General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 510 Views
  • 0 replies
  • 0 Likes

Resolved! Source NAT subnet from wrong interface

Hi, So im having difficult with a source nat to Internet.. My goal is to route traffic between two vlans in my cisco 2960x switch and let palo handle the rest.. The problem is that the source net arrives to the palo on the wrong interface (well its e

...

Site to Site vpn with Dhcp server at remote site

Hi,

 

I have a site to site ipsec vpn between 2 PA devices. Lets call them Site A and Site B and at Site A I have a Cisco router acting as a dhcp server. I'm trying to have all the client at Site B get their dhcp address and scope options from the cisc

...

strobins by L1 Bithead
  • 5354 Views
  • 5 replies
  • 0 Likes

Traffic steering to wrong sub interface

Tearing my hair out here so any help appreciated.

This is a VM firewall, VM-300 ver 8.0.3-h4.

 

I have created new subinterfaces for three VLANs, one of which is a guest VLAN (111) which has its own vSwitch, port group, sub-interface and zone. However,

...

Firewall 00 - Logs.PNG
Firewall 01 - Policies.PNG
Firewall 02 - Interfaces.PNG
Firewall 03 - Objects.PNG

is APAC an option of logging service region ?

Hi all

i would just like to know what region logging service is available for ?

is APAC included?

 

 

and Do we have a plan for PANORAMA service on cloud. so customers dont have to have panorama on premise,  instead, just pay by month for this service?

 

 

t

...

DannyDai by L1 Bithead
  • 1841 Views
  • 1 replies
  • 0 Likes

Resolved! PA SMB deny behaviour

Hi,

 

We have detected a atrange behaviour with SMB session.

 

We have created a rule for blocking wannacry (SMB) sessions 

 

We can see sessions being blocked:

 

 

So all sessions from trust to untrust should be blocked but we have done a tcpdump in our ISP

...

Captura2.JPG
Captura3.jpg

Apply QOS for a particual Service or Server

Dear Team,

 

we have a SFTP server behind our firewall and its nated to one of the interfaces of the firewal , we need to restrict the bandwidth to the  SFTP server . when clients connects to the server for downloading files they will be restricted to

...

Syam83 by L0 Member
  • 1896 Views
  • 1 replies
  • 0 Likes

PAN-DB Cloud Connectivity Issues

Has anyone else had the issue with the firewall blocking URLs when the cloud db is not working?

 

I have had two issues where the firewall will not allow sites that are common and catorgorized correctly in the local db because the cloud connection is n

...

aarronj by L0 Member
  • 1827 Views
  • 1 replies
  • 0 Likes

Show how long the VPN site-to-site tunnel is up

Hi everybody,

 

Is there any CLI command or log that show the time of the tunel VPN (phase 1, phase 2 or both of them) is up?

 

The commands:

show vpn ike-sa gateway <gateway name>

show vpn ipsec-sa tunnel <tunnel name>

 

It shows the lifetime since the last

...

How to Block all countries

I am trying to make a policy on my new PA-220 and i want to block all traffic coming in from every country except the united states..I can't figure out how to do that except by blocking every country one country at a time.. Can anyone tell me if ther

...

hill11 by L0 Member
  • 4177 Views
  • 4 replies
  • 0 Likes

Resolved! Spyware Infect Host report from P.A.

I just got a spyware infected host report that says something like

 

 

Destination address    |    Destination Host Name         |   Count

X.X.X.X                                hostname.domain.com              2.94k 

X.X.X.X                             

...

Globalprotect IPSec crypto

A couple of questions 

1. Is the IPSec crypto for global protect completely separate for the IPSec crypto option that you find lower down in the list on the firewall?

2. Is the Globalprotect IPSec crypto still used when x-auth is turned on?

jdprovine by L4 Transporter
  • 2859 Views
  • 2 replies
  • 0 Likes

how to write a simple miner documentation

Hi there,

   I'm a new user, so hopefully this is a simple question.

 

I installed minemeld via source code on ubuntu 14.04 using the instructions on this page : 

https://github.com/PaloAltoNetworks/minemeld-ansible

 

 The installation went smoothly

...

vb0398 by L2 Linker
  • 14011 Views
  • 18 replies
  • 0 Likes
  • 24095 Posts
  • 116 Subscriptions
Labels