General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! site-to-site VPN / no "IKE Info"

Hey, We have a couple of VPN's which have just been transitioned to the PA firewall. Under network > ipsec tunnels > the VPN status shows as up, but the "IKE info" shows as down, with no info. If I run: "show vpn ike-sa detail gateway" there is nothing listed. If I run "test vpn ipsec-sa tunnel" it brings it up and shows IKE Phase1 SA:Coo...

SARowe_NZ by L3 Networker
  • 11178 Views
  • 3 replies
  • 0 Likes

Resolved! QoS issues on dual-ISP setup with differing circuit speeds.

Hi- We have dual connections and have our Palo Alto set up similar to described in this article: https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774 Our primary connection is 100Mbps whilst 2nd is only 10Mbps. Presumably this should involve 2 QoS profiles, one with ...

Share screen in skypeforbussiness not working

Hi, We are facing a strange problem with Skypeforbusiness. Two users are in a conference. When the user behind Palo alto tries to share the screen is not working, but when the remote user shares the screen is working. The error in skype is "Skype for Business: We couldn’t connect to the presentation because of network issues" In our PA is every...

dr1.JPG

Resolved! Is it possible to keep SIP calls from dropping when failing over between ISPs, or using ECMP?

I've heard of some SD-WAN providers that claim their devices will allow ISP aggregation and failover between ISPs without dropping SIP calls when one ISP goes down. Is this achievable without putting a SD-WAN device between our firewalls and the ISPs? At our site we have two ISPs, and currently are using PBF and monitoring to fail over between ...

uvdes by L2 Linker
  • 3736 Views
  • 1 replies
  • 0 Likes

Resolved! Add QOS for same source but different times & BW

We want to have different qos restrictions at different times for a single source ip. traffic from source to destination is over a tunnel. How can i achieve this, i can not assign multple qos profiles to same tunnel interface.

raji_toor by L4 Transporter
  • 5314 Views
  • 3 replies
  • 0 Likes

Mac connected in VPN doesn't work

Hi Guys, customer connected a Mac (OSX 10.13.2) using global protect and other vpn client (native and cisco), but i can't reach a remote server. Doing a packet capture i found the PA (pa-3020, 7.1.14) doesn't forward the reply packet.[Mac]--------->[PAN]--------->[Server] OK[Mac] [PAN]<---------[Server] PAN s...

DKanta by L2 Linker
  • 3396 Views
  • 2 replies
  • 0 Likes

Login BANNER variables?

Question. Does Palo alto have any variables that return the Devicename or Hostname? I want to create a Template in Panorama with the login banner settings and then push this out via a template stack to the devices. But I want each device to return their NAME in the Login Banner

PARKS by L0 Member
  • 2356 Views
  • 1 replies
  • 0 Likes

Resolved! Captive Portal settings

I am running Palo Alto Pan OS version 7.1.11 and need to adjust my captive portal settings. How do I disable or bypass the captive portal for particular networks. I have a guest network that I do not want any authentation and need to make sure the user is not bothered by a pesky captive portal logon.. Thanks

rmsdip3 by L1 Bithead
  • 4659 Views
  • 4 replies
  • 0 Likes

How to limit application or rule sessions

Hello. Let's going to say that I have the following scenario: - 1 remote server where can be connected just two users at the same time- Group of 3 users (Group 1 => user1, user2, user3)- Group of 3 users (Group2 => user4, user5, user6) I would like to allow just one user of each group at the same time, to do it I checked application overr...

m.molina by L1 Bithead
  • 2775 Views
  • 1 replies
  • 0 Likes

Resolved! FW's Not connected to M100, SSL failed to connect to panorama

We are on a test network with one Panorama m100 and two PA-5020s that are at 6.1.7 (there are reasons). they have not been modified lately but are showing disconnected after an attempted push. They show In Sync, for Shared Policy. Out of sync for templates. Last commit status is not connected. They were/are not an HA pair When i have tried the ...

Dataplane under severe load - Log entries

I see occasional "Dataplane under severe load" log entries. It is now occurring most days, sometimes a few times a day. Our monitoring system never shows the CPU average over 30% so whenever it happens it is apparently very brief. I also have never noticed any particular issues that correspond with these events. The events usually occur far ...

dp high load.PNG
Demast by L2 Linker
  • 5205 Views
  • 3 replies
  • 0 Likes

Resolved! How much hardware can I assign to the Virtual Firewall?

Hello, everybody. I want to acquire the VM-300 virtual firewall which is equal to the VM-1000-HV, for KVM. I do not wonder what the minimum requirements are. I wonder how much is the maximum I can assign from Memory Ram and Cores to this virtual firewall? Greetings and thank you for your help.

javihere by L1 Bithead
  • 2466 Views
  • 1 replies
  • 0 Likes

Stop web browsing to ssl

The external IP of our WiFi controller requires 443 to be open to the internet, so we have this open on our inbound rule>external IP of the controller. 443 needs to be open but we don't want this to be accessible via a web browser - as currently this rule allows the external IP to be accessed via https. Is there a way of stopping this behavi...

Resolved! Schedule a rollback to last known good configuration

Hi all, Is it possible to rollback to 'last known good' configuration, or even previously running config. Say for example I make some changes and issue a commit, then subsequently lose connectivity. Is there a mechanism to schedule a rollback to previously running config after say 5minutes?. Many thanksAjaz NawazJNCIE-SEC No. 254CCIE-RS No. 15721

nawaza by L2 Linker
  • 8137 Views
  • 6 replies
  • 0 Likes

RTP and RTCP traffic jumping rule

Hi, We have created a rule for Voice IP. Zone A to Zone B / Application RTP - RTCP / Service ANY / PERMIT So all the voice RTP connections should matched in the previous rule, but we are seeing connections which should be matched the previous rule but its matching in this rule: Zone A to Zone B / ANY / ANY / PERMIT Its like some connections are ...

  • 24443 Posts
  • 125 Subscriptions
Top Solution Authors
Labels