General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Deny any any ruleset

So if you accidentally put the any any and deny ruleset at the top of the panorama firewall and it wont let you in through the web interface. How would we be able to get into the panorama to change it back to the previous configurations??

Port forwarding through ipsec tunnel

Hello,

 

I have two Pa-440's.  One 440 has a public static ip and the other is just dhcp as of right now.     I do a site to site to site vpn working between them.  

 

I setup an original port forward on the public  static ip device to a local host a

...

User id integration cisco ISE

hi i did User id integration cisco ISE using syslog field identifier as article http://k12itdir.blogspot.com/2016/02/paloalto-user-id-from-cisco-ise-nodes.html?m=1 and its working fine . Problem its just send user name without domain and since i have

...

mhmameen by L0 Member
  • 172 Views
  • 2 replies
  • 1 Likes

Resolved! Using the REST API to create a bunch of Address Objects

I have to create a large number Address Objects and would like to use teh REST API to do so.  I've seen a number of examples at adding various things, but I'm running into an issue with these specific shared objects.  The all live in a device group c

...

DaveFitz by L0 Member
  • 187 Views
  • 1 replies
  • 0 Likes

Anydesk issue.

Hi everyone!
I have some issues with anydesk application. It has ssl issue because of decryption, I think.

I've added *.anydesk.com ind 'SSL decryption exclusion', but it didn't worked.

Maybe some of you have faced such kind of issue?

Thanks in advance!

anydesk.jpg

setting up multiple internet connections

Translator
 
 
 
 

 

Translator
 
 
 
 

Hi everyone. I have a PA-220 firewall. It is currently connected via interface 1/8 to an internet connection that I will soon have to discontinue, and which I will call GW1 here.
At the same time I

...

gnesper by L1 Bithead
  • 417 Views
  • 5 replies
  • 0 Likes

Resolved! SSL Inspection issues with GlobalProtect users

We're having some strange SSL/TLS Inspection errors while on GlobalProtect. We are getting unsupported-parameter errors while a user is connected to GlobalProtect trying to get to any internet site, including things like google.com. Doing a packet ca

...

Claw4609 by L4 Transporter
  • 2004 Views
  • 12 replies
  • 0 Likes

TUNNEL STATUS RED AWS PAN TO ONPREM PAN

Hi Guys,

 

Need your help, as I cannot figured out what's wrong with my configuration. Both side of my Phase 1 are working fine but when it comes to Phase 2 connection is not complete. Any idea how to fix this issue?

 

Here is my AWS PAN configurati

...

MCipriano_0-1714708155306.png
MCipriano_1-1714708264907.png
MCipriano_2-1714708425551.png

Resolved! What does the configd process do for PAN-OS?

I'm documenting new services in PAN-OS present in 10.x. What does the configd process do? It appears to bind to udp/28879 (if only accessible "internally"). I do not see this service described in the Commonly Used Processes/Daemons url found here: 

h

...

jasonroy by L2 Linker
  • 1041 Views
  • 3 replies
  • 1 Likes

Cyserver stopped by ntdll.

Hi team, 

 

Recently, We discovered endpoints that got disconnected from the console and there is no clue on trapsd why it happened because the agent didn't record logs since its last_seenn on the console, for example; the agent has a last_seen on 1

...

MarcoMJ by L1 Bithead
  • 190 Views
  • 1 replies
  • 1 Likes

Email laerts for just zone protection alerts

Hello all,

 

I have applied a zone protection profile to the outside zone on my firewall. I am wondering how I can configure the firewall to receive email notifications just for alerts for this zone protection profile. Like every time an IP address i

...

GlobalProtect and other VPNs

Good afternoon friends  

I have some doubts regarding the application of GlobalProtect VPN, which is mandatory in my work.

I have a few questions and would love to hear the community's answers regarding the below.

I'm in Ireland and I would like to

...

Explicit proxy chaining

 

Hello,

 

I like the explicit proxy functionality but missing option to use proxy chaining and forward all the explicit proxy requests to an upstream proxy.

 

Some ideas how to archive this? 

 

Thanks for any recommendations

Lumir

 

itsnoc by L1 Bithead
  • 211 Views
  • 1 replies
  • 0 Likes

Panorama Push Failure

hello

I am deploying a GP Portal/Gateway configuration on a Panorama platform 

the commit to Panorama is successful 

the push to the device is failing   as shown below

tunnel.199 has a virtual router configured 

has  anyone seen this issue before ?

...

SByrne_0-1714735050886.png
S.Byrne by L2 Linker
  • 228 Views
  • 2 replies
  • 0 Likes
  • 24235 Posts
  • 99 Subscriptions
Top Solution Authors
Top Liked Authors
Labels