General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4246 Views
  • 0 replies
  • 0 Likes

Office 365 access issue

Hi Guys, we have a problem: if a pc is in the lan, behind the firewall, we are not able to log in to office365, but if we use an external connection it works.i don't see any log with application containing 'office'We have not decryption enabled, PA-3020 with 7.1.14 Do you have any hint?Regards,Daniele

DKanta by L2 Linker
  • 3566 Views
  • 3 replies
  • 0 Likes

Resolved! User-ID Agent installed on Domain Controller doesn't appear to be collecting event logs

Hi guys, I've installed the Palo User-ID agent on a single domain controller (8.0.906) using the Palo Networks guide below: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/user-id/map-ip-addresses-to-users/configure-user-mapping-using-the-windows-user-id-agent/install-the-windows-based-user-id-agent Our environment already has Us...

Palo Alto 5250 - Configuring HA between vsys

Hi, Is it possible to configure two physical Palo Alto 5250 in Active - standby mode while distributing the load for Vsys across both the physical firewalls. For eg.I have two physical firewalls - PA1 & PA2I have 6 vsys in each firewalls - Vsys1, Vsys2, Vsys3, Vsys4, Vsys5, Vsys6 Is it possible to have the below mentioned setup? PA1Vsys1 -...

MGRashmi by L2 Linker
  • 6169 Views
  • 2 replies
  • 0 Likes

ECMP Config for 2 Internet links Site (Dual ISP)

Hello Everyone! Site with 2 X PA500 in HA2 Internet LinksPANOS 7.1.16ISP1 - 187.190.74.22 (internet dedicated)ISP2 - 192.168.0.66 (DSL link) Config doneVirtual Router 1 - RT-LANVirtual Router 2 - RT-WAN @RT-LAN0.0.0.0/0 points to next VR "RT-WAN" @RT-WAN0.0.0.0/0 points to 1/1, next hop 187.190.74.1, metric 100.0.0.0/0 points to 1/2, next hop 19...

Problems after RMA

hello After RMA the device we had prepared new device.Updated software and APPs and Threats signatures and also other signaturesThen imported the old config.But there are many problems.First time after time it is impossible to update dynamic updates (wildfire,antivirus and so on).Only after dateplane restart everything works but for awhile and t...

Radmin_85 by L4 Transporter
  • 2544 Views
  • 3 replies
  • 0 Likes

Connecting to Management GUI remotely on a different port.

I have a PA500 offsite that I manage remotely by connecting to the outside interface IP address, let's call it 188.1.1.1. My issue is I want to also set up a Global Protect SSL VPN gateway and the only IP choice it gives me is the outside interface 188.1.1.1/28. If I configure that then I can no longer reach the Management GUI remotely. Is there...

Walt by L1 Bithead
  • 8112 Views
  • 2 replies
  • 0 Likes

SNMP aged out

Dear Guys, I have a WAN router where we are trying to do a SNMP read only, but it keeps saying aged out. we have different devices as well which are working but SNMP on this router doesnt seem to be working.How can i prove that it is not the issue with Palo alto but on the remote side .The Service provider is telling us that we are sending the ...

NiteshS by L2 Linker
  • 4097 Views
  • 3 replies
  • 0 Likes

Is there a minimum upload and download speed required for Global Protect to operate?

I have a group of users that use Sprint and Verizon hot spots in order to establish a VPN connection from a remote location to our corportate network using the Global Protect Agent. Some of the hotspots are experiencing a 2-3 Mbps upload and 2-3 Mbps download speeds. The users at these locations are experiencing VPN disconnection issues such as ...

Qradar couldn't connect MM Taxii output

Hi Guys, It seems issue happend at Minemeld side. This is error from Qradar Threat Intell app "There is a problem connecting to the TAXII server. Verify that the TAXII server is available. Get list of collections failed." This is error from Minemeld (/opt/minemeld/log/minemeld-web.log)"POST /taxii-discovery-service HTTP/1.0" 200 1658 "-" "Qradar...

Woranon by L1 Bithead
  • 5180 Views
  • 3 replies
  • 0 Likes

Resolved! User-ID Agent placement (Domain Controller)

Hi all, I've read the best practice guide and I can't see anything that says the agent SHOULDN'T be installed onto a domain controller. Any experiences with that here? We currently have the agent installed onto two Windows Server 2012 R2 member servers that are close to the DC's but will be retired soon and I need to evaluate my options. Just ma...

Slow throughput on newly installed PA-820

Hello all...I have a newly installed HA pair of PA-820. Our ISP circuit is 50Mbps/50Mbps. Testing from a LAN pc, I am only able to download a max of 14Mbps using speedtest.net or speakeasy.net. I have called Palo Alto support and they suggested setting up QOS on my WAN interface and setting the speed to 50Mbps on the interface. The slow downl...

PAN-OS 8.0 Upgrade Blocking Nexflix

I recently upgraded my home PA-200 to PAN-OS 8.0.1 from 7.1.7. All seems fine, except that from two Samsung smart TVs Netflix streaming is affected. A diagnostic test on one of the TVs shows that the app is able to connect to 1 of 4 Netflix servers only. Strangely, I can stream Netflix to a Chrome browser on a Windows 10 machine without issue...

Sbarlock by L1 Bithead
  • 11328 Views
  • 8 replies
  • 0 Likes

Zone available in template stack but not available in policy

Issue Description Specific zone which created in global template is available in one stack but unavailable in other, though this global template is part of their stack. Config detailsEach firewall has their own stack, template and 1 common global template zone created on global template is available on both stackspa_3050_stack(firewall1)pa_vm(...

2018-05-03 10_12_10-Panorama.png
2018-05-03 10_12_54-Panorama.png
2018-05-03 10_13_06-Panorama.png
2018-05-03 10_13_28-Panorama.png
  • 24359 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels