General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Dynamic Updates on PA-200

I have a PA-200 that is configured to check for updates every half hour aprox. The thing is that Antivirus, Aplications and Threats are not installed as scheduled!!!

 

When I log in to check, the check to Internet is done, but the package is not downlo

...

Two-Factor authentication failures

Hi, we have a few clients using GlobalProtect as VPN (various versions), some are authenticating using 2FA, using SecurEnvoy as a RADIUS server.

 

What we're seeing is as follows - the user has an authenticated VPN connection, then their network connec

...

A.Mellor by L0 Member
  • 2924 Views
  • 1 replies
  • 0 Likes

Resolved! Non-interruptive Panorama device migration

Hello!

Is there any way to perform migration of local configured firewall to panorama management without service interruption?

For example:
I use Panorama 7.0
There is configured PA-5060 6.1.5 HA-cluster that I need to migrate to centralized Panorama Man

...

Minemeld - Cannot create new Miner Node

Heya All,

 

I've been testing out minemeld and have it a bit of a brick wall.. When I attempt to create a new miner node via CONFIG > NEW, it completes successfully but the node cannot be found listed under nodes so I cannot add it as an input to the

...

Resolved! Filter items from source feed

One of the feeds I would like to import is the alienvault feed.  However, I only want a subset of the IPs listed.  I have tried using a regex with a transform to limit the results, but the miner is still showing an indicator count of 54,000.

 

I clon

...

deanm by L2 Linker
  • 8351 Views
  • 11 replies
  • 0 Likes

Resolved! HA configuring questions?

Hi folks,

 

A couple more questions about HA, if you please.

Hopefully my post frequency will reduce after training next week.

(Yes, configuring HA just before the training this weekend)

 

I will configure HA on an existing running production PA-3020 and t

...

OMatlock by L4 Transporter
  • 4102 Views
  • 9 replies
  • 0 Likes

Resolved! Bootsrap Image Error

Hi All

 

I am seeing the following in the system log of a PA-200 on reboot:

 

 critical hw             bootstr 0  No bootstrap media detected

 

 

I can't find any reference to this message anywhere and indeed all the errors that can be ebcountered while boo

...

Export Configuration

Hi,

 

It is probably very simple thing.. I wish to retrieve full configuration of Palo Alto firewall to build new firewall which will NOT be managed by Panorama.

 

Could someone please suggest me procedure or command on how to retrieve (via web or cli -

...

session QoS rule

Hi,

i have created a qos rule for skype and assign class which is real time ,

When I look in to the session details I could not find the session qos rule .

 

 

 

How to interpret the details ? 

for example like flow1 c2s and flow 2 c2s and PRED

any related d

...

skyp.jpg
simsim by L4 Transporter
  • 1884 Views
  • 3 replies
  • 0 Likes

Resolved! Policy application question

Hi

 

So I created an application 

 

TEST HTTPS tcp/443

TEST HTTP tcp/443

 

and a policy from any where to 10.10.10.10/24 application TEST HTTPS & TEST HTTP allow

and then deny everything else

 

if I go to my test box say 10.20.20.20/24 (different network), pre

...

Migrate from Check Point to PaloAlto step by step

Hi guys

I have some document that I made about migration from CP to PA,

Please feel free to contact me if you had some issue with that migration.

If you want the PDF file, please check the following link:

http://zwerd.com/2017/09/05/paloalto-migration.ht

...

Document-page-001.jpg
page2.PNG
Document-page-003.jpg
Document-page-004.jpg
guyzwe by L0 Member
  • 3200 Views
  • 1 replies
  • 3 Likes

7.1 default behavior changes

So I was reading about OS 7.1 because I am planning on upgrading from 7.0.12 to 7.1 and found some information of the default behavior of app-id

 

 

appid.PNG
jdprovine by L4 Transporter
  • 4135 Views
  • 12 replies
  • 0 Likes

Resolved! Path Monitoring question?

Hi folks,

 

Preparing for my HA configuration this weekend.  

 

I have a question about creating a Path monitoring group on the Passive device.

 

While I go through the procedures to configure HA on the Active device, I plan to set a Path monitoring group

...

OMatlock by L4 Transporter
  • 2309 Views
  • 3 replies
  • 1 Likes

Finally IPv6 over GlobalProtect, or should i say v6IP?

About 2 months ago I was thrilled to hear that PANOS 8 was coming out and that it would bring us IPv6 inside a Globalprotect VPN. After fixing the "licence issue", i finally came arround to doing the upgrade and eagerly started to configure a tunnel

...

P.Braat by L1 Bithead
  • 3815 Views
  • 6 replies
  • 0 Likes
  • 23560 Posts
  • 106 Subscriptions
Labels