Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
jforsythe by Community Team Member
  • 27 Views
  • 0 replies
  • 0 Likes

BlackNurse Denial of Service Attack

http://www.netresec.com/?page=Blog&month=2016-11&post=BlackNurse-Denial-of-Service-Attack

Has anyone here tested the effect of this on any PAN-devices ?

http://blacknurse.dk says:
LIST OF REPORTED AFFECTED PRODUCTS :
Cisco ASA 5515, 5525 (default setting

...

Dulle by L2 Linker
  • 3943 Views
  • 4 replies
  • 0 Likes

Resolved! Different subnets on the same interface

Hi,

 

my ISP has assigned me with a /30 for the p2p connection and it is routing a /24 public subnet towards that /30. Meaning the WAN interface in the Palo will have to respond to many different ips on two different subnets. I haven't found any Kb tha

...

myrdin by L2 Linker
  • 10047 Views
  • 10 replies
  • 0 Likes

Block page for security policy matches

Is there a way to return a block page to users when their connection is blocked not by the URL-filter but by a security policy?

 

We have a security policy that blocks all outbound traffic to a list of foreign countries.  The problem is when users atte

...

fmurray by L1 Bithead
  • 1719 Views
  • 1 replies
  • 0 Likes

how to install PANOS in new HD

Hello Community,

 

I have my PA2020 with issues. The device is booting from PanOS Bootloader.

 

What is the proceess to upload and install again the PANOS?.

 

PA2020.JPG
Apadilla by L3 Networker
  • 2937 Views
  • 5 replies
  • 0 Likes

Is there any reason that tunnel interface will go down

Hi There,

 

I configured two IPSEC VPN on PA, as PA has two ISP connectivity. Configured a PBF to forward the traffic through primary tunnel interface and enabled monitoring to monitor trust interface of remote PA. A route was configured to forward the

...

fozail by L3 Networker
  • 4351 Views
  • 7 replies
  • 0 Likes

Resolved! Snapchat

Has anyone had success blocking Snapchat? We have a rule for blocking "bad" apps and Snapchat is presently in this list. In testing I can see that a reset-both occurs when the firewall detects the traffic and the application is recognized as Snapchat

...

rmiller1 by L1 Bithead
  • 12610 Views
  • 12 replies
  • 0 Likes

Resolved! Miner polling interval ?

I can't find information about polling interval in Dev guide or 'How to Write a Simple Miner'. What's the minimum, 1s, 60s ? Can it be cron like with day of the weeks or months etc (but less than 60s) ? 

niuk by L3 Networker
  • 5116 Views
  • 2 replies
  • 0 Likes

Resolved! Put Cisco MAC on PAN firewall? / Change interface MAC address

We're migrating from Cisco ASA to PAN firewalls.

The ASA is default gateway for many subnets & hosts.

 

To achieve a smooth migration, one thought is to put the ASA's MAC address on the PAN firewall, so that the hosts don't need to ARP for the new MAC.

 

...

khuang by L0 Member
  • 2553 Views
  • 3 replies
  • 0 Likes

multi-vpn

Is it possible to use a single install of globalprotects with multi vpn connections? I know you can set it up on a cisco vpn client but I don't see a way to do it on the GP client except for manualy changing the portal and lately that hasn't worked a

...

jdprovine by L4 Transporter
  • 2630 Views
  • 7 replies
  • 0 Likes

Change HDD in PaloAlto 5000 raid

Hi,

 

We have a PA-5000 with 2 HDDs. One of them had an error and we asked for RMA. We have received 2 HDD for replacement.If the new HDD has the same part-number as the old HDD working , we wil only add a new HDD but if the model is different we have

...

Resolved! BFD yet?

Has PaloAlto implemented BFD yet? I searched the previous discussions and found a thread from 2011 that indicated it might be looked into.

Disk Space problem on root

Dear All

 

I'm facing issue with low disk space on root in my palo alto PA-3020.

 

Please see below

> show system files

/opt/dpfs/var/cores/:
total 4.0K
drwxrwxrwx 2 root root 4.0K Mar 13 2016 crashinfo

/opt/dpfs/var/cores/crashinfo:
total 0

/var/cores/:
total 3

...

GlobalProtect Remote User VPN Connection Issues

 

Hi All,

 

We deployed PA3020 firewall to our production. We have given vpn to client side and it working fine but the problem is they are no any disconnection button to disconnect from vpn client.

 

 

Please advice me

Thanks.

 

test.JPG

VM PA to VM PC Unable to ping.

Hi,

 

I've created a VM LAB. But, I facing some issue.

 

VM Details: VMnet3: 10.128.1.0 (HOST)

 

PA Details: int 1/1 10.128.1.254/24 mac: aaaaaaa1(sampleonly)

 

PC: IP: 10.128.1.2

DGW: 10.128.1.254

 

I already enable ping on Profile(PA). Disabled Firewall on PC

...

  • 23584 Posts
  • 107 Subscriptions
Labels