General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4130 Views
  • 0 replies
  • 0 Likes

GlobalProtect on new MAC pc

Hello, We have installed the Global Protect software (version 4.0.5-8) on a new MAC computer (High Sierra version 10.13.3). However the Connect button is greyed out along with a number of other buttons. The only available buttons are Show Panel / About / Help / Welcome Page / Notifications and Collect Logs.If I open the panel it has the correct ...

Farzana by L4 Transporter
  • 2201 Views
  • 2 replies
  • 0 Likes

OS upgrade rollback from 7

I am currently on version 6.1.10 and when I upgraded to it in March I was told by TAC that is was currently the most stable version. I am looking at what it would take to move up to the most stable version of 7 but first I want to figure out the best way to roll back the upgrade should it not go well, I am assuming its not as easy as re-installi...

jdprovine by L4 Transporter
  • 4043 Views
  • 5 replies
  • 0 Likes

Resolved! How many firewalls justify Panorama

Curious to see if there's some group concensus on how many firewalls an organization needs to have before the cost of Panorama is justified? Right now we have two H.A. pairs (four total) and im not sure Panorama would make life that much easier. Thanks for your input.

fmurray by L1 Bithead
  • 8664 Views
  • 7 replies
  • 1 Likes

Fiber Connectivity For PA-850

Hello, we are going to connect our PA-850 firewalls with FortiGate-300D firewalls via multi-mode fiber cables and will most likely be using PAN-SFP-SX for the cable connectivity. 1) I see that the specification sheet mentions only OM2 multi-mode fiber cables but OM3 is typically used nowadays. Can OM3 multi-mode fiber cables be used in our scena...

poolnet by L0 Member
  • 3127 Views
  • 2 replies
  • 0 Likes

PA220 PANOS 8.0.7 Dual ISP

Hello Everyone I know there is a fair amount of information on this topic but I have a few issues/questions I have a PA220 with PANOS 8,0,7. My questions are relating to dual ISP connectivity. I would like to setup my PA with a backup ISP connection. I do have IPsec tunnels. But I am allowing for the second tunnel to negotiate when the backup IS...

Resolved! VSYS with Shared Gateway and Existing Global Protect

We have a 3050 with one VSYS and is connected to an ISP with one IP address as we also use this VSYS for user VPN (Global Protect). All is working fine but we will be adding another VSYS to segregate another department’s Internet traffic. I would like both VSYS to share the same Internet and IP but I’m concerned if I read correctly about our exi...

Resolved! Windows Based User-ID Agent Setup

Hi Fellas! I have integrated a Windows Based user-ID agent to our VM-300 series firewall and having some issues with some users not having ip-user mapping. Since we are enforcing security policy by AD groups for internet access, these users that doesn't have ip-user mapping will not be able to access the internet. Some times, I will let the user...

Intermittent username drops

Username-IP mappings intermittently stops and traffic logs show just IP but not username. And mapping happens after sometime automatically. This is limiting me from creating rules based on usernames. What might be the reason? Thanks.

PANOS-8.0 broke IPSec XAuth VPN?

Hi, After I upgraded to our PA-3050 to PANOS-8.0, ios and android native clients (using ipsec xauth) don't work anymore. These clients can authenticate successfuly and get a valid IP from the gateway ip pool. But after this they can't access anything. There is no traffic logs shown with the vpn ip either. Anybody using 8.0 can test if ipsec xau...

Resolved! Miner for host file format.

Is there a miner + documentation on how to get it working for a host file list? i.e. https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts This tool was recommended by Palo Alto for a project we are working on, howver the documentation on how to actually use it is hard to understand.

Slow Traffic

Hi,PA in vwire mode , zone client and zone serversIn zone servers there is a print server(windows) and the zone client users pc .Users are trying heavy duty printing (50-100) pages .User complaining about slow operationsHow can I verify pa is bottleneck or making some issuesdata plane is seems to be okThanks

simsim by L4 Transporter
  • 6596 Views
  • 13 replies
  • 0 Likes
  • 24337 Posts
  • 124 Subscriptions
Labels