General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Exchange emails stopped working due to zone protection profile

Hi All Emails from inhouse exchange server is not getting delivered to target email ID or either getting delayed . I have configured the secuirty policy with no security profile attached and the traffic is showing as allowed was suspecting that it might be getting blocked or dropped due to some security profile .once i remove zone protection pr...

Rameshwar by L3 Networker
  • 2465 Views
  • 2 replies
  • 0 Likes

Resolved! SonicWall to Palo Alto Migration?

Hello 🙂I am doing a migration from a Sonicwall device to a Palo device and I am not finding any migration tools that can help me. Does anyone know of a tool that will migrate from Sonicwall to PAN? I am at a loss of how to go about this without building it all up from scratch.

Roshawn by L2 Linker
  • 11294 Views
  • 3 replies
  • 0 Likes

UserID - nt authority\accesso anonimo

Hi guys, EnviromentPA3020panOS 7.1.11 -- UserID agent 7.0.4 I got issue with UserID that is currently receiving identites from UserID Agent.UserID has already mapped IP address with a specific LDAP user for example "domains.it\test".Sometimes happens that UserID starting to map the same IP address with this user: "nt authority\accesso anonimo (a...

Resolved! How to configure the firewall so that all traffic goes in and out through it?

Hello, everybody. I am configuring a VM-300 Virtual Firewall on a KVM installed in CentOS. The dedicated server where the virtual firewall is installed has two network cards.One of which connects to the Internet and the other with which it connects to a switch to which other servers are connected. My intention is for all incoming and outgoing tr...

DRAW.png
javihere by L1 Bithead
  • 2598 Views
  • 1 replies
  • 0 Likes

Resolved! Adding address objects and tagging them via CLI.

In my network we tag certain IP addresses for various reasons on our Palo Alto's. Sometimes we will get a large batch of these that need to be done and manually creating an address object and then tagging it via the GUi can be time consuming (to say the least). I'm wondering if there is a way to add these object groups and tag them via the CLI. ...

Logging events from Panorama to SIEM?

What methods are available for sending events from a distributed palo alto deployment which have been aggregated in panorama...to a syslog server or SIEM product? I know how to send events directly from a firewall but would hate for all my remote locations to have to send the logs twice, once to panorama and a second time to the SIEM.In panoram...

MineMeld Service's Not starting after installation

Hello Discussion Board, I am installing MineMeld in ESX 6. VM was built with trusty-server-cloudimg-amd64.ova and has minemeld-cloud-init-0.9.10-1build1.iso connected to the CD/DVD drive. Every time I reboot the server minemeld does not start and the system says there are 2 available packages that can be updated. I added a screenshot of...

qos

Hi,What are the differnces between cisco qos and pa qos Thanks

simsim by L4 Transporter
  • 2357 Views
  • 1 replies
  • 0 Likes

Resolved! site-to-site VPN / no "IKE Info"

Hey, We have a couple of VPN's which have just been transitioned to the PA firewall. Under network > ipsec tunnels > the VPN status shows as up, but the "IKE info" shows as down, with no info. If I run: "show vpn ike-sa detail gateway" there is nothing listed. If I run "test vpn ipsec-sa tunnel" it brings it up and shows IKE Phase1 SA:Coo...

SARowe_NZ by L3 Networker
  • 11018 Views
  • 3 replies
  • 0 Likes

Resolved! QoS issues on dual-ISP setup with differing circuit speeds.

Hi- We have dual connections and have our Palo Alto set up similar to described in this article: https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774 Our primary connection is 100Mbps whilst 2nd is only 10Mbps. Presumably this should involve 2 QoS profiles, one with ...

Share screen in skypeforbussiness not working

Hi, We are facing a strange problem with Skypeforbusiness. Two users are in a conference. When the user behind Palo alto tries to share the screen is not working, but when the remote user shares the screen is working. The error in skype is "Skype for Business: We couldn’t connect to the presentation because of network issues" In our PA is every...

dr1.JPG

Resolved! Is it possible to keep SIP calls from dropping when failing over between ISPs, or using ECMP?

I've heard of some SD-WAN providers that claim their devices will allow ISP aggregation and failover between ISPs without dropping SIP calls when one ISP goes down. Is this achievable without putting a SD-WAN device between our firewalls and the ISPs? At our site we have two ISPs, and currently are using PBF and monitoring to fail over between ...

uvdes by L2 Linker
  • 3673 Views
  • 1 replies
  • 0 Likes

Resolved! Add QOS for same source but different times & BW

We want to have different qos restrictions at different times for a single source ip. traffic from source to destination is over a tunnel. How can i achieve this, i can not assign multple qos profiles to same tunnel interface.

raji_toor by L4 Transporter
  • 5252 Views
  • 3 replies
  • 0 Likes

Mac connected in VPN doesn't work

Hi Guys, customer connected a Mac (OSX 10.13.2) using global protect and other vpn client (native and cisco), but i can't reach a remote server. Doing a packet capture i found the PA (pa-3020, 7.1.14) doesn't forward the reply packet.[Mac]--------->[PAN]--------->[Server] OK[Mac] [PAN]<---------[Server] PAN s...

DKanta by L2 Linker
  • 3330 Views
  • 2 replies
  • 0 Likes
  • 24407 Posts
  • 124 Subscriptions
Top Solution Authors
Labels