General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Advertise 10.10.10.0/24 via BGP

I am trying to understand how to advertise my network 10.10.10.0/24 via BGP with the Palo. in the Cisco world, I use the command NETWORK 10.10.10.0. But with the Palo Alto, is it EXPORT or REDISTRIBUTION? Any comments will be greatly appreciated. Thx

jac101 by L2 Linker
  • 2258 Views
  • 2 replies
  • 0 Likes

Resolved! Filter-List

Hello everyone! any one has list of safed filters that could help a lot and saves our time

Resolved! DHCP from separate interface

I feel like this is a fairly simple issue to solve - yet I'm having problems figuring it out: My scenario:I have an L3 interface that is acting as a DHCP server (eth1) as an example.I want to get DHCP from that DHCP server on the PA from a separate interface (eth2). My thought was to simply setup the other interface in L2 mode and it would bridg...

Data Exfil Blocking policy

Hi All, We were planning to implement some egress rules to protect any king of large uploads/data exfil activities from inside network.And when thinking through it, the first though came to my mind is to block all outgoing connections, except web-servers and some legit services like ssh etc.But then thought, that it might get lot of pushback and...

Fatema by L2 Linker
  • 2863 Views
  • 2 replies
  • 0 Likes

Resolved! Is it possible to create custom role in PAN-OS that allows management of administrator accounts?

I would like to create a custom Admin Role in PAN-OS 7.1.9 that is like a system admin for the device with the ability to configure and manage authentication, logging, licensing, certificates, dynamic updates, software, and administrators; however, when I am creating a new Admin Role, the Administrators and Admin Roles items can only be set to R...

Resolved! Support dial in number

Hi I have tried to use the australian number 1 800 002 378 after wating 50min plus with no contact and also using their leave your number we will call you back and not having done that in the last 3 times. I'm wondering how the other regions call in supports numbers are working. Thinking I might call US, but not if I am going to be waiting mor...

Resolved! commit failed with configurations invalid!

Hi PA Community, I got one issue with client where the commit is failing with details of only "Configurations Invalid" without any further details.We wanted to change the management interface IP to a different one and the commit is not accepted, even the validation is failing.I tried to made any other changes rather than mgm IP change and got th...

Problem in making palo alto test lab

Dears ,i installed palo alto ova and windows xp client and host is windows 10 , i am trying to make a test lab using cbtnuggets and my configuration as the following :1- windows XP is on VMnet3 and has IP : 10.3.3.11/242- i added all VMnet to palo alto virtual machine to be able to make inside , DMZ and outside3- i configured interface 1/1 in th...

Resolved! IKEv1 phase-2 SAs increasing

Hello, We are trying to clear and initiate IPsec connection using the following commands: clear vpn ike-sa gateway <value>clear vpn ipsec-sa tunnel <value>test vpn ike-sa gateway <value>test vpn ipsec-sa tunnel <value> However, the SA’s are not clearing , instead they are increasing. Any idea how to stop and clear them? I...

Farzana by L4 Transporter
  • 2463 Views
  • 1 replies
  • 0 Likes

Inbound SSL Decryption issues

Wondering if anyone has an idea on why I might be getting "decrypt-error" on an Inbound SSL decrypt rule? This service only runs a few times at night so I haven't done a packet capture yet... tonight I did some debug commands and found this in the log: 2017-07-31 22:00:15.865 -0500 Error: pan_ssl3_client_process_handshake(pan_ssl_client.c:871): ...

jsalmans by L4 Transporter
  • 7506 Views
  • 9 replies
  • 0 Likes

What is the long term plan for MineMeld

This project seems to be a very capable platform and I'm considering incorporating this into our environment. However, I have concerns about viability of this as a long term supported solution. Does this community provide any executive summery type documentation for management level with regards to what's supported by palo alto and what's commun...

  • 24381 Posts
  • 123 Subscriptions
Top Solution Authors
Top Liked Authors
Labels