General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Site to Site VPN Tunnel - NAT

Hello everbody, I am most likely struggling with a NAT problem in a site to site VPN tunnel, hoping you have an idea or tip to this topic.The setup is a site to site VPN tunnel between a PAN and a Cisco ASA.There is a host (172.16.2.20) behind the PAN which should be reached through the VPN tunnel.The problem is that the service provider behind ...

Resolved! PaloAlto WAN Interface segmentation

Hello Please help me in this scenario There is the big "Company Site" and the other branches point to this Site, there is an MPLS connection between the branches.Our need is, the PaloAlto supports segmentation on the WAN part ? can we create a sub-interfaces in the connected interface (MPLS) at the big headquarters, and each sub-interface commun...

VRF WAN.jpg

candidate configuration

Hi,What is candidate configuration and what is the purpose of candidate configuration ?What is the differnece between save candidate configuration and the save using the button on the top right corner ? What is the differnce between save candidte configuration and commitThanks

simsim by L4 Transporter
  • 4398 Views
  • 4 replies
  • 0 Likes

Resolved! Can Palo Alto firewall act as a SCEP server

I would like to generate a SCEP request that I want to have signed by the CA on the Palo Alto firewall. I have beel looking at the documentation and asking my buddy Google, but have not found a way to do this. I am thinking this is not supported. Pleas confirm.

Firewall VM for GNS3

Hello everyone. Can anyone please tell me the steps to getting a PA-VM for GNS3? I've been doing some reading and need to practice using a virtual environment. Thanks.

QoS on Tagged VLAN Sub-interface - PAN5250

Hi, this question may have been asked before, but I'm still curious what the best practice is in my situation. Here's what I need to do: a LAG (port-channel) with two 10gig interfaces is carved into mulitple subinterfaces. I'd like to cap the max bandwidth usage for one of the suninterfaces only. Apprently PAN5250 does not support QoS on subi...

Global protect IP address

GlobalProtect gateway client configuration generated. User name: bozo, Private IP: 136.176.144.x, Client version: 4.0.0-90, Device name: clownmobile, Client OS version: Microsoft Windows 10 Pro , 64-bit, VPN type: Device Level VPN. Why is the PA classifying the IP address given to the VPN session as private?

jdprovine by L4 Transporter
  • 4267 Views
  • 7 replies
  • 0 Likes

Resolved! Top countries where cyber attacks originate

Good day everyone, I am looking for some help information with finding "Top 15 countries where cyber attacks originate"I know there are alot of blocklist out there, those have IP addresses. That is not what I am needing. If anyone can recommend websites or which countries they have blocked with the reason as well. I am looking to but together ...

SSL CSR SAN Multiple Uses

PA-5220, 8.0 I need to generate a CSR for a cert that will be used for multiple things - web gui admin, globalprotect vpn, etc. The instructions for how to gen the CSR with subject alternative names are not clear. Should the common name be one of the uses e.g. vpn.mycompany.com or should the common name be *.mycompany.com with all host names lis...

mike406 by L2 Linker
  • 6891 Views
  • 5 replies
  • 0 Likes

How to easily switch between multiple GlobalProtect VPN profiles???

Forgive me if this question has been asked before. My searches did not turn up any useful items in the discussion groups. I work for a company who supports multiple customers that use the GlobalProtect VPN. As an end-user, changing from one VPN portal configuration to another is a bit tedious. Can you recommend any easy methods for changing...

Resolved! nat before vpn tunnel use case question

Hello I am looking to understand if what I am trying to accomplish will work. Given a PAN connecting to an ASA using a L2L IPSec VPN Tunnel to access two distinct ip addresses behind the ASA. Now these IP Addresses are duplicated on the LAN the PAN connects, essentially overlapping. I know what to do in an ASA. But for the Pan I want my logic ch...

Tsquared by L0 Member
  • 5067 Views
  • 4 replies
  • 0 Likes

Panorama 8.0.7, Losing Templates following Import Device Configuration to Panorama

Experiencing some rather odd behaviour when Importing Device Configuration to Panorama In short what I'm witnessing is the loss of Templates (Device + Network), as soon as import is completed. The result is same whether I check the Import Shared Objects or not. Reversing the the changes by Config > Revert makes the Template section reappear o...

nawaza by L2 Linker
  • 2535 Views
  • 2 replies
  • 0 Likes
  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels