General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 776 Views
  • 0 replies
  • 0 Likes

GlobalProtect commit fail on PAN-OS 7.0

help me please.

config ip pool for client access but commit fail

commit log message

Operation CommitResult Failed
Detailsmissing ip pool from both dynamic ip pool and authentication server ip pool for config 'default' in gateway GP-Gateway (tunnel GP-Gat...

Dent by L1 Bithead
  • 5391 Views
  • 5 replies
  • 0 Likes

Detalied url log

Hi all!

i'm new in this community and we have put in work 2 PA-3020.

I configured ELK for log forwarding.

i've search every log and i couldn't find a filed with the url theat a user is visiting. Is there a way to achieve that.

Example! Now i'm writing fr

...

Matteo by L1 Bithead
  • 3122 Views
  • 3 replies
  • 0 Likes

Internal traffic is hitting in the isp firewall

Palo alto is perimeter to customer which is connected to isp firewall.

Internal subnet traffics which are not allowed in isp/ untrust interface are hitted in isp firewall.
Routing is proper. ARP is proper in isp interface( only next hop arp is there)

Im...

Resolved! MP utilization high after the HA failover to primary

When Secondary Firewall became active, management plane utilization is not more than 10% for over months.

Last week manual failover made, Primary is active now. MP utilization is above 60% all the time.

 

All the configurations are same as it's in HA. B

...

Resolved! Panorama question

Why is it for 

 

network / interface / <some interface>

 

I can't use a name for a zone.

 

I wanted to have a template that had all of my zones in it, but unlike policies and objects there is no shared attribute.

 

Which means I have recreate my zones for ea

...

PA-220 Aggregate Interface with LACP supported?

Hi,

 

I need to confirm whether the PA-220 is able to aggregate 2 interfaces or more in a LAG (LACP).

 

I was able to find out that the PA-200 does not support aggregating interfaces with LACP, but the PA-220 is rather new and I have not been able to fin

...

Web Filtering and Reporting

I have been tweeking reports on these Palos we purchases (3020) and trying to find a good Web Browsing/Filtering report to provide for senior management that will encompass top xx users with most visited external sites, preferrably with the duration

...

What services are used by the Management port?

We have been tasked to follow the CIS benchmark for our Palo Alto firewalls. One item is to limit access to specific IP addresses for the Management port. That is easy enough if the only thing using the management port was users connecting to manage

...

kjsocher by L0 Member
  • 2575 Views
  • 3 replies
  • 0 Likes

Resolved! Installing Global Protect on Mac not working.

I have downloaded and installed the latest GlobalProtect for Mac.  The install does not show any errors, but the agent does not seem to have started.  Rebooted and installed again, but still no joy.

 

I am running 10.12.5, Sierra on a 2010 Mac Mini wit

...

mdorsey by L0 Member
  • 4987 Views
  • 2 replies
  • 0 Likes

Resolved! Logging levels

Palo Alto is currently logging URLs which includes a path such as webserver.com/code.exe?id=4 but Palo is capable of logging a message that would display just the code.exe filename as well as a content type such as application/x-octet-stream or ms-ex

...

jerm1020 by L0 Member
  • 2428 Views
  • 2 replies
  • 0 Likes

Panorama shared objects

Hi

 

I am about to import my config from a PA into panorama. 

 

Now with shared objects, how do you manage them, can you delete them, I haven't found a way to do it via the web ui

How do change it from shared to non shared or the reverse ?

 

 

native VPN for Iphone on Pan os 8.0.2

Hello everyone, recently, i have access the acces for a palo alto Pa 500 i made the upgrade from 7.1.8 to 8.0.2, but now i need to do the configuration for a native vpn, for conect some iphone´s, but i dont have idea how to do this,  there is anyone

...

  • 23985 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Authors
Labels