General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! ECMP link monitor 7.1.4

We had an issue with our secondary ISP last night that ECMP didn't handle passing all traffic to the promary ISP as the interface was still up.Does anyone have a suggestion on how to monitor the ISPs and down the link that is having issues? Current c

...

nwetech by L1 Bithead
  • 2773 Views
  • 3 replies
  • 0 Likes

Panorama ISP redundancy

Hey

 

I have a situation that my main site has 2 ISPs i configured the remote PA to talk with panorama thought the External Interface in order to maintain connectivity even if i have problems with the internal network on the remote site.

 

I would like t

...

minow by L4 Transporter
  • 1648 Views
  • 1 replies
  • 0 Likes

PAN-5060 Fans running at Full Speed

My 5060 fans are running at full speed at all times. I attempted to run the follow command "set system setting fan-mode auto" in Operation and Configure mode and it will not work. Getting the "invalid syntax" error.

 

Any thoughts???

DHCP Relay source Interface

Hi all,

 

We're having some difficulties with DHCP Relay on PA 7.0.5.  Our setup looks like this:

 Client <-> L2 SW <-> PA <-> L3 SW <-> DHCP Server

 

We use a VLAN sub-interface on the PA as the default gateway for that subnet and I configured DHCP Relay

...

Question about application group and custom service group

Hi All, 

 

First off I appologize if this question has been answered before.

I have a question regarding the use of application groups and custom service groups in the same security policy. Can traffic identified in the application group use a non stand

...

jmathew by L1 Bithead
  • 1695 Views
  • 2 replies
  • 0 Likes

Warning on commit new config - anyone recognise the cause?

Folks.

 

I made a rule change this morning - first one in a while (fairly static environment of late) - and when committing, got the following warning

 

Error: Invalid id 6 for os WindowsUWP.(Module: useridd)

 

Anyone recognise this/know the cause/know wha

...

darren_g by L4 Transporter
  • 1610 Views
  • 1 replies
  • 0 Likes

Cannot enter "Maint" at boot via cli

All,

 

somehow I lost connection to my PA-200. Im trying to do a factory reset on it and I am not able to enter 'maint" during boot via console.  I am using putty .  When I try, it just keeps loading the kernal.  is there a way to pause to enter "maint

...

2016-10-07_14-46-38.jpg
BryanMay by L1 Bithead
  • 2558 Views
  • 2 replies
  • 0 Likes

PAN-OS 6.1.2 issue with threat updates

I'm looking to see if anyone else is having an issue with dynamic updates past the 596 threat update on a 3050 running 6.1.2.

 

Here is what we are seeing. A while ago the 596 threat update came out and we encountered an issue. This was a known issue b

...

Kadall by L0 Member
  • 1199 Views
  • 0 replies
  • 0 Likes

Resolved! PA-7050 LACP causing delay in fail-over times

We have an HA A/P PA-7050 cluster running 7.0.2 with QNPC (40G). The 40G links are bundled in AE1 with LACP enabled. We noticed during testing that LACP causes 8-10 ping loss during a fail-over event. With LACP disabled we have a 1 ping loss during f

...

lacp.jpg

U-Turn NAT with Port Address Translation in a DMZ

Hi Community,

 

I am configuring my first PA-200 and having a difficult time. I have a /27 external network and have the PA-200 seeing the internet properly. I have internet untrust zone setup as l3 on Int 1.1, and a DMZ setup as l3. The DMZ zone is on

...

DMZ Depiction PA-200.jpg

Resolved! Custom applications and application override

I'm looking to get a better understanding of how custom applications work in relation to application override policies vs security policies.

 

I have created a simple custom application with just a tpc port for an internal application. There appears to

...

Priority in PAN-QoS

Hi, 

 

When you are configuring QoS, it's possible to define more than one profile, and in this profile put 'til 8 Class defined. 

 

When you apply over the egress interface, it's possible to add this Class based over an source Subnet.

 

Here is my questio

...

nanukanu by L2 Linker
  • 3307 Views
  • 5 replies
  • 0 Likes
  • 24215 Posts
  • 99 Subscriptions
Top Liked Authors
Labels