General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4115 Views
  • 0 replies
  • 0 Likes

Managing single pair of VM firewall with and without Panorama

Hi Palo Alto Community I wanted to ask what are the pro's and cons of not using a Panorama for managing a single pair of VM-300 firewalls. From reading documentations etc, the main benefit of Panorama would only be if this was a distrbuted deployment managing 10's or 100's of firewalls. If in this case it was only 2 VM's to be managed a Panorama...

Resolved! How does the PFS Inbound Inspection work?

Hello Team, I am wondering how exactly the Inbound Inspection with PFS works? Diffie-Hellman per definition has the functionality that a key agreement is happening without transfering the key through the "unsecure" channel. All passively listening instances are not able to determine (calculate) the key used for the encryption. Well with this inf...

tisc by L1 Bithead
  • 3860 Views
  • 1 replies
  • 1 Likes

GlobalProtect - MacOS Support for Unscoped DNS Lookups

I am running Global Protect 4.0.3 and everthing is wokring successfully with Windows Devices. When DNS requests are made for the seach domain "foobar.com" they are directed at the internal DNS Servers defined within the GP Client Configuration and the requests are sent down the tunnel to internal DNS Servers. If it is for any other domain lookup...

Impossible? List unused Addres Objects?

I assume there is no report to list address objects that have not been used Ones that may or may not be in rules, relate to long dead or incorrectly entered endpoints, that have not generated any traffic. I have seen the "Shared_dup_and_unused... script, but don't think that gives me the desired result. Unless someone has something already, I th...

Policy Rules for BFD, OSPF , DHCP and DHCP relay

Hi So do I have to setup policy rules to allow OSPF, I have OSPF on the PA . But when i don't have the rules in place OSPF fails, when i have them it doesn't log anything DHCP, do I need it if the PA is running DHCP. what is the source and destination ? DHCP-relay, source is the input zone and the destination is the dhcp server I am relaying to...

Looking for maximum cps made by the firewall since last reboot

Hello All, I understand that there is show session meter, show session id and also show system statistics session But I would like to find out how many maximum connections were made in a second, since my firewall last rebooted. I am looking for a number, which tells me what is the maximum connections my firewall made in a second since it reboote...

SuryaR by L3 Networker
  • 2069 Views
  • 1 replies
  • 0 Likes

Rules with schedules failing intermittantly

I recently upgraded to OS 7.1.15 on my PA 5050, I have two rules with schedules on them and have had for over a year. In the traffic logs it was showing the traffic going back and forth between denying and allowing the traffic. When I removed the schedules they worked with no issues. Any ideas what could be going on?

jdprovine by L4 Transporter
  • 4711 Views
  • 10 replies
  • 0 Likes

Captive portal - how to logout?

Hello I need to do changes to my CP settings. Now I have CP in redirect mode and everything is OK. I have task to setup few computers in library that will allow our students use internet - but after logon. This part is easy ... but students need it for short time, and new one would use same computer (I can ask to shutdown browsers every time th...

_slv_ by L4 Transporter
  • 5159 Views
  • 1 replies
  • 0 Likes

multiple user-ip-mapping sources

I recently configured windows user-id agent and have it in conjunction with agentless user-id. Can I have both running on the firewall as a redundancy?or should I remove agentless config?will it create any harm if I keep both running?

Resolved! User activity report Query

Hello, I go to ACC tab -->Onleft side select the time frame --> Network Activity -->User Activity --> Export to PDF 1) User activity report when it is pulled it shows Source User and destination User. What is that destination user means? 2)Under Destination IP activity tab, once the report is pulled it shows the destination IP's but ...

Farzana by L4 Transporter
  • 2512 Views
  • 1 replies
  • 0 Likes

Check GlobalProtect VPN users with PowerShell GUI

I wrote a simple PowerShell GUI script that can check for GlobalProtectVPN users connected currently, or at a past date.It uses the Rest API to grab the information. Not sure if anyone would find it useful.Here is the Github link: https://github.com/marcusit/PaltoShell

paltoshell
molander by L2 Linker
  • 15291 Views
  • 15 replies
  • 2 Likes

Resolved! Wildfire Activity?

Hi folks, We have a Wildfire public cloud subscription, dynamic updates, and security profile configured.I've been asked, "How do we know it's doing anything?". When I look at Wildfire submissions, the last submissions are from January and end of last year.I am looking at this article and our settings, I don't think our's looks correct. Our Fil...

wildfire2.jpg
wildfire1.jpg
OMatlock by L4 Transporter
  • 3433 Views
  • 4 replies
  • 0 Likes
  • 24333 Posts
  • 124 Subscriptions
Top Solution Authors
Labels