General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4110 Views
  • 0 replies
  • 0 Likes

Resolved! Is Zone Protection on Shared Gateways Supported

I have a question regarding Zone Protection on Zones in a shared gateway. Is it supported. When I try and configure it it seems to be valid configuration. However as a shared gateway does not generate logs where do the the ZP logs go? Also when I run the command "show zone-protection zone ?" the SG zones do no show in the list so I can't col...

CHammock by L2 Linker
  • 4997 Views
  • 4 replies
  • 0 Likes

Unstable ipsec detection for ipsec-esp-udp application when connecting Globalprotect VPN

We have a setup with a primary PA firewall 1 that pass through Globalprotect VPN traffic to a second PA firewall 2. We've seen sporadic connection problems when connecting a Globalprotect client. Sometimes it can spend up to 2 minutes to establish the VPN. When these connection problems occur firewall 1 will log unknown-udp on port 4501. Besides...

GlobalProtect install restrictions

Hi allI was wondering if there was a way to restrict who can install the GlobalProtect client ? As an example, at the moment if any user launches the gateway page can download and install the client on their own computer albeit they need an active account, but the thought of them being able to install it on an infected home computer does worry m...

djh3003 by L0 Member
  • 3278 Views
  • 4 replies
  • 0 Likes

SSL decryption error

I had configured SSL decryption on PaloAlto VM-50 before 6-7 months ago. There was working normally till today. Today some users get below error when they want to enter site. There is shown “decrypt-cert-validation” message on PaloAlto traffic logs. There isn’t shown any error on PaloAlto and on user computer When I disable SSL decryption rule.

image005.jpg
Radmin_85 by L4 Transporter
  • 5652 Views
  • 4 replies
  • 0 Likes

Help with configuration for a test network going through our live environment 5050's

Just mainly need direction on where to go with this. We have 2 PA5050's in our environment and no test network for the main network. We do however have a new test satellite network where some of our DB's and others want it to have access to live environment servers. My idea is to use the 5050's to keep the devices on the test network talking to ...

JeffTQT by L2 Linker
  • 6333 Views
  • 6 replies
  • 0 Likes

Help with IPSEC VPN with overlapping subnets

I'm working with a vendor to setup an IPSEC VPN but we have an overlapping host address. My side has a PA500 and their side is a Sonicwall. Palo Alto Side: Source server: 192.168.100.20Their Server: 192.168.100.85 My server NAT address: 10.0.0.20Their Server NAT address: 10.0.1.85 I've configured a NAT rule that goes from Trust to Tunnel Zone: D...

High memory usage PA 3020

Hi, can someone help me? I have PA-3020, about 900 security policies, about 50 vpn tunnels (low traffic), I noticed high memory usage , What could be the reason for this? How can i relaease this? soft: 7.1.4-h2 Cpu(s): 0.5%us, 0.5%sy, 0.0%ni, 98.8%id, 0.0%wa, 0.0%hi, 0.2%si, 0.0%stMem: 3850716k total, 3520216k used, 330500k free, 1...

Unused Services

Is there a way to tell if a service is being used? I am trying to verify that the services the migration tool lists as unused can be deleted. It might be enough to go by what the migration tool says but I usually like to verify it a couple different ways.

jdprovine by L4 Transporter
  • 4643 Views
  • 3 replies
  • 0 Likes

Resolved! Oversize Microsoft RADIUS Response Packets

Oversized MS NPS radius response for EAP authentication request is dropped from the Firewall.Is there any solution on this? Customer do not want to make any adjustment or modification from the server end. Apart from enabling Jumbo frames and "adjust TCP MSS", are there any other options which can enable the large packet size only for a particul...

Resolved! Global Protect Access routes for Office 356

Hi Guys, I am struggling to find a solution for one request that I have from customer. We have VM-300 with PanOS-7.1.6 and customer wants to enable Global Protect for remote access users. The tricky part is that for the split-tunneling configuration he wants all Office 365 traffic to go via the tunnel. He was provide me with a list of hosts and ...

The dreaded any

I got a health check report and according to it I have a least one any in every single rule I have on my firewall. I was just curious if anyone has been able to have at least one or more rules with no any's at all.

jdprovine by L4 Transporter
  • 8879 Views
  • 14 replies
  • 1 Likes

Resolved! Logs Retention on MineMeld

Hello, I want to change the log retention on MineMeld. It looks that the default configuration is 7 days. I was not able to find where to change this parameter. Can you please help?

Resolved! Source NAT subnet from wrong interface

Hi, So im having difficult with a source nat to Internet.. My goal is to route traffic between two vlans in my cisco 2960x switch and let palo handle the rest.. The problem is that the source net arrives to the palo on the wrong interface (well its expected..)i have zone already configuerd in the palo fw with zones, interface. Ive created a acce...

Site to Site vpn with Dhcp server at remote site

Hi, I have a site to site ipsec vpn between 2 PA devices. Lets call them Site A and Site B and at Site A I have a Cisco router acting as a dhcp server. I'm trying to have all the client at Site B get their dhcp address and scope options from the cisco router at Site A. I have the sites connected to each other and I setup a dhcp relay agent on Si...

strobins by L1 Bithead
  • 6330 Views
  • 5 replies
  • 0 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels