General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 342 Views
  • 0 replies
  • 2 Likes

Pan-OS 8.0 and PA-200

Has anyone upgraded a PA-200 to PAN-OS 8.0? If so have you seen a performance hit at all? Notice a difference in how long things take? Commits? Response time? How long did the upgrade take? Did it take the 50-60 minutes Palo says? If so is that sitti

...

JeffTQT by L2 Linker
  • 5564 Views
  • 8 replies
  • 1 Likes

Resolved! How PA deals with packets with bad checksum?

Hey Guys,

 

Just trying to find out if someone knows, what PA policy is regarding packects with bad checksum?

Will they be allowed through the PA, or PA silently drops those packets or sends back a reset to

the source?

 

Any help appreciated.

 

Thanks,

Fatema

...

Fatema by L2 Linker
  • 5649 Views
  • 2 replies
  • 0 Likes

BGP peers transit sessions flapping

Hi Guys,

 

PA-5050 is a transit device for four BGP peers. Had no flapping since 2015 on PAN-OS 6.0.12. After upgrade from 6.0.12 > 7.0.11 BGP peering no longer stable:

 

 

Can anyone advise something? Apart of the increasing a timeout session under the a

...

BGP flapping.png

GlobalProtect Patch management Issue

Hi everyone,

 

We have a (HIP) check list of security requirements (joined domain, antivirus version etc… ) for our user machines must be comply with this list before our VPN user can access corporate servers. 

 

We want to add Microsoft Patches (updates

...

GP V3.1.6.PNG

MineMeld sudden_death...how does it work?

I need some help understanding the sudden_death behavior with a MineMeld miner/prototype.

 

From the documentation[1], I understand that sudden_death is designed to immediately age out indicators when they disappear from a feed.

 

Is it comparing the cur

...

BRosenba by L1 Bithead
  • 2874 Views
  • 3 replies
  • 0 Likes

PA-200 Pan OS 5 12 **anyone with a config file?**

I've about ripped out enough hairs no matter what config or method or video i try my setup doesnt work. I know its a check box or something.

 

I just want a basic/simple config

 

 

I'd like all ports 2/3/4 usable on same subnet with nat/dhcp

port 1.1 as wa

...

Resolved! Using PA-200 for home internet router?

Hello folks,

 

I recently bought a used PA-200 software version 6.1.4 for learning and testing purposes. 

I replace my home Linksys with the PA-200 following this article to configure.

https://live.paloaltonetworks.com/t5/Configuration-Articles/Setting-U

...

OMatlock by L4 Transporter
  • 7305 Views
  • 9 replies
  • 0 Likes

Application & URL Filtering/ Blocking

Hi

 

 

I've been this question, and I'd assume we'd need to block under both but I just want to make sure.

 

If we block a URL e.g dropbox, does this block the application as well or do we need to double up and also block the application itself under file

...

Mlangley by L0 Member
  • 1945 Views
  • 2 replies
  • 0 Likes

DUAL ISP Failover Single VR

I have a situation below and I need to be able to configure failover, seeking some guidance.

 

Basically I have

 

SG3 (two ISP's in the same VR)

ISP1 (eth1/7)

--------------> WAN-VR2

ISP2 (eth1/8)

 

Then I have a whole bunch of other sub interfaces on the LAN

...

mali77 by L1 Bithead
  • 5436 Views
  • 6 replies
  • 0 Likes

update.newinfoclientstack.com

I looked in the threat database and PA classifies this URL Inbox  update.newinfoclientstack.com as maleware. Is there a way to know if this is covered by the threat prevention subscription? There were no details in how to deal with it in the database

...

jdprovine by L4 Transporter
  • 2061 Views
  • 4 replies
  • 0 Likes

Resolved! Quickest way to add and manage Azure / AWS address group

Hi All, 

 

New to PA here - What is the quickest and most efficient way to Add / Delete / Manage large lists of IP addresses and subnets such as ones that belong to AWS or Azure?

 

I would like to create an Address Group and add in all Azure or AWS IP /

...

Resolved! IPSEC VPN ECMP - Issue

Dear Collegues,

 

Let imagine the following situation:

 

PA Firewall connected to two ISP, e1/1 - 1.1.1.1 and e1/4 - 2.2.2.2.

Default virtual router with ECMP configured with weights e1/1-50 and e1/4-50.

 

IPSEC tunnel configured to the remote site, IKE Gat

...

  • 23671 Posts
  • 108 Subscriptions
Top Liked Authors
Labels