General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4111 Views
  • 0 replies
  • 0 Likes

Resolved! DNAT issues into servers with teamed nic's ?

DNAT issues into servers with teamed nic's ?Anyone seen issues with this before ? I literally can't DNAT into servers with teamed nic's.. I'm going to run a wireshark capture on the server to see what is going on..

mpgioia by L3 Networker
  • 10821 Views
  • 18 replies
  • 0 Likes

PA upgrade problems

Hi, we have a cluster with PANOS 7.0.6, we want to upgrade to 7.1.8. In a similiar upgrading path we were affected for a bug related to VPN, which was applying when you jump to 7.1.0 an then 7.1.8. So we would need to jump directly to 7.1.8. On the another hand, when we have upgraded others cluster A/P, downloading version 7.1.0 and 7.1.8 and j...

Qos question

Hi,Let's say user wathing youtube , to limit the user's traffic ,do we need to create qos profile for upload and download ?Thanks

simsim by L4 Transporter
  • 6403 Views
  • 10 replies
  • 0 Likes

PA-200 FYI

I haven't seen this mentioned so I thought I would put it out there quick. Palo Alto has identified an issue with PA-200 units with the serial numbers ange 001606044723 to 001606075266 that have SSDs that do not meet their standards. If you have an effected unit you can get it replaced by following the steps at the below link. https://support....

BPry by Cyber Elite
  • 6478 Views
  • 1 replies
  • 2 Likes

Forward segments exceeding TCP content inspection queue

Hi, On a new PA-3020 Firewallcluster I decided to disable the default setting "Forward segments exceeding TCP content inspection queue". Practically everything was working as it should. But onfortunately the devil is in the details. I had very few connections, specially http downloads, which where causing problems. Sometimes the same download wa...

Remo by L7 Applicator
  • 18176 Views
  • 7 replies
  • 0 Likes

Resolved! Virtual Firewall

Dear All,is it possible to make a Local Virtual Firewall using Hyper V or Vmware for the purpose of learning the functionalities of the Virtual Firewall ?

Resolved! Can't join Windows Updates server, application "not applicable"

Hi ! I'm trying to connect the server to the Internet in order to download and to install updates. My server is a Windows Server 2016, so i'm trying to reach Windows Updates servers. In order to do that, I created a rule in the firewall : The address group contain theses addresses : To verifiy that my server can reach Windows Update server, ...

Regle SRVACD WU.PNG
adresse.PNG
Log.PNG
Srv - WU not applicable trame.PNG

Adding a section title to a group of rules

Hello,is there a way of adding a title/header to a group of rules in order to create some logical structure/grouping in the rule set?In Checkpoint this is possible and we find that it helps keeping a big ruleset organised.Thank you.

NicPezzi by L0 Member
  • 3583 Views
  • 1 replies
  • 0 Likes

Whats wrong with my xpath??

Hi all, trying to delete a single object from a static address-group. Why does it keep deleting entire group?? My syntax below: https://x.x.x.x/api/?type=config&action=delete&key=LUFRPT1BeWFJamVEYmdUV0JXZTdjNlFzOUMzdmhOaXM9RkdEb0lMT1g1WVNhMk9mL3&xpath=/config/devices/entry/vsys/entry[@name='vsys2']/address-group/entry[@name='clyde']...

Using unlicensed VM100.

I have a VM-100 on VMWare ESXi running 7.0.4 . The demo license has expired for VM.Would I be able to us it for testing still ( not using any url,threat features). I am see speed issue from trust to untrustand traffic just trickles.

How can I get dual ISP with DUAL IPSEC Tunnel to work with static routes and no tunnel monitor?

HI, How can I get dual ISP with DUAL IPSEC Tunnel to work with static routes and no tunnel monitor? I want the IPSEC tunnel to only failover when the primary circuit goes down. Problem I am having is the static route metrics is not taking over when the primary ISP and primary IPSEC tunnel goes down. Metric is 10 for primary tunnel and 20 for bac...

junior_r by L3 Networker
  • 3769 Views
  • 3 replies
  • 0 Likes

FQDN jobs FAILED

Hi, We have added several FQDN objects and its not working. If we run update.symantec.com (Objectname update.symantec.com):Not resolvedus.archive.ubuntu.com (Objectname us.archive.ubuntu.com):Not usedxxxxxxx (Objectname HOST_xxxx13):Not resolved 2017/04/25 13:35:54 29960 FqdnRefresh FIN FAIL 13:36:042017/04/25 13:31:44 29959 FqdnRefresh FIN FAIL...

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels