General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Global Protect with self-signed certificate

Hi, 

 

We have configured GlobalProtect with a self-sign certificate working properly, but when we try to connect through global protect we always receive this advise about "this certificate is not valid...." and we have to accept it to continue. Thi

...

Resolved! Firewalls accessing Panorama: best practice

Hi,

 

I'm looking for a best practice when deploying Panorama accross multiple sites that do not really have any interconnections (and have quite a few overlapping subnets).

From what I understand, the firewalls themselves initiate the connection tow

...

Arne-VDH by L3 Networker
  • 4152 Views
  • 2 replies
  • 0 Likes

Blocking Internet Access based on User-Agent

I am currently researching a way to be able to intercept traffic from an unsupported IE browser and then be able to feed that information about the host, mainly FQDN hostname or IP address of the host into the PAN dynamically based on the user-agent:

...

Resolved! PA200 disaster recovery option...?

Hi all --

 

I curently have one PA200 with all four eth ports taken (internal/trust network, internet/untrust, dmz, voip vlan), as well as the mgmt port connected to the internal network.  I'm looking to get a disaster recovery plan in place, but, as

...

thatguy by L2 Linker
  • 3728 Views
  • 7 replies
  • 0 Likes

Resolved! Higher Management CPU post upgrade to 7.0.4

I've got a 5060 A/P pair that was running 6.1.4.

 

We are/were doing :

 

SSL forward Intercept

SSL Mirror

7 AD Group Mappings

Transparent Captive Portal

4 UIA

 

Pre-upgrade our MGMT CPU was around 20%.  Post upgrade to 7.0.4 we're 70%.  There have be

...

Failed to find PANPG virtual adapter interface

Hi all,

 

I am experiencing this issue with Global Protect : "Failed to find PANPG virtual adapter interface".

The version of GP is the latest released 2.3.3.

Version of client is Windows 8.1.

I have already tried:

 

- Uninstalled Anti-Virus

- Disabl

...

Failed to find pan PG.JPG

Configure Backup ISP

 

 

 

 

 

Not sure this is the right venue or forum to post this, but I’m looking to set up an automated failover to a backup ISP line per the attached network diagram of my environment.

 

I’m new to PAN and the PAN way of doing things so thought I’

...

PANBackupISP.png

PAN HA P/A with GLBP on core

Hi Everyone,

 

Is it possible to setup a passive/active HA setup when the core switch pair are using GLBP to load balance end-user traffic ? Essentially, I will have two cores in A/A and the PANs in P/A. I am using PA-500s.

Panorama connectivity issue

Hi everybody,

 

When I configured my new firewalls to register with my panorama, they didn't appear.

I checked the following points:
- Connectivity between my firewalls and my Panorama : OK => I do some packet captures on both side
- TCP bidirectional t

...

MT 3.1 and CheckPoint VSX

We're running a really old version of CP 71.40 running VSX with multiple virtual firewalls.

 

This document describes where to get a config file from, but this does't account for a virtualized enviornment and the file nor directory exists for these v

...

Resource-unavailable for http traffics

Hi All,

 

Some of the sessions are ended with Resource-unavailable reasons. Almost all traffics in these sessions are web-browsing and some updates traffics on port-80.

 

All https-443 are working fine. this issue happened for 4 hours on last week. 

...

Javith by L3 Networker
  • 8882 Views
  • 6 replies
  • 1 Likes

Resolved! Agentless USER-ID - rules

Good Day

 

I'm testing user-id in policy-rules and its not working the way I thought it would.

 

Example Rule

src zone/ip - Zone A/any

dst zone/ip - Zone B/any

user - gdc\test.user

application - any

service - application-default

action - allow

 

I st

...

burtond by L2 Linker
  • 4641 Views
  • 12 replies
  • 0 Likes

creating vsys

 

Hi ,

I would like to create , vsys for routing .P resently fw is runnin in virtual wire mode .
How i can copy the same policy which is in another vsys

Thank you

 

sib2017 by L4 Transporter
  • 1582 Views
  • 1 replies
  • 0 Likes
  • 24272 Posts
  • 99 Subscriptions
Top Liked Authors
Labels