General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 777 Views
  • 0 replies
  • 0 Likes

DIPP A/A Enviroment Floating IP

Hi Guys,

 

we´ve an Active/active Cluster enviroment. For the normal Internetconnection we will use Source/Hide NAT (DIPP).

At the moment we will NAT on both firewalls the traffic through the interface IP. This works fine, the failover is

ok only one pak

...

mschwab by L1 Bithead
  • 2401 Views
  • 3 replies
  • 0 Likes

topology

Hi,

 

I have the below topology .

Planning to put  PA in vwire mode in betweent the asa and core in active standby.

If r1 fails and asa1 is active and asa2 is standby  ,asa2 will become active .

. Lets say pa1 is active and pa2 is standby .

When asa change

...

PA.png
sib2017 by L4 Transporter
  • 4289 Views
  • 8 replies
  • 0 Likes

http proxy -session end reason decoder.

All traffic via firewall works fine except http-proxy. PC makes connectio with http-proxy but the proxy session keeps on dropping. session end reason decoder. Is that normal for http-proxy app.

Resolved! Console conection using CISCO terminal server

Hi

 

First of all i would like to say that im able to conect with serial cable to the Console Port with my laptop.

 

The issue only occurs when i try to conect to the Console port via Cisco Terminal controller (TTY)

At the begining i thought was a problem

...

Confused over EBL size limit

We have a 3020 running 7.0.8 and are experimenting with MineMeld.

 

As soon as we get close to 5k IPs on the combined EBLs we get an error on a EBL refresh that it's been truncated as it's over the limit.

 

Palo Alto's own KB suggests that on an entr

...

Resolved! Migrating old FW Config to new device

I have 2 PA-500's and have been planning to purchase a new device.  Perect timing with the new PA-800's, fits my needs and then some.  Is it possible to migrate my current configurations from the 500 to the 850?

 

Network-ethernet-Radius-Users wtc as w

...

Resolved! Is the Intel Atom c2000 platform in any Palo Alto Products?

There is an advisory released by Intel (and probably Cisco) about the Intel Atom c2000 platform and a clock signal component failure that can brick devices using that platform.  The Atom c2000 was marketed towards (among other uses) networking equipm

...

bshelton by L0 Member
  • 3389 Views
  • 2 replies
  • 0 Likes

License Transfer

Hello,

 

I am not sure if this is the right place to seek this type assistance.

 

Is it possible to transfer subscriptions from PAN-3050 to VM-300 or VM-500?

 

The client has a pair of PAN-3050 with TP, URL4 and Wildfire subscriptions which will be expired

...

MiZhang by L0 Member
  • 2689 Views
  • 2 replies
  • 0 Likes

Resolved! Skype is not working with allow rule

Hi,

 

We have a demand to allow skype for internal employees. However, we've created a security rule to allow the following applications:

 

-skype

-skype-probe

-ssl/web-browsing

 

Still skype couldn't connect with an error message "please check your internet

...

URL Reclassifications to Unknown in 20170207.20264

Hello,

 

I was just wanting to see if anyone else has noticed that in URL DB 20170207.20264 many sites are being reclassified to Unknown?

 

sites include 

www.maxtend.com.au 

fairfaxstatic.com.au (used for Australian Financial Review website)

cdn.newsapi.co

...

PhilH by L2 Linker
  • 3341 Views
  • 5 replies
  • 0 Likes

Natting issue with new subnet.

I am applying destination nat. Natting public ip(untrust zone) to internal ip(trust zone). Public ip subnet is /28.

When access public ip in the monitoring logs it shows me dst zone as Untrust whenit should show dst zone as Trust.

I have policy in plac

...

  • 23985 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Authors
Labels