Integration Discussions
This forum was created for Palo Alto Networks partners and customers to collaborate on topics related to integrating Palo Alto Networks products.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Integration Discussions
This forum was created for Palo Alto Networks partners and customers to collaborate on topics related to integrating Palo Alto Networks products.
About Integration Discussions
This forum was established for Palo Alto Networks partners and customers to collaborate on topics related to integration on the Palo Alto Networks products.

To start a new topic, simply click "New Message" below.

Discussions

Resolved! Cannot integrate with AD Server

I am trying to integrate PA firewall with newly installed Active Directory server (windows server 2019) but it is not connecting. I get the error Failed to connect to 10.x.x.x(10.x.x.x):389 and the server monitoring status says host unreachable. The group mapping, group include list does not populate as the firewall has not made connection yet...

Grekko by L1 Bithead
  • 10269 Views
  • 3 replies
  • 0 Likes

XML API - Need to replace services for a security rule via XML api - currently api call is appending new port

Hi - I create a service (tcp-443) and then create a security rule that uses this service as the service member. This works. Then, if I call the same API call with the same xpath and provide a different service, say tcp-449, the resulting security rule has *both* tcp-443 and tcp-449 in the Service column: First call is <service>["tcp-443"]&...

Connection between PA-5020 and Cisco 9407

Hi there, I have 2 sites on 2 different locations. On the first one i have a core router Cisco 9407 and on the other site i have a Firewall PA-5020. Since the ownership of the line between the sites is not ours do you have any suggestions how to connect the NGFW and the Core router securely?For example I will use MACSEC for the connection betwee...

NPen89 by L0 Member
  • 2142 Views
  • 0 replies
  • 0 Likes

DicksSportingGoods Feedback

If you’re questing for a baseball product or cycling accessories, you can assure the goods of **bleep**’S sporting. Are you aware of **bleep**’s? It’s the biggest provider of athletic types of equipment in the United States, and their shops are scattered worldwide. dicks

riteaid by L0 Member
  • 1797 Views
  • 0 replies
  • 0 Likes

Panorama Plugins

hey, do anyone know if paloalto intends to open the plugins infrastructure so customers can add plugins to enrich panorama functions, menus UI and functions.. like other vendors have ?

minow by L4 Transporter
  • 3069 Views
  • 0 replies
  • 0 Likes

Automate Minemeld .lst entries

Needing Automation. Our Security analysts often send an email with URL(s), IP(s) that need to be Allowed/Blocked. We have experimented with EDL and Minemeld and are successfully using each. We are going to consolidate to using only Minemeld for these requests. We would like to automate it, so that the initial request can easily be approved an...

Policy Based Forwarding - Enforce Symmetric Return

Dear All,I integrade PALOALTO to Tacacs+ for authenticator, but I got message error as belowAuthentication to TACACS+ server at '192.168.101.46' for user 'user1'Server port: 49, timeout: 10, flag: 0Egress: 192.168.101.42Attempting CHAP authentication ...CHAP authentication request is createdSending credential: xxxxxxCHAP authentication request i...

HengTIDC by L0 Member
  • 10534 Views
  • 4 replies
  • 0 Likes

Recent SAML integration with Global Protect

I've recently moved from using RADIUS authentication for Palo Alto and moved authentication over to SAML so I can integrate with Duo Security. With this change, the domain info is no longer passed by SAML to Global Protect thus breaking several policies that I had that we applied based on their AD credentials. Is there any way to fix this so I...

cdb_unoh by L1 Bithead
  • 10747 Views
  • 2 replies
  • 0 Likes

VM-serries firewall for aws ECS cluster

How I can deploy VM-series Auto scaling for ECS cluster.I already have ECS cluster, vpc, subnets on aws and subscription of VM-Series Next-Generation Firewall Bundle 2 on aws market place. I need to configure VM-series firewall.Could any one help me to setup VM-series firewall.

Palo Altp - Cisco WLC Anchor - Foriegn

Hi Created a new zone on PA ether1/5 configured all interfaces. Installed a Cisco 5520 WLC as and Anchor WLC and setup piolices to allow the Capwap tunnnel to the Foreign WLC.This was a 1 legged approach, WLC in LAGThis worked, tunnel is up and stayed up. The client traffic breaks out to a layer 2 connection to a 3rd party managed guest soluti...

Scooby by L0 Member
  • 5920 Views
  • 1 replies
  • 0 Likes

dynamic interfaces (DHCP) and full site to site

Hi I have Palo-220 that move every X- days from one office to another office the Palo have a Lan interfaces and wan interfaceinterface Wan (eth1/1) configured with DHCP and automatically add a default route checkbox also i have a full Site2Site tunnel that all (0.0.0.0/0) network need to go into the tunnel i have to static route in routeing tab...

SDP Issues with VOIP deployment

Hi There, We have a hosted mitel voice solution that we are seeing call quality issues in the inbound direction, ie calls in. I am attempting to troubleshoot this with our provider and they are seeing SDP attributes being added from our firewall. I'm relatively new to the voice game so please excuse the ignorance! I have disabled SIP ALG and app...

  • 79 Posts
  • 27 Subscriptions