General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

The dreaded any

I got a health check report and according to it I have a least one any in every single rule I have on my firewall. I was just curious if anyone  has been able to have at least one or more rules with no any's at all. 

jdprovine by L4 Transporter
  • 6135 Views
  • 14 replies
  • 1 Likes

Resolved! Logs Retention on MineMeld

Hello,

 

I want to change the log retention on MineMeld.

It looks that the default configuration is 7 days. I was not able to find where to change this parameter.

Can you please help?

Resolved! Source NAT subnet from wrong interface

Hi, So im having difficult with a source nat to Internet.. My goal is to route traffic between two vlans in my cisco 2960x switch and let palo handle the rest.. The problem is that the source net arrives to the palo on the wrong interface (well its e

...

Site to Site vpn with Dhcp server at remote site

Hi,

 

I have a site to site ipsec vpn between 2 PA devices. Lets call them Site A and Site B and at Site A I have a Cisco router acting as a dhcp server. I'm trying to have all the client at Site B get their dhcp address and scope options from the cisc

...

strobins by L1 Bithead
  • 4451 Views
  • 5 replies
  • 0 Likes

Traffic steering to wrong sub interface

Tearing my hair out here so any help appreciated.

This is a VM firewall, VM-300 ver 8.0.3-h4.

 

I have created new subinterfaces for three VLANs, one of which is a guest VLAN (111) which has its own vSwitch, port group, sub-interface and zone. However,

...

Firewall 00 - Logs.PNG
Firewall 01 - Policies.PNG
Firewall 02 - Interfaces.PNG
Firewall 03 - Objects.PNG

is APAC an option of logging service region ?

Hi all

i would just like to know what region logging service is available for ?

is APAC included?

 

 

and Do we have a plan for PANORAMA service on cloud. so customers dont have to have panorama on premise,  instead, just pay by month for this service?

 

 

t

...

DannyDai by L1 Bithead
  • 1609 Views
  • 1 replies
  • 0 Likes

Resolved! PA SMB deny behaviour

Hi,

 

We have detected a atrange behaviour with SMB session.

 

We have created a rule for blocking wannacry (SMB) sessions 

 

We can see sessions being blocked:

 

 

So all sessions from trust to untrust should be blocked but we have done a tcpdump in our ISP

...

Captura2.JPG
Captura3.jpg

Apply QOS for a particual Service or Server

Dear Team,

 

we have a SFTP server behind our firewall and its nated to one of the interfaces of the firewal , we need to restrict the bandwidth to the  SFTP server . when clients connects to the server for downloading files they will be restricted to

...

Syam83 by L0 Member
  • 1667 Views
  • 1 replies
  • 0 Likes

PAN-DB Cloud Connectivity Issues

Has anyone else had the issue with the firewall blocking URLs when the cloud db is not working?

 

I have had two issues where the firewall will not allow sites that are common and catorgorized correctly in the local db because the cloud connection is n

...

aarronj by L0 Member
  • 1580 Views
  • 1 replies
  • 0 Likes

Show how long the VPN site-to-site tunnel is up

Hi everybody,

 

Is there any CLI command or log that show the time of the tunel VPN (phase 1, phase 2 or both of them) is up?

 

The commands:

show vpn ike-sa gateway <gateway name>

show vpn ipsec-sa tunnel <tunnel name>

 

It shows the lifetime since the last

...

How to Block all countries

I am trying to make a policy on my new PA-220 and i want to block all traffic coming in from every country except the united states..I can't figure out how to do that except by blocking every country one country at a time.. Can anyone tell me if ther

...

hill11 by L0 Member
  • 3546 Views
  • 4 replies
  • 0 Likes

Resolved! Spyware Infect Host report from P.A.

I just got a spyware infected host report that says something like

 

 

Destination address    |    Destination Host Name         |   Count

X.X.X.X                                hostname.domain.com              2.94k 

X.X.X.X                             

...

Globalprotect IPSec crypto

A couple of questions 

1. Is the IPSec crypto for global protect completely separate for the IPSec crypto option that you find lower down in the list on the firewall?

2. Is the Globalprotect IPSec crypto still used when x-auth is turned on?

jdprovine by L4 Transporter
  • 2474 Views
  • 2 replies
  • 0 Likes
  • 23721 Posts
  • 104 Subscriptions
Top Solution Authors
Top Liked Authors
Labels