General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4115 Views
  • 0 replies
  • 0 Likes

Decryption problem

We have such a problem with Microsoft Exchange OWA which we have recently published through Palo Alto.We have installed certificates with private keys,created necessary rules for PBF and NAT.Everything is working fine except decryption.We can see in monitoring tab errors like decrypt-error or decrypt-unsupport-paramwe have tried to connect from...

CC.png
Radmin_85 by L4 Transporter
  • 5645 Views
  • 6 replies
  • 0 Likes

SSL Decryption Session Limit

Hello We are planning to implement the SSL Decryption in our Enviornment. We would like to know how the session limit is counted in the firewall. Also is there any session limit for the PAN OS 7.1.3 and if yes what is it. Also if we upgrade to version 8.0 Whether the session limitis increased. RegardsMahesh Damani

mdamani by L0 Member
  • 5006 Views
  • 1 replies
  • 0 Likes

Resolved! Global protect and virtual MAC address

HI. We run global protect for a reasonable number of remote users on our PA3050's without much in the way of issues. One thing which pops up, though, is that our Virus management server (McAfee) gets hugely confused about which machines are on which IP address. We've done a little digging, and it apepars to be related to te fact that all machine...

darren_g by L4 Transporter
  • 5448 Views
  • 2 replies
  • 0 Likes

Palo Alto MPLS failover

Please give me a best Solution I have one Palo alto firewall and Branch end Cyberoam I need to do MPLS VPN Failover between both device any suggetion it will work or notpalo alto MPLS supported or not ? Thanks regrardsHiroli Mohsin

Mohsin91 by L0 Member
  • 2989 Views
  • 1 replies
  • 0 Likes

Skype audio and video problem

hello We have some problem with skype.Inside the company we can use skype application.But when we try to call by skype outside the company call and video dont work onle chat.But inside network we can use all features.When we test the skype without Palo Alto it works fine.What can be the reason? why Palo Alto dont pass the voice outside

Radmin_85 by L4 Transporter
  • 2609 Views
  • 3 replies
  • 0 Likes

Is there any easy way to check Daily Log and how Retention working?

Expect this stupid calculation - https://live.paloaltonetworks.com/t5/Management-Articles/Panorama-Sizing-and-Design-Guide/ta-p/72181 Is there any easy to check log capacity depending on daily, weekly, monthly? this is so ridiciluous that doing calculation like this not matching reality, also any possible way to check what days logs have delete...

Tulgabat by L0 Member
  • 2555 Views
  • 1 replies
  • 0 Likes

Resolved! Wildfire & Brightcloud URL filtering

Hi All. So when Wildfire creates a signate for a piece of malware and assoicated URLs are added to the malware category of URL filtering. Is this added to the brightcloud URL database or only the PAN-DB database? Thanks Chris

Talos Blacklist

I am trying to create a miner/processor/output nodes for the talos black list ( https://talosintelligence.com/documents/ip-blacklist ) and am failing. Has anyone got this to work?

Hal_Blum by L0 Member
  • 7526 Views
  • 2 replies
  • 1 Likes

One GP portal, forward select users to alternate firewall zone?

Hi all, We currently have a single GlobalProtect gateway, single portal VPN configuration which happens to work really well (currently running on a single PA-3020). This gateway/portal combination first authenticates against LDAP (employees) and then against the local user database. What I'd like to do, however, is add support for vendors and co...

Resolved! How to monitor for VOIP traffic interuptions?

Hi folks, We've had a couple of occassions lately when our Lync phone system all of sudden will stop sending/receiving external calls. In this case a restart of the Windows server Lync Mediation service restored service. Our carrier does a "heartbeat" type of session ping every second and I can see the gap in this communication during the down...

voipsessionping.jpg
OMatlock by L4 Transporter
  • 4293 Views
  • 2 replies
  • 0 Likes

Amazon Echo Alexa video calling issues

I'm a current Palo Alto Home user. I've been able to figure out issues with current APP ID's that are not listed for most home use for IOT devices. I'm trying to see if anyone has figured out how to let Amazon Echo Alexa Video calls go through using custom App ID's.

hicksm by L0 Member
  • 7995 Views
  • 2 replies
  • 0 Likes

Email config audit on change.

On our old firewalls we used KIWI CATTOOLS to pick up configs hourly and compare them for differences, this sort of works on the Palo but each night it seems to generate strange changes in the configs. Ideally I would want to send out the config audit on commit, the emails that normaly come through are more or less useless and unreadable. Or can...

Resolved! PA-820 - Am I asking too much!

Hi,I've been asked to assess if PA-820s could be used to support a smallish MSP environment and as I'm new to the PA world (and indeed MSP network design) I'm hopeful some of you can point me in the right direction. I may be going about the design wrong so do say if you think there are better/relatively cost free ways to acheive the desired outc...

Generic Customer.png

Resolved! SSH2 Brute Force events in System Logs

Hi guys,I've noticed in my System logs that there are SSH2 brute force attempts against our firewall.Unfortunately nothing is listed in the Traffic or Threat logs under the Monitor tab to indicate from which zone the traffic is originating from.Why would this be the case and how can I enable logging for this in the Traffic\Threat logs to determi...

  • 24335 Posts
  • 124 Subscriptions
Top Solution Authors
Labels