General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Traffic steering to wrong sub interface

Tearing my hair out here so any help appreciated.This is a VM firewall, VM-300 ver 8.0.3-h4. I have created new subinterfaces for three VLANs, one of which is a guest VLAN (111) which has its own vSwitch, port group, sub-interface and zone. However, all traffic seems to be steering to the same interface (eth1/2.15). Since eth1/2 was the original...

Firewall 00 - Logs.PNG
Firewall 01 - Policies.PNG
Firewall 02 - Interfaces.PNG
Firewall 03 - Objects.PNG

is APAC an option of logging service region ?

Hi alli would just like to know what region logging service is available for ?is APAC included? and Do we have a plan for PANORAMA service on cloud. so customers dont have to have panorama on premise, instead, just pay by month for this service? thanks a lot Danny

DannyDai by L1 Bithead
  • 2094 Views
  • 1 replies
  • 0 Likes

Resolved! PA SMB deny behaviour

Hi, We have detected a atrange behaviour with SMB session. We have created a rule for blocking wannacry (SMB) sessions We can see sessions being blocked: So all sessions from trust to untrust should be blocked but we have done a tcpdump in our ISP router an we see 2017-11-21 20:01:46: 8x.x.x.x => 213.187.106.86:4452017-11-21 20:01:46: 8x.x...

Captura2.JPG
Captura3.jpg

Apply QOS for a particual Service or Server

Dear Team, we have a SFTP server behind our firewall and its nated to one of the interfaces of the firewal , we need to restrict the bandwidth to the SFTP server . when clients connects to the server for downloading files they will be restricted to use 5 mbps only or something like that. they wont be able to use full bandwidth how to implement ...

Syam83 by L0 Member
  • 2175 Views
  • 1 replies
  • 0 Likes

Resolved! The way to select authentication methods of DUO using GlobalProtect

Good day! How are you doing? I'm looking for a way to select authentication methods of DUO while I'm using Globalprotect(NOT USING Captive Portal. There are so much problems shown when user tried to authenticate) I've done test about 2 factor authentication without authentication server(but I should have a proxy server, of course) 1st authentica...

PAN-DB Cloud Connectivity Issues

Has anyone else had the issue with the firewall blocking URLs when the cloud db is not working? I have had two issues where the firewall will not allow sites that are common and catorgorized correctly in the local db because the cloud connection is not established. Todays correction was a simple DNS fix but my question is more of function. Is i...

aarronj by L0 Member
  • 2160 Views
  • 1 replies
  • 0 Likes

Show how long the VPN site-to-site tunnel is up

Hi everybody, Is there any CLI command or log that show the time of the tunel VPN (phase 1, phase 2 or both of them) is up? The commands:show vpn ike-sa gateway <gateway name>show vpn ipsec-sa tunnel <tunnel name> It shows the lifetime since the last key was negotiated, but it doesn't show the total lifetime of activity of VPN tunnel...

How to Block all countries

I am trying to make a policy on my new PA-220 and i want to block all traffic coming in from every country except the united states..I can't figure out how to do that except by blocking every country one country at a time.. Can anyone tell me if there is a block all except feature?

hill11 by L0 Member
  • 5768 Views
  • 4 replies
  • 0 Likes

Resolved! Spyware Infect Host report from P.A.

I just got a spyware infected host report that says something like Destination address | Destination Host Name | CountX.X.X.X hostname.domain.com 2.94k X.X.X.X hostname2.domain.com 1.44k X.X.X.X hostname3.domain.c...

Globalprotect IPSec crypto

A couple of questions 1. Is the IPSec crypto for global protect completely separate for the IPSec crypto option that you find lower down in the list on the firewall?2. Is the Globalprotect IPSec crypto still used when x-auth is turned on?

jdprovine by L4 Transporter
  • 3346 Views
  • 2 replies
  • 0 Likes

The FW Can not match User based Rule when users were changed IP in using GP internal Gateway.

My customer uses GP Internal Gateway with a non-Tunnel mode.It means it uses just only user authentication and enforces user-based rules. I am facing an issue .A user was connected to GP Internal GW in office 1F and successed authentication.The FW was updated A user has 192.168.1.1 from GP.The user moves to 2F and changed IP from 192.168.1.1 to...

how to write a simple miner documentation

Hi there, I'm a new user, so hopefully this is a simple question. I installed minemeld via source code on ubuntu 14.04 using the instructions on this page : https://github.com/PaloAltoNetworks/minemeld-ansible The installation went smoothly and there were no errors. I then went through the exercise of writing a test miner using these ...

vb0398 by L2 Linker
  • 17461 Views
  • 18 replies
  • 0 Likes

Resolved! PBR forwarding does not work

For the first time I configured a Palo Alto firewall.I have created three zones each connected with a specific interface:INTERNEXTERNDMZ For each zone I created a virtuel router each configured with static routes :Intern:DMZ -> Interface DMZDmz:EXTERN -> Interface EXTERNINTERN -> Interface INTERNExtern0.0.0.0 0.0.0.0 -> IP ISP Router...

ZEBIT by L3 Networker
  • 7343 Views
  • 7 replies
  • 0 Likes
  • 24418 Posts
  • 125 Subscriptions
Top Solution Authors
Labels