General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 776 Views
  • 0 replies
  • 0 Likes

Response Page Issue

https://mail.yahoo.com (web based email) and https://web.tresorit.com (online storage and backup)  are both  blocked via url category filter as per screen shot. But... I am only getting the response page for mail.yahoo.com.

web.tresorit.com just gets

...

URL-Block.png
Mick_Ball by L7 Applicator
  • 2097 Views
  • 2 replies
  • 0 Likes

IPSEC VPN Tunnel Failover and Nexus 7K VPC Design

Hello,

 

A and B question:

 

A. We have two Palos in A/S. The active has a functioning IPSEC VPN tunnel  terminated to it. Is there any way to have the tunnel renegotiate to the S when it becomes A?

 

B. What is the proper way to design an A/S PA/Nexus 7k

...

Resolved! LDAP group member enumeration problem

I am running PAN OS 8.0.7 and having a problem with getting the members of a group enumerated by the firewall.

 

The group is shown by the firewall in the GUI and can be added to security policies, and the CLI if I run the "show user group list" comman

...

rbentley by L0 Member
  • 3789 Views
  • 1 replies
  • 0 Likes

Strange packet drop

Hello guys,

 

I have a PA820 in active/passive mode who has a strange behaviour. I have created a rule that permits that traffic but the device drops it. I see "allow"in the logs, but with a capture I can clearly see the SYN in the dropped section and

...

PA_log_forum.png
PA_rule_forum.png
Shye80 by L1 Bithead
  • 2233 Views
  • 2 replies
  • 0 Likes

Any issues not documented on version 8.0.6?

Hello Community,

Since the security advisories were released yesterday, we are looking to upgrade to the newer version. Has anyone experienced any issues with 8.0.6 from 8.0.5 that are not in the release notes?

 

 https://securityadvisories.paloaltonetw

...

Resolved! TEST VM-500 on ESXi Deployment

Dear Community,

 

I hope you are doing alright.

We are in process of renewing our firewalls and I would like to test-deploy latest version of the Palo Alto VM-Series 500 on VMware vSphere Hypervisor (ESXi).

 

Could you please let me know how I can the fol

...

Resolved! PA cluster certificate missing

Hi,

 

We have two devices in HA, we realized that active node has a certificate (captive portal) but the passive not. The configs are synchronized but the passive doesnt have this certificate. We tried to export this certificate from node active and im

...

Resolved! ROBOT attack - some advice needed

Hello

 

According to https://live.paloaltonetworks.com/t5/Threat-Vulnerability-Articles/PAN-OS-exposure-to-ROBOT-attack/ta-p/192397

For complete protection, signature #38407 must be applied upstream from any interfaces implementing SSL Decryption, or ho

...

_slv_ by L4 Transporter
  • 5640 Views
  • 5 replies
  • 0 Likes

Edge Firewall Design

I am trying to design the edge firewall and core network currently and I have a core Layer not in a "stack" or "VSS" so they are independent Core switches. They are doing the routing to the private WAN, and will be doing the routing to the Edge Firew

...

UserID and VPN

Is it necessary to have userid enabled on the VPN zone interfaces to see the userids?

jdprovine by L4 Transporter
  • 3073 Views
  • 8 replies
  • 0 Likes

Trust and Untrust on same interface

I am pretty new to the Palo Alto's so I have a questions that will be pretty easy to answer.

 

I am setting up a PA-820 in Virtual Wire and we have both Trusted and Untrusted networks on the same interface from the router.  The External interface is th

...

Default cursor location on GlobalProtect iOS login

Is there a place to report issues? On GlobalProtect forIOS, you can save your default username for your VPN, and the app pre-populates the field, however it leaves the cursor in the username field. It should, however, start in the password field. It ...

wseguin by L0 Member
  • 2178 Views
  • 3 replies
  • 0 Likes
  • 23985 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Authors
Labels