General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4120 Views
  • 0 replies
  • 0 Likes

Resolved! Application vs Service in PA

Hi Experts, I've query in Application vs Service columns. As we all know the Palo Alto preferred method is to use Application column (SSL, Web-browsing) and refer to 'Application default' in Service. My query is, if we mark 'ANY' in Service column and filter the ports in Application column (SSL, Web-browsing) will PA firewall stop further proc...

PA1.JPG

QoS for VOIP over IPSEC VPN

Hi All I have four VPN sites and HQ with VOIP deployed. On HQ Palo Alto, I want if traffic come from LAN with some marking like 'af41' then give priority (real time) and copy the dscp marking when send across IPSEC VPN? -> For this, I have made one qos profile say 'vpn_profile_voip' with class '2' and assign priority 'real time'-> Then app...

Resolved! PA-3060 Whats Up Gold (WUG) Integration: Auto Link Creation Fails

I have a PA-3060 connected to a Cisco 3850 S-E via a 4-member aggregated dot1q trunk (ae1) link. The MGT interface connects to a different 3850 S-E on its own Mgmt VLAN, in the same subnet as the Whats Up Gold Server (WUG). The MGT interface has HTTP, SSH, Ping and SNMP Services enabled, with the correct permitted IP address list. The WUG Serv...

DeanFarr by L1 Bithead
  • 10083 Views
  • 5 replies
  • 0 Likes

Dynamic 1:1 NAT on the Palo Alto interface.

We are looking at some method where we can dynamically NAT subnets behind the Palo Alto Firewall to pick an IP address from the network defined on the external interface. e.g. I have the external IP address network defined as 10.100.100.0 /24. The IP address 10.100.100.20 is defined as the IP of the external interface. In the internal network we...

nson2139 by L3 Networker
  • 3332 Views
  • 2 replies
  • 0 Likes

Issue Static Source NAT

Hi Expert , I have some issue about Static NAT due to I have secondary public ip on the same interface such as on ethernet 1/3 have 192.168.1.22/24 and 192.168.55.1/32 and config nat bi-direction such as source trust > 172.16.1.22 to untrust and Source nat ip 192.168.55.2 to untust and try to use and I have observed on traffic log found na...

Resolved! how to whitelist an URL with a wildcard in the name ?

I'v got a question about whilesiting URL's I want to whitlist the following URL, github-production-user-asset-*.s3.amazonaws.com.but, it's only possible to use a wildcard to replace full hostname spaces of the URL ( like *.s3.amazonaws.com ) how do I solve this ?

DaxVC by L2 Linker
  • 3946 Views
  • 1 replies
  • 0 Likes

Minemeld install error on RHEL

I am attempted to perform an ansible install of Minemeld on RHEL 7. I am receiving the following error. Anyone seen this and have any suggestions for remediation? Thanks I receive the following message when I run the ansible playbook: TASK [minemeld : bower install] ***************************************************************************...

taustin by L1 Bithead
  • 3437 Views
  • 2 replies
  • 0 Likes

invalid interface

hello have getting a lot of 802.1q tag not configured and invalid interface message in global counters. I'm trying to find the cause, I have configured subinterfaces I see traffic in rx.pcap with properly tag, all traffic is dropped, I see as destination mac addres of the fisical interface when I have configured subinterfaces, could someone help...

Marivi by L2 Linker
  • 8915 Views
  • 8 replies
  • 0 Likes

Feature Request - Reporting

I just spoke to Jim Silha about reporting. Palo Alto comes with a user activity report. Under the section 'Browing Summary by Website' there is a 'Host' column. It is much more report friendly than say 'URL'. I would like to be able to use that in my custom reports but was unable to find that under the 'Available Columns' for any of the logs....

HA Active/Active and VPN

Hello, We have a scenario where a customer wants to deploy two PA3250s in two different locations which will be an Active/Active cluster. There will be a layer 2 link between the two sites and also customer wants a VPN as a backup if the layer 2 link goes down. Is this possible? How can we implement this if possible? Thanks.

sajidsil by L0 Member
  • 3973 Views
  • 3 replies
  • 0 Likes

LDAP interval

Hi,I have a question in reference to the LDAP interval time. Specifically what my goal is I want to be able to let the firewall know about my AD group membership changes quicker. For example if I have a specific AD group that is configured on the fw to control a specific PBF rule, when I add or remove a domain account from that AD group, what is...

Resolved! URL domain reports

Hello,I'd like to produce URL reports. I noticed that you can get report on the comlete URL but not based on the URL domain.i.e i get entry for www.pippo.com/cpp/layout.css and another entry for www.pippo.com/img/pippo.jpg and for report purpose is only www.pippo.com that is relevant for me ...That seams for me relatively usefull ..... Is possib...

Resolved! Meaning of different Interface states

I have scourred everywhere...... What are the differences between the interface states? I can't find anything anywhere!! ukn/ukn/down(power-down)disabled/downforced/uknforced/down If there are others I have missed, I'd love to be enlightened.

  • 24336 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels