General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 241 Views
  • 0 replies
  • 0 Likes

Resolved! Oversize Microsoft RADIUS Response Packets

Oversized MS NPS radius response for EAP authentication request is dropped from the Firewall.
Is there any solution on this? Customer do not want to make any adjustment or modification from the server end.

 

 

Apart from enabling Jumbo frames and "adjust

...

Resolved! Global Protect Access routes for Office 356

Hi Guys,

 

I am struggling to find a solution for one request that I have from customer. We have VM-300 with PanOS-7.1.6 and customer wants to enable Global Protect for remote access users. The tricky part is that for the split-tunneling configuration

...

The dreaded any

I got a health check report and according to it I have a least one any in every single rule I have on my firewall. I was just curious if anyone  has been able to have at least one or more rules with no any's at all. 

jdprovine by L4 Transporter
  • 6289 Views
  • 14 replies
  • 1 Likes

Resolved! Logs Retention on MineMeld

Hello,

 

I want to change the log retention on MineMeld.

It looks that the default configuration is 7 days. I was not able to find where to change this parameter.

Can you please help?

Resolved! Source NAT subnet from wrong interface

Hi, So im having difficult with a source nat to Internet.. My goal is to route traffic between two vlans in my cisco 2960x switch and let palo handle the rest.. The problem is that the source net arrives to the palo on the wrong interface (well its e

...

Site to Site vpn with Dhcp server at remote site

Hi,

 

I have a site to site ipsec vpn between 2 PA devices. Lets call them Site A and Site B and at Site A I have a Cisco router acting as a dhcp server. I'm trying to have all the client at Site B get their dhcp address and scope options from the cisc

...

strobins by L1 Bithead
  • 4643 Views
  • 5 replies
  • 0 Likes

Traffic steering to wrong sub interface

Tearing my hair out here so any help appreciated.

This is a VM firewall, VM-300 ver 8.0.3-h4.

 

I have created new subinterfaces for three VLANs, one of which is a guest VLAN (111) which has its own vSwitch, port group, sub-interface and zone. However,

...

Firewall 00 - Logs.PNG
Firewall 01 - Policies.PNG
Firewall 02 - Interfaces.PNG
Firewall 03 - Objects.PNG

is APAC an option of logging service region ?

Hi all

i would just like to know what region logging service is available for ?

is APAC included?

 

 

and Do we have a plan for PANORAMA service on cloud. so customers dont have to have panorama on premise,  instead, just pay by month for this service?

 

 

t

...

DannyDai by L1 Bithead
  • 1642 Views
  • 1 replies
  • 0 Likes

Resolved! PA SMB deny behaviour

Hi,

 

We have detected a atrange behaviour with SMB session.

 

We have created a rule for blocking wannacry (SMB) sessions 

 

We can see sessions being blocked:

 

 

So all sessions from trust to untrust should be blocked but we have done a tcpdump in our ISP

...

Captura2.JPG
Captura3.jpg

Apply QOS for a particual Service or Server

Dear Team,

 

we have a SFTP server behind our firewall and its nated to one of the interfaces of the firewal , we need to restrict the bandwidth to the  SFTP server . when clients connects to the server for downloading files they will be restricted to

...

Syam83 by L0 Member
  • 1700 Views
  • 1 replies
  • 0 Likes

PAN-DB Cloud Connectivity Issues

Has anyone else had the issue with the firewall blocking URLs when the cloud db is not working?

 

I have had two issues where the firewall will not allow sites that are common and catorgorized correctly in the local db because the cloud connection is n

...

aarronj by L0 Member
  • 1622 Views
  • 1 replies
  • 0 Likes

Show how long the VPN site-to-site tunnel is up

Hi everybody,

 

Is there any CLI command or log that show the time of the tunel VPN (phase 1, phase 2 or both of them) is up?

 

The commands:

show vpn ike-sa gateway <gateway name>

show vpn ipsec-sa tunnel <tunnel name>

 

It shows the lifetime since the last

...

  • 23625 Posts
  • 107 Subscriptions
Labels