General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 1882 Views
  • 1 replies
  • 10 Likes

Resolved! Management Plane Cores in PA-400 Series

Hello,

 

We would like to recommend that one of our clients move from PA-220 to PA-400 series firewalls. I had added multiple points regarding the improvement in Threat and Session information, however, one of the most important points for us to see th

...

osmasoud by L1 Bithead
  • 2398 Views
  • 3 replies
  • 0 Likes

Enforcing Global Protect only on remote sessions

My company only allows company issued laptops (Windows only) to remotely connect to our network via VPN. Since these are company devices I feel they should always be restricted to company internet usage polices that only allow access to approved site

...

dahoove by L1 Bithead
  • 881 Views
  • 3 replies
  • 0 Likes

site2site vpn. calling end is dynamic

I have a Palo gateway connecting via ipsec to a Palo gateway, the calling end has a dynamic IP and will need NAT-T.  The called end has a static public IP.  Whats the recommended method of using an identifier?

Resolved! Source Address - Show ipv4

I just upgraded from a PA 500 to a PA 820 and something is throwing me for a loop.  In all of my reports and in the monitoring section under App Scope the firewall is reporting what appears to be ipv6 addresses, they are in the format of: "::678b:540

...

Screen Shot 2021-07-08 at 8.26.00 AM.png

FTP (SCP) Error

Finished generating reports. Please press enter to continue...
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THA

...

NavidAlam by L3 Networker
  • 4484 Views
  • 6 replies
  • 0 Likes

Resolved! Certification expiration alert

Is there a way to generate alerts for certificates which are about to expire?

I mean, for certificates installed and used for example for GlobalProtect, SSL decrypt and etc...

Resolved! LSVPN not working when NAtted via Loopback

Hi Community,

 

I got the following problem:

We have a running LSVPN with primary and secondary tunnel, which are connected on the hub on two different VRs, which sync themselves via iBGP - everything fine so far.

 

One of the satellite sites got two ISP

...

Chacko42 by L4 Transporter
  • 5083 Views
  • 9 replies
  • 0 Likes

The specific URL is not shown in the traffic log

PAN OS 9.1.7

The following traffic log shows the  specific URL

The other traffic log doesn't have the specific URL, and also this log cannot be seen in the url filtering log 

Is this a expected behaviors or something wrong with the customer's envir

...

3.png
4.png
zji by L3 Networker
  • 929 Views
  • 3 replies
  • 0 Likes

IP SLA

Hi,

Could you please help me with a small query.

Do we have any concept like IP SLA   to monitor an ip and deactive route in a routing table.

Thanks

Raj

Adobe Creative Cloud -- Block Uploads

Hello has anyone had any success with blocking the ability to upload content via Adobe Creative Cloud using the Palo Firewall ?  Is it as simple as creating a rule to block UDP\443 traffic for either QUIC, the domain, or both? 

 

Pancast: Have an Idea for an Episode?

Hey Everyone! Have you listened to the PANCast podcast? 

 

PANCast is a Palo Alto Networks podcast that provides actionable insights from cybersecurity experts to customers, helping ensure each day is more secure than the one before it.

 

Since launc

...

Screen Shot 2023-02-01 at 7.41.19 AM.png
Screen Shot 2023-02-01 at 7.45.27 AM.png
JayGolf by Community Team Member
  • 632 Views
  • 0 replies
  • 0 Likes
Top Liked Authors