General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Export Configuration

Hi, It is probably very simple thing.. I wish to retrieve full configuration of Palo Alto firewall to build new firewall which will NOT be managed by Panorama. Could someone please suggest me procedure or command on how to retrieve (via web or cli - xml or set format) full configuration (local and shared – both together) from Palo Alto firewall ...

session QoS rule

Hi,i have created a qos rule for skype and assign class which is real time ,When I look in to the session details I could not find the session qos rule . How to interpret the details ? for example like flow1 c2s and flow 2 c2s and PREDany related documents Thanks

skyp.jpg
simsim by L4 Transporter
  • 2551 Views
  • 3 replies
  • 0 Likes

Resolved! Policy application question

Hi So I created an application TEST HTTPS tcp/443TEST HTTP tcp/443 and a policy from any where to 10.10.10.10/24 application TEST HTTPS & TEST HTTP allowand then deny everything else if I go to my test box say 10.20.20.20/24 (different network), presume I can ping. I run telnet 10.10.10.10.443 it connects and i type GET /This will fail, bu...

Migrate from Check Point to PaloAlto step by step

Hi guysI have some document that I made about migration from CP to PA,Please feel free to contact me if you had some issue with that migration.If you want the PDF file, please check the following link:http://zwerd.com/2017/09/05/paloalto-migration.htmlAnd also share with me your expariance!:]Good lock [email protected]

Document-page-001.jpg
page2.PNG
Document-page-003.jpg
Document-page-004.jpg
guyzwe by L0 Member
  • 3861 Views
  • 1 replies
  • 3 Likes

7.1 default behavior changes

So I was reading about OS 7.1 because I am planning on upgrading from 7.0.12 to 7.1 and found some information of the default behavior of app-id

appid.PNG
jdprovine by L4 Transporter
  • 6243 Views
  • 12 replies
  • 0 Likes

Resolved! Path Monitoring question?

Hi folks, Preparing for my HA configuration this weekend. 🙂 I have a question about creating a Path monitoring group on the Passive device. While I go through the procedures to configure HA on the Active device, I plan to set a Path monitoring group for our virtual router named SDTSS. When I go through the same procedures on my Passive devic...

OMatlock by L4 Transporter
  • 3320 Views
  • 3 replies
  • 1 Likes

Finally IPv6 over GlobalProtect, or should i say v6IP?

About 2 months ago I was thrilled to hear that PANOS 8 was coming out and that it would bring us IPv6 inside a Globalprotect VPN. After fixing the "licence issue", i finally came arround to doing the upgrade and eagerly started to configure a tunnel for IPv6. To my regret it did not work. As I figured it, it would probably be some remote setting...

P.Braat by L1 Bithead
  • 5474 Views
  • 6 replies
  • 0 Likes

Headsup: AZURE VPN not comming up again, session discarding

Hi, I just want to share a problem i have been troubleshooting. I have lots of vpn's terminating on our FW, haven't had real problems until i started to connect Azure VPN's. After a network hickup they usually did not come up again. I had the hardest time in finding out why. It seems that Azure sends so many IKE initiation packets that if for so...

P.Braat by L1 Bithead
  • 2942 Views
  • 2 replies
  • 0 Likes

Log Card Interface Issues

We have configured a log card interface on one of our 7050 devices for submission to wildfire. This is not working. Our testing shows we cannot ping the default gateway conifgured on the interface. If we ping from the router, then no response is recived, but the packet count on the log card interface increases according for both recicieved and t...

HTTP OPTIONS Method

Hi,I am getting contionous 'HTTP OPTIONS Method' - alertWhat is the reason for thisIf I have multiple vulnerabilty profile ,I want to exclude this from one of the profile or one of the ip(I want to ignore this vulnerabilty checking in a profile or against an IP)How can i do that ?Thanks

simsim by L4 Transporter
  • 3375 Views
  • 3 replies
  • 0 Likes

cookie size

Hi, Is there something settings related to 'cookie size' in pa Thanks

simsim by L4 Transporter
  • 2070 Views
  • 2 replies
  • 0 Likes

Resolved! Path Monitoring Group Name field will not save?

Hi folks, Another HA question, but seems like could be an easy one. I have one test PA-200 OS 6.1.4, enabled HA (for practice), created a Link Group, and now trying to create a Path Group.However, when I type in a name and click off of it, press enter, or click OK the text I typed disappears and unable to save it. I tried it on our production PA...

PathAny1.jpg
OMatlock by L4 Transporter
  • 2451 Views
  • 2 replies
  • 0 Likes

IPSec Tunnel PAN to Cisco ASA - matching for phase 2

Do the proxy ID's on the pan side have to match the ACL defined crypto domain on the ASA? That is - suppose on the PAN side you had for phase II of the tunnel 192.168.1.0, 192.168.2.0 and 192.168.3.0 while the ASA side had only 192.168.1.0 and 192.168.2.0. Would phase II tunnel still come and allow traffic for the first two subnets? Or would bot...

palomed by L3 Networker
  • 2857 Views
  • 3 replies
  • 0 Likes

Resolved! It's time to allow verified PAN customers to change URL categories for specific websites

Long time PAN Customer with huge PAN deployment, we have a very large user base and get multiple website blocked requests daily. We block Parked and Unknown domains for security purposes, it's worth it. However, there's a large amount of new websites that are rightfully listed as parked or unknown, then updated shortly after, then legit websites...

Rags by L2 Linker
  • 4831 Views
  • 5 replies
  • 1 Likes
  • 24443 Posts
  • 125 Subscriptions
Top Solution Authors
Labels