <-> user's device (172.16.1.0/24)

 

1. The SSG-140 can reach internet

2. The PA-220 external port (192.168.1.100) can reach internet too

3. T

...

jeremylo by L3 Networker
  • 2373 Views
  • 2 replies
  • 0 Likes

Resolved! [Minemeld 0.9.48] - Some prototypes not available in the GUI

Hello team!

 

I hope you are doing alright !

 

It looks like that since the last update (0.9.48), I am no longer able to setup new nodes with the prototypes:

 

stdlib.localDB

OR

stdlib.aggregatorIPv4Inbound

 

Moreover,  a couple of my miners/nodes no

...

camsad by L1 Bithead
  • 7198 Views
  • 11 replies
  • 0 Likes

Resolved! PA-3260 hardware specification

Hi All,

 

Does anybody know what CPUs are used and how many ram is installed for PA-3260?

Our potential customer wants the hardware specification including CPU/RAM information but I cannot find those information. What I only found is following which onl

...

Resolved! GlobalProtect Access Route for a public website?

Hi folks,

 

We are using a PA 3020 PANOS 7.1.14.

 

We have entered all public IP addresses for Okta in our Global Protect Gateway Client Access route settings.

Our intention is for Okta to only see client IP requests come from our one corporate public IP

...

OMatlock by L4 Transporter
  • 4726 Views
  • 5 replies
  • 0 Likes

Resolved! How to disable Global Protect inside Firewall

Hi All,

I am looking for a way to have the GP client client NOT connect when I am inside the firewall of at a remote site with a VPN tunnel.  Basically I would like to make a rule that says do not connect when connected to certain subnets.

Is there a w

...

Ignoring Users in Mapping

Howdy,

 

Sorry if this has been asked thousands of times, but I cannot seem to locate something quite similiar.

 

We have noticed recently, that some users are logging in with a local computer account and then obviously being able to browse the internet

...

PIRSA by L0 Member
  • 2396 Views
  • 2 replies
  • 0 Likes
  • 24225 Posts
  • 117 Subscriptions
Top Liked Authors
Labels