General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4136 Views
  • 0 replies
  • 0 Likes

Routing via PBF vs OSPF

I’m working on an implementation for about 15 branch offices where my organization is replacing an inconsistently-configured mix of SonicWALL and PA hardware with mostly PA-220’s. Each office has a Metro-Ethernet connection (100 Mbps at branches and 1 Gbps at HQ) and will also have an IPSec VPN tunnel back over their local internet connection ba...

locampo by L2 Linker
  • 4071 Views
  • 3 replies
  • 0 Likes

Resolved! Forwarding Decisions in PANOS

Hey guys. Fairly new to PANOS and also coming from the perspective of having been a longtime IT generalist with a large interest in networking to finally having a role as a dedicated SEM network engineering role. Having said that, we recently encountered a situation that confused me greatly. Context: we’ve got several branch offices with Metro-E...

locampo by L2 Linker
  • 7810 Views
  • 5 replies
  • 0 Likes

I want know CPU resouse mesage

What is mean??? flow_lookup flow_fastpath flow_slowpath flow_forwarding flow_mgmt flow_ctrl nac_result flow_np dfa_result module_internal aho_result zip_result pktlog_forwardinglwm flow_host ThanksRegard

awawa100 by L2 Linker
  • 3043 Views
  • 2 replies
  • 0 Likes

Resolved! SSL Website won't load with decryption enabled

Hello. One of my users was trying to go to: https://mn.b3benchmarking.com/Launch We have SSL forward proxy enabled. If I exclude the site from decryption is comes up fine. We are not using any decryption profiles. Can anyone tell my why the sites won't come up? I did run a check using https://www.ssllabs.com/ssltest/analyze.html?d=mn.b3benchma...

dannon by L3 Networker
  • 5833 Views
  • 3 replies
  • 0 Likes

Best Practice IPSec Tunnels

I was wondering if anyone had some good best practice recommendations for IPSec tunnel configurations. I’ve set up a lot of these in my time, but I’m realizing that I still don’t have a firm grasp over all these choices other than “make them match on both ends if you want them to work” and “more secure is better than less secure”. Especially, fo...

locampo by L2 Linker
  • 3879 Views
  • 1 replies
  • 0 Likes

Resolved! GlobalProtect breaking the Internet

Hello, We have an issue with our Global Protect client. The end users are able to connect and work fine, but when they press the disconnect button on the Global Protect client it is breaks their internet. Whether the user is connected to a WiFi network or via an ethernet cable or doesn't matter. To illustrate the issue, this is what we do:1. Use...

Error.jpg
Farzana by L4 Transporter
  • 12909 Views
  • 3 replies
  • 0 Likes

Allowing Mapquest

Greetings, One of my departments is requesting access to Mapquest for their users. Currently they have limited Internet access. I have added *.mapquest.com/ and it brings up a very limited webpage (no links). So I did some searching and found that Mapquest also uses a hosting site called mqcdn so i added *.content.mcqdn.com/ in as well. I was a...

Resolved! Group Mapping vs Authentication Profile

Hi Here is what we want to do:1. Implement a security policy rule based on user group membership2. There is no User ID using any Agent. The users will authenticate using captive portal.3. Firewall will use LDAP to retrieve group mapping4. PAN OS 7.1 Here's the question:Assume that I want to allow only users from LDAP Group "HR" in the security p...

NTP and proxy bypass

Hi i have a problem at the moment where it appears there is a proxy/Vpn application that is using port 123 .as i have lots of byod devices that require access to NTP i leave the port open. When I look at the monitor logs it source port can be anything from 123 to any other port and the dest port is 123 and P.A is letting me know the application ...

Resolved! Query on Certificate/access Internet

Is there a way to configure the firewall so that users can access internet without needing to install certificate?Currently users have to have a certificate installed on their devices to be able to connect to the internet.Any article on this?

Farzana by L4 Transporter
  • 2927 Views
  • 2 replies
  • 0 Likes

Session info not in sync in CLI and Web GUI

My PAs are on PAN OS 7.1 OS, I have noticed that session info is immediately displayed in CLI when I use sh session all filter command but when I see in GUI , there is a delay or sometimes I never see that session in Web GUI >Monitor>trafficIs this a bug ?

Resolved! After upgrading a pair of PA-3050 to 8.0.4, very slow throughput, reduced network connection speeds

After upgrading a pair of PA-3050 to 8.0.4, very slow throughput, reduced network connection speeds Before upgrading from 8.0.2 to 8.0.4, we hace average speeds of 18/18 Mbps with other headquarters, and 100/100 with Internet.After upgrading to 8.0.2, we have very slow connection with headquarters and Internet, average speeds of 300 Kbps with he...

High Avaibility problem A\P

There are two PA-500 firewalls in High Availability state A\PAfter failover process the passive device become active but didnt pass the traffic.One possible reason which i suppose to be is the Gratious Arp packets are not send to the port of switch (cisco 3850) which is connected to passive devicebecause when we type show mac-address interface ...

Radmin_85 by L4 Transporter
  • 2861 Views
  • 3 replies
  • 0 Likes

Global Protect - Nowhere to enter credentials

Hiya, I'm very new to this so if this is the wrong place please move it or let me know so I can repost in the correct place. I use Global Protect to connect to my University account through a VPN. However it updated overnight and is now version 4.0.4-9. Before it updated I had the option to enter the Portal, Username and Password. Now i only hav...

EmsUni by L0 Member
  • 1900 Views
  • 1 replies
  • 0 Likes
  • 24340 Posts
  • 124 Subscriptions
Top Liked Authors
Labels