General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 243 Views
  • 0 replies
  • 0 Likes

Panorama Read Only mode?

Hi all,

 

I cannot modify my Panorama templates (Network, Device), even though I logged in with the admin account. As I attached the screenshots, it says (Read Only) mode and grayed out the check boxes, so I am unable to modify the Interface Management

...

Panorama_ReadOnly_services.jpg
Panorama_ReadOnly_interfacemgmt_profile.jpg

Multiple DHCP Scope’s on 1 interface

I have a router with 2 VLAN’s. The router is connected to a PaloAlto and behind this PaloAlto I have a server witch serves DHCP. The VLAN interfaces on the router are configured with a helper address to the DHCP server.

 

We would like to remove all se

...

Sjoerd by L2 Linker
  • 6745 Views
  • 6 replies
  • 1 Likes

App-id not working on some Apps

I am seeing a number of applications which have definitions, but are not being identified correctly:  kaokatalk, league of legends, battle.net and guild wars to name a few.  these are showing the correct ports but showing as "unkown-tcp".  Is there s

...

BobW by L4 Transporter
  • 6121 Views
  • 3 replies
  • 0 Likes

Removing peer from HA cluster

I have a pair of PA-3020s running 7.1.x in HA configuration. I need to remove the passive switch from the rack to be used in another location. What is the best way to disable the HA and delete the config from the active switch without risk of service

...

Resolved! Re-creating a specific routing configuration.

Hello folks,


I am trying to reproduce a configuration from work where we use a Metro Line to connect our two sites.  It's working at my job, but not at home.  It seems like a simple setup and I think I am close, but having an issue.  Checking if anyon

...

metrof.jpg
metroc.jpg
metrob.jpg
metrod.jpg
OMatlock by L4 Transporter
  • 3480 Views
  • 5 replies
  • 0 Likes

Interface in vsys

Hello

 

this may sound like a stupid question but i could not somehow find a definitive answer to this in the PAN OS Guide:

 

We have to configure a 3050 iun multi-vsys configuration. We would be needing 2 interfaces per vsys and we wil be having 2 vsys

...

Resolved! Is Zone Protection on Shared Gateways Supported

I have a question regarding Zone Protection on Zones in a shared gateway.  Is it supported.  When I try and configure it it seems to be valid configuration.  However as a shared gateway does not generate logs where do the the ZP logs go?  Also when I

...

CHammock by L2 Linker
  • 3764 Views
  • 4 replies
  • 0 Likes

GlobalProtect install restrictions

Hi all


I was wondering if there was a way to restrict who can install the GlobalProtect client ?

 

As an example, at the moment if any user launches the gateway page can download and install the client on their own computer albeit they need an active ac

...

djh3003 by L0 Member
  • 2413 Views
  • 4 replies
  • 0 Likes

SSL decryption error

I had configured SSL decryption on PaloAlto VM-50 before 6-7 months ago. There was working normally till today. Today some users get below error when they want to enter site. There is shown “decrypt-cert-validation” message on PaloAlto traffic logs.

...

image005.jpg
Radmin_85 by L4 Transporter
  • 4106 Views
  • 4 replies
  • 0 Likes

Help with IPSEC VPN with overlapping subnets

I'm working with a vendor to setup an IPSEC VPN but we have an overlapping host address. My side has a PA500 and their side is a Sonicwall.

 

Palo Alto Side:

 

Source server: 192.168.100.20

Their Server: 192.168.100.85

 

My server NAT address: 10.0.0.20

Thei

...

High memory usage PA 3020

Hi, can someone help me? I have PA-3020, about 900 security policies, about 50 vpn tunnels (low traffic), I noticed high memory usage , What could be the reason for this? How can i relaease this?

 

soft: 7.1.4-h2

 

Cpu(s):  0.5%us,  0.5%sy,  0.0%ni, 98.8

...

  • 23626 Posts
  • 107 Subscriptions
Labels