General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! NAT Security rule

I'm used to working on Cisco ASA and I'm having a hard time understanding why the security rule states Untrust-L3 for both the source and destination zone. Typically wouldn't that be Untrust-L3 to DMZ? Is there a specific reason for this behavior?

 

 

Screen Shot 2018-01-06 at 6.57.18 PM.png
Glitchen by L0 Member
  • 1901 Views
  • 2 replies
  • 0 Likes

DNS proxy not working

Hello,

 

We are currently getting resolve-fail events for DNS. 
Failed to resolve domain name: after trying all attempts to name server(s): 8.8.8.8 8.8.4.4
DNS server is in loopback.2 Interface/Untrust/IP:203.44.x.x
 
Below are some pics of DNS proxy setti
...

sessiondetails.jpg
DNS Proxy.jpg
Farzana by L4 Transporter
  • 4515 Views
  • 3 replies
  • 0 Likes

Outlook and Global Protect

In the past when our users disconnected Global Protect, Outlook would disconnect immediately.

 

Seems like this no longer the case. When GP is disconnected Outlook continues to work.

 

I'm wondering if anyone has every eperience this before?

 

Thanks

berket13 by L0 Member
  • 2526 Views
  • 4 replies
  • 0 Likes

Resolved! Expressway-E and C and NAT and VW

Hi,

 

I have deployed Expressway (cisco ToIP) E and C  as per the diagram below .PA is in VW mode .

Does it work  without any changes in the PA ? 

Or Is there any policy must be created ? 

 

Thanks 

PA.png
simsim by L4 Transporter
  • 2305 Views
  • 1 replies
  • 0 Likes

Response Page Issue

https://mail.yahoo.com (web based email) and https://web.tresorit.com (online storage and backup)  are both  blocked via url category filter as per screen shot. But... I am only getting the response page for mail.yahoo.com.

web.tresorit.com just gets

...

URL-Block.png
Mick_Ball by L7 Applicator
  • 1822 Views
  • 2 replies
  • 0 Likes

IPSEC VPN Tunnel Failover and Nexus 7K VPC Design

Hello,

 

A and B question:

 

A. We have two Palos in A/S. The active has a functioning IPSEC VPN tunnel  terminated to it. Is there any way to have the tunnel renegotiate to the S when it becomes A?

 

B. What is the proper way to design an A/S PA/Nexus 7k

...

Resolved! LDAP group member enumeration problem

I am running PAN OS 8.0.7 and having a problem with getting the members of a group enumerated by the firewall.

 

The group is shown by the firewall in the GUI and can be added to security policies, and the CLI if I run the "show user group list" comman

...

rbentley by L0 Member
  • 3206 Views
  • 1 replies
  • 0 Likes

Strange packet drop

Hello guys,

 

I have a PA820 in active/passive mode who has a strange behaviour. I have created a rule that permits that traffic but the device drops it. I see "allow"in the logs, but with a capture I can clearly see the SYN in the dropped section and

...

PA_log_forum.png
PA_rule_forum.png
Shye80 by L1 Bithead
  • 1963 Views
  • 2 replies
  • 0 Likes

Any issues not documented on version 8.0.6?

Hello Community,

Since the security advisories were released yesterday, we are looking to upgrade to the newer version. Has anyone experienced any issues with 8.0.6 from 8.0.5 that are not in the release notes?

 

 https://securityadvisories.paloaltonetw

...

  • 24034 Posts
  • 102 Subscriptions
Top Liked Authors
Labels