General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 449 Views
  • 0 replies
  • 2 Likes

Resolved! Deleting Aggregate Interface

Good Morning,

 

can someone verify that the following command is correct for removing an aggregate-ethernet interface?

 

          delete network interface aggregate-ethernet ae1 layer3 units ae1.82

 

I am a litte leary of implementing this command due to

...

global protect multiple portal issue

We want to configure Portal level redundancy in Global protect .If we bind 2 IPs of 2 different location firewalls to our portal address then how does clinent interpret the DNS resolution .after how much time client will try on another system 

NIRAVK9 by L1 Bithead
  • 5992 Views
  • 13 replies
  • 0 Likes

ASK: GP with 2 network access

Hi All,

Anyone have tried to create 2 network access within PAN-GP on PANOS 6.1?

So, basically I want to create 2 PAN-GP Profile, one with split-tunnel, another one without split tunnel.

 

Already read some article, said that I'll need PAN-GP license and

...

Customer Account Personal Email

I bought a pa-220 for my own personal lab through my employer's pa vendor and I would prefer not to use my company email account just in case I were to leave my company. If that would happen, a year from now when my licenses expire, I won't be able t

...

Routing via PBF vs OSPF

I’m working on an implementation for about 15 branch offices where my organization is replacing an inconsistently-configured mix of SonicWALL and PA hardware with mostly PA-220’s. Each office has a Metro-Ethernet connection (100 Mbps at branches and

...

locampo by L2 Linker
  • 2871 Views
  • 3 replies
  • 0 Likes

Resolved! Forwarding Decisions in PANOS

Hey guys. Fairly new to PANOS and also coming from the perspective of having been a longtime IT generalist with a large interest in networking to finally having a role as a dedicated SEM network engineering role. Having said that, we recently encount

...

locampo by L2 Linker
  • 5406 Views
  • 5 replies
  • 0 Likes

I want know CPU resouse mesage

What is mean???

 

flow_lookup       flow_fastpath     flow_slowpath     flow_forwarding   flow_mgmt         flow_ctrl         nac_result       flow_np           dfa_result       module_internal   aho_result       zip_result       pktlog_forwardinglwm  ...

awawa100 by L2 Linker
  • 2466 Views
  • 2 replies
  • 0 Likes

Resolved! SSL Website won't load with decryption enabled

Hello.

 

One of my users was trying to go to:

 

https://mn.b3benchmarking.com/Launch

 

We have SSL forward proxy enabled.  If I exclude the site from decryption is comes up fine.  We are not using any decryption profiles.

 

Can anyone tell my why the sites w

...

dannon by L3 Networker
  • 4748 Views
  • 3 replies
  • 0 Likes

Best Practice IPSec Tunnels

I was wondering if anyone had some good best practice recommendations for IPSec tunnel configurations. I’ve set up a lot of these in my time, but I’m realizing that I still don’t have a firm grasp over all these choices other than “make them match on

...

locampo by L2 Linker
  • 3138 Views
  • 1 replies
  • 0 Likes

Resolved! GlobalProtect breaking the Internet

Hello,

 

We have an issue with our Global Protect client. The end users are able to connect and work fine, but when they press the disconnect button on the Global Protect client it is breaks their internet. Whether the user is connected to a WiFi netwo
...

Error.jpg
Farzana by L4 Transporter
  • 11771 Views
  • 3 replies
  • 0 Likes

Allowing Mapquest

Greetings,

 

 

One of my departments is requesting access to Mapquest for their users. Currently they have limited Internet access. I have added *.mapquest.com/ and it brings up a very limited webpage (no links). So I did some searching and found that M

...

Resolved! Group Mapping vs Authentication Profile

Hi

 

Here is what we want to do:

1. Implement a security policy rule based on user group membership

2. There is no User ID using any Agent. The users will authenticate using captive portal.

3. Firewall will use LDAP to retrieve group mapping

4. PAN OS 7.1

 

...

NTP and proxy bypass

Hi i have a problem at the moment where it appears there is a proxy/Vpn application that is using port 123 .

as i have lots of byod devices that require access to NTP i leave the port open.

 

When I look at the monitor logs it source port can be anythin

...

  • 23703 Posts
  • 110 Subscriptions
Top Solution Authors
Labels