General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

URL category block triggers not logging in Panorama

Hi,

I am testing global protect using Prisma Access - Panorama managed..

On panoroma - i have a mobile user security rule applied with a custom URL filtering profile enabled where I have set the action to block for some of the newer URL categories in

...

PA_nts by L3 Networker
  • 435 Views
  • 1 replies
  • 0 Likes

pan-os-python Panorama set_ha_peers() method not working

The document I'm referring to - https://pan-os-python.readthedocs.io/en/latest/howto.html > High Availability Pairs

 

I've been working with the pan-os-python SDK, specifically with a Panorama High Availability (HA) pair. I'm following the documentat

...

vsurresh by L1 Bithead
  • 744 Views
  • 1 replies
  • 0 Likes

Resolved! IPV6 how to protect the hosts

Hi everyone, I learn the palo alto firewalls as I configure them.

 

I have a PA firewall with 3 vlans, with management allowed over main vlan.

 

My ISP provided the Ipv6/48 block and I have manage to redistribute it over the networks it works great.

...

nevolex by L3 Networker
  • 736 Views
  • 1 replies
  • 0 Likes

PA-7000 Series PANOS-10.1

Hello,

 

We have a PA-7050 firewall that we are looking to upgrade from 9.1.15 to 10.1.10-h2. 

 

We are following the upgrade path provided by Palo Alto however when we upgrade to the recommended 10.0 release or the 10.1 release the entire firewall c

...

Owen1 by L0 Member
  • 378 Views
  • 1 replies
  • 0 Likes

Sending logs to SIEM one file per type

I am an administrator of a SIEM, for this I have usually asked the paloalto administrator to send me the logs via Syslog using port 514 to the IP of the server I administer.

 

After informing me that the process has been done, I check a specific rout

...

Error: failed to handle CUSTOM_UPDATE

HEllo,

 

I am using 5220 series firewall in 2 different DC. versions 9.0.9 and 9.1.6. When I commit on both firewalls, I get a custom_update error. After check now the dynamic updates, I commit again and the problem goes away.

Any suggestion,
Thank you K

...

Resolved! Using HA without a virtual mac possible?

Hello,

as the title says: I want to implement an HA active-passive setup on a virtualization platform that doesn't support MAC address changes on the VM side. Therefore, a newly generated virtual MAC is unfortunately not an option.

So, is there a way

...

User-ID with OpenLDAP

Hi,

I'm looking for a guide or guidelines on how to set-up User Identification with OpenLDAP. I've already set-up User-ID with Active Directory for an other customer but I fail to see how this is doable on a non-Windows machine (no PAN agent).

Any help

...

Resolved! Internet and internal network sepration via virtual router

Hello,

 

I am new to Palo Alto. I have basic question. 

 

Traditional setup I worked on my last project was as below,

 

 

VRF on cisco router for 

- Internet -0 bgp

- Production - bgp

- DMZ  - bgp

 

FW connects to all 3 VRF. Route between VRF is via

...

gondolf by L1 Bithead
  • 1690 Views
  • 4 replies
  • 0 Likes

cluster PA-5020 migrating to PA-1410

Hi Experts,

We are migrating from Cluster PA-5020 to PA-1410, I have some queries below if you guys can help me out please.

1. For platform migration(PA-5020 to PA-1410), we can just upload configuration files on the new PA-1410, just recheck physica

...

  • 23707 Posts
  • 103 Subscriptions
Top Solution Authors
Top Liked Authors
Labels