General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4221 Views
  • 0 replies
  • 0 Likes

Limting Globalprotect client access via IP address

Is there a way to allow specific GlobalProtect users to only connect from specific public IP addresses? For example say I only wanted to allow user1 to connect from IP address 1.1.1.1, and if user1 connects from any other public IP address, or if user2 is trying to access from 1.1.1.1, to have that access be denied?

Resolved! Newbie question on polices

Hi Got to test pa-3060's got them setup in HA active active mode. I have a LACP trunk setup with 2 vlans of it. vlan 213 - zone trustedvlan 215 - zone devi have ospf and ip addresses assigned and working on the 213 side of things. so I can ping it from the rest of my network.vlan213 gets DGW from OSPF. I have .2 and a .3 address assigned to pa1 ...

Resolved! OSPF LSA Threshold: Security Finding

Wondering if there's a way to configure a threshold for OSPF LSA updates/messages?Or if such a threshold is already in place by default on Palo Alto firewalls. Something that can maybe drop anything more than say 7 LSA messages in 5 minutes.Apparently, there's a security threat related to a device getting DOS'd by an overwhelming flow of LSA me...

Resolved! Exposing Videoconference - "Incomplete" traffic allowed

Hi allI have tried to expose Videoconference system behind Palo Alto.Unfortunately using App ID in security policy I have seen Palo Alto allows a lot of "incomplete" traffic.That's really an issue: When enabling h.323 in security Policy App id engine starts to allows every port in order to find something related to this protocol and obviously yo...

TheRealDiz by L4 Transporter
  • 10713 Views
  • 14 replies
  • 0 Likes

BFD Dropping During Firewall Failover

Having an issue with BFD. I have BFD configured between the Palo Alto and a couple of routers (BFD Single Hop). When a firewall failover occurs, this causes the BFD peering to drop and come back. I would not anticipate this to happen. This causes a unicast path between multihop BFD peers to drop in turn causing multihop BGP peerings to drop as w...

Resolved! Management Interface traffic logs

Hi guys,Is there a way to see traffic logs of management traffic? I'm trying to troubleshoot user-id redistribution source from the management interface.ThanksNetWorkZeus

Resolved! Customizing Prototypes in Office365

I note that Office 365 recently updated the URL definitions to include microsoft Teams etc. Has anyone customized the prototypes to support this change ? https://support.office.com/en-gb/article/Office-365-URLs-and-IP-address-ranges-8548a211-3fe7-47cb-abb1-355ea5aa88a2 Drew.

Resolved! Panorama shows FW as disconnected after App and Threats Update

So I got the mail today about the certificate which is about to expire.I installed App protection 694-4000 on the Panorama as described .After the reboot I no longer have communication between my 2 PA-2050 boxes and Panorama. The log is no longer updated and it shows the 2 boxes "Device State" as Disconnected. I currently run 7.0.10 on all devic...

Resolved! DNAT issues into servers with teamed nic's ?

DNAT issues into servers with teamed nic's ?Anyone seen issues with this before ? I literally can't DNAT into servers with teamed nic's.. I'm going to run a wireshark capture on the server to see what is going on..

mpgioia by L3 Networker
  • 11043 Views
  • 18 replies
  • 0 Likes

PA upgrade problems

Hi, we have a cluster with PANOS 7.0.6, we want to upgrade to 7.1.8. In a similiar upgrading path we were affected for a bug related to VPN, which was applying when you jump to 7.1.0 an then 7.1.8. So we would need to jump directly to 7.1.8. On the another hand, when we have upgraded others cluster A/P, downloading version 7.1.0 and 7.1.8 and j...

Qos question

Hi,Let's say user wathing youtube , to limit the user's traffic ,do we need to create qos profile for upload and download ?Thanks

simsim by L4 Transporter
  • 6512 Views
  • 10 replies
  • 0 Likes

PA-200 FYI

I haven't seen this mentioned so I thought I would put it out there quick. Palo Alto has identified an issue with PA-200 units with the serial numbers ange 001606044723 to 001606075266 that have SSDs that do not meet their standards. If you have an effected unit you can get it replaced by following the steps at the below link. https://support....

BPry by Cyber Elite
  • 6500 Views
  • 1 replies
  • 2 Likes

Forward segments exceeding TCP content inspection queue

Hi, On a new PA-3020 Firewallcluster I decided to disable the default setting "Forward segments exceeding TCP content inspection queue". Practically everything was working as it should. But onfortunately the devil is in the details. I had very few connections, specially http downloads, which where causing problems. Sometimes the same download wa...

Remo by L7 Applicator
  • 18392 Views
  • 7 replies
  • 0 Likes
  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels