General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4231 Views
  • 0 replies
  • 0 Likes

Slow internet performance behind PA-500

I recently upgraded to a 250Mbps internet speed.When I plug my laptop directly into the ISP router I am getting close to 300Mbps.But behind the PA-500 firewall, I am getting around 80-90Mbps.Firmware is 7.1.10 running in HA What would cause this?

Looking for some rule guidance

Hello all, I'm trying to get some access restricted to a few subnets that fall into our /16 range that we currently have in our Palo. The way it would look is we would have 2 subnets smack in the middle of the /16 that we only want to allow access to a handful of hosts in that subnet, yet block everything else in that range. To explain it cleare...

Miner certificate authentication

Hello! Could you tell me, Is there a miner with support authentification via client certificate? In particalur I need a JSON miner with this function. Thanks!

KVasiliy by L2 Linker
  • 4636 Views
  • 3 replies
  • 0 Likes

Accept UPN when GlobalProtect is the default credential provider?

PANOS 8.0.2GlobalProtect 4.0.2Client Windows 10 Enterprise x64We currently use Microsoft DirectAccess for all our Windows clientsThe Big plus of DirectAccess is that it works pre-logon and is completely seamless for the end-user, but it is Windows only, speed is not good and troubleshooting issues my be cumbersome. Therefore we are looking into ...

Details on URL Filtering Domain Classification

We've recently launched a Palo Alto deployment on our campus and are using the URL filtering capabilities to block any URL that is classified as 'malware' or 'phishing'. We're using PAN-DB as the source for the categories and were wondering what exactly goes into the process that classifies a domain as 'malware' or 'phishing'? Does PAN-DB source...

Resolved! Can I block malicious files sent via email ?

If my organization users send or receive emails (internal or external) with malicious file attachments , will I be able to block such emails using PAN firewall file blocking features ? I think Microsoft O365 already creates an encrypted channel so the email attachments or contents are protected until the files are manually downloaded by user.W...

Active/Passive HA cabling to Cisco Switch Stack or Nexus

I am looking for a cabling recommendation diagram for LACP portchannels from Cisco Switch Stacks or Nexus to HA Palo Alto Pair. Nexus can obviously use vPC feature so it may be slightly different than a switch stack. Switch stack cabling currently: Cisco SW#1 - Port gi1/0/1 ---> PA3050 (Active) Eth1/1Cisco SW#2 - Port gi1/0/2 ---> PA3050 ...

aged out vs unknown

HI,From some pc session end reason for dns traffic shows 'aged out'and for some shows 'unknown'what could be the reasoninternet traffic from the pc which shows aged out are really slowany helpThanks

simsim by L4 Transporter
  • 15273 Views
  • 6 replies
  • 0 Likes

Resolved! Dynamic Updates from Panorama

If we have 200 firewalls connected to PANORAMA. And we have in PANORAMA, dynamic updates set to update at midnight. Does it fire off one at a time each firewall until its downloaded and installed on each firewall, before moving on to next firewall to update? Or does it fire update to all 200 firewalls at once?

internet issue

Hi,I have an issue the internet is very slow for a vlan 10 , In my qos rule this is network class in 2 and the another vlan 11 in the same class has no issues . And the rule number for qos vlan10 is 10 and for vlan 11 is 50 .'If any client using all the bandwidth in that class vlan 11 also have to have the same issue ? How can I trou...

simsim by L4 Transporter
  • 1958 Views
  • 1 replies
  • 0 Likes

Resolved! VPN IPSec No Proposal Chosen

Hi, I keep having issues with my IPSec sts VPN. Always have a No proposal chosen message on the Phase 2 proposal.And then P2 proposal fails due to timeout.I read that it could be IPSec crypto settings or proxy ID that don't match.Proxy IDs are OK because when I put non-existing network, I don't have these messages.Encryption settings seem also w...

M6P2.png
crypto.png
IPsec tunnel.png
IPsec tunnel2.png
Naelwan by L1 Bithead
  • 62326 Views
  • 10 replies
  • 0 Likes

skype for Business issue

Hi ,I'm facing issue with skype for business through paloalto. very bad quality, it's not BW issue because we check it even at night.any one support more with this subject.

  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels