Beginnings are not always perfect. Whether you started your Palo Alto Networks journey years ago or just recently, tell us what you learned early on that you wish you had known before.
If there was one thing, or maybe more, Live Community users would love to hear about it. Share your stories, your tips to help other users along the way.
Read a tip you like, make sure to like it or let them know by commenting!
The most popular and helpful stories will get you a cool new Live Community t-shirt!
Looking forward to reading all the great stories!
It is probably will be more as a feedback from my side but every time l am dealing with Palo issues, either it is through the TAC or community l always come across nice people. Didn't have any negative experience. All information really here and l would never believe that the community can be so helpful. Keep it up and thanks all!
p.s l also like this new t-shirt :0
I have less than a year experience, but I wish I had known to look in the "Unified" logs for the reasons things would be blocked. I've seen traffic allowed in the traffic logs but blocked because the file that was attempted to be downloaded wasn't of a permitted type. It was confusing at first when I saw the traffic permitted.
The benefit of using the forums unless I actually need emergency support through TAC. A lot of the frontline support folks love to simply get your configuration and 'verify it for issues' when there really isn't a need for it; heck simply opening up a ticket for the weird URLs I was seeing on my botnet report the first line support was adimit that the predefined report was in some way misconfigured on my end.
In the past I've worked through issues soley by myself because I loathed contacting support and having to do the same troubleshooting steps I had already done multiple times, or hearing how I should try to restart in the middle of the day to fix the issue. In the forums it's by far more likely that you'll either get told the solution or be told to restart a specific process, instead of restarting the whole data/management plane.
I've been administrating a Palo Alto Firewall for 3 years now and think it's a really good tool, it friendly and faily easy to configure and manage. It has helped to improve our traffic controll and solve connection issues. I do encourage other administrators to use it!
i've been working with Cisco ASA before start using Palo Alto more than 4 years ago. since the first beginning i've appreciated the very friendly web interface and the huge amount of feature which are very helpful to manage our network and security.
especially indicated for corporate and sysadmins focused on the websecurity, you have a lot of automated and manual tools to prevent, detect properly attempts of breaches and vulnerabilities.
growing and growing version after version, i can't wait to see and test the 8 version.
If I knew then what I know now.....
1. Use Panorama for (almost) everything. Building all objects, profiles, zones, and policies in Panorama has numerous manageability/scalability benefits. Other than network interfaces, virtual routers, and IPSec tunnels, build everything else in Panorama and push it to the firewalls.
2. Use nested device groups in Panorama to create a hierarchy for shared security policies. This allows a single rule, created once, to be applied to multiple firewalls.
3. Template grouping should be based on device model do to zone limitations. Device grouping should be based on function or purpose.
4. Using tags, and corresponding colors, in your security rules helps with visual grouping the rules, and can also help with searching and filtering.
I'm about 2-months in, and I'm still looking for what I need to know.
What I most want is the "How to think Palo Alto" guide - the biggest picture of how the parts fit together, and the minute details of what little "other-guy" process or method doesn't work here.
I'll publish it myself once I think I have it ;)
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!