General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

ICMP gets dropped by DEFAULT DENY ANY ANY

Source IP: x.x.172.230Source Zone: int-fw Destination IP: x.x.20.50Destination Zone: DMZ Requirements: SRC and DST IPs should be pinged bi-directionally. Scenario:- I've allowed the traffic using ICMP, ICMP-0, ICMP-8, PING bi-directionally but still unsuccessful- Upon checking the logs, I can see that from SRC ----> DST is allowed using the R...

mcjyrnn by L1 Bithead
  • 9999 Views
  • 11 replies
  • 0 Likes

Always on/Pre-Logon GP and Windows logon time

Does anyone have any tweaks or suggestions that might improve the windows logon time when GP is configured as pre-logon always on? Our users have gotten used to waiting sometimes up to 5 minutes after logging in before they see their windows desktop. The only way we have found to alleviate that is to set GP to on-demand (not an option) or uninst...

hshawn by L4 Transporter
  • 6362 Views
  • 6 replies
  • 0 Likes

Trunking a new switch existing PA (Active/passive)pair

Hello Everyone, I am having some trouble with trunking. Below is our current setup: PA pair(vlan 48---x.x.48.254) ------core switch (vlan 48....x.x.48.1) for internal access (trust zone). we have a static route on PA---any traffic to internal network, should be pointed core switch (vlan 48....x.x.48.1) .Similarly we have default route on core sw...

[PANORAMA][ERROR] Can't use export or push device config bundle feature

Hello, I got issues using the feature : Panorama > Setup > Operations > Export or push device config bundle.I try to erase the local configuration of a PA-850 and push the Panorama configuration on it. I got this error message when I click on push & commit : I would appreciate some help on this, does anyone already saw this error ...

Capture.PNG

Need help on VPN PA firewall to IBM cloud VPN

All, I am new to Palo Alto World Really need your Help in understanding how can i create the VPN for the below 1. IBM cloud subnet only 1 subnet so thats okay. 2. Multiple subnets behind my PA firewall, my question is how to NAT them all to go out? IBM just confirmed that they are using ROUTE based VPN , so i believe i do not need to define prox...

SNMP on Active-Passive HA Cluster

Hello, I have SNMP configured and working on the Active member of my HA cluster. i need to set SNMP up on the Passive member, i have made the changes and saved config but it is not working, do i need to commit the config? if so, would this cause any unforseen issues as i am doing a config commit on the Passive member where we normally only com...

GlobalProtect Connection Problems

Hi All I have had to re-install a user client Global Protect Agent 2.3.3-5 as he couldn't connect, after re-installing he still cant connect and getting a error message off: #“(T10576) 02/01/18 13:55:00:745 Debug( 226): CPanSocket::onConnect - return error code = 10061." he is the only one in the office that is getting this, everyone else can c...

ptotham by L0 Member
  • 6756 Views
  • 2 replies
  • 0 Likes

Decryption policy options explanation required.

Hello Everyone, I am reading about decryption policy and have some questions in my mind, so looking for some answers. 1- In order to apply the decryption profile, do I need to have action set to decrypt ? 2- what is the advantage if I have a decrypt policy with options set to:a) Action: No decrypt (with no profile) <-- is not it same as if it...

Xtreme by L1 Bithead
  • 3627 Views
  • 5 replies
  • 0 Likes

Determining failed administrator interface logons from syslog

Hello!I'm running into an issue. I would like to record failed logons to the administrator interface via syslog but the log format and contents of the logs appear to be exactly the same as those when a user performs a failed login to GlobalProtect Client VPN. Therefore I am getting a bunch of false positives.Has anyone had any luck with this?

Jimkoo by L0 Member
  • 2351 Views
  • 1 replies
  • 0 Likes

Traffic in interface tunnel

Hi, I have enabled QoS in order to limit a tunnel interface to maximum badwith to 50Mbps. QoS is well-applied but the current BW value is not being showed in QoS statistics. What ways are there to know the amount of traffic that goes in a moment through this tunnel to know if it exceeds 50MB??????? Except QoS statistics.....

Resolved! syslog forwarding

how can i forward exact below information to Syslog server ? > show log userid1,2013/03/28 12:53:05,001701000225,USERID,login,12,2013/03/28 12:53:05,vsys1,172.17.128.92,plano2008r2\administrator,test,0,1,2700,0,0,active-directory,unknown,1,0x01,2013/03/28 12:53:05,001701000225,USERID,login,12,2013/03/28 12:53:05,vsys1,172.17.128.92,plano2008r...

  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels