General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Destination NAT - Entire Subnet

I have a PA-500 running PANOS v4.1.10.   Is it possible to configure a single destination NAT rule that translates the address for any given /24 subnet on to the equivalent address in the destination /24 address; e.g. Original Packet Dest: 192.168.50

...

kroche by Not applicable
  • 4434 Views
  • 4 replies
  • 0 Likes

Resolved! problem with management plane

Hi,

I am not able to access the management website. The website does not load. When I try to restart the management plane from ssh with a command "debug software restart management-server" I get this error:

2014-05-08 12:08:11.503 +0200 Error: pan_rea

...

UMWL by L0 Member
  • 4309 Views
  • 1 replies
  • 0 Likes

Amazon AWS VPN (VPC)

Hi all,


We are working on moving some of our servers to AWS and they require 2 VPN redundant tunnels to be configured with our network. Amazon suggested to terminate the VPN on Internet edge router because the VPN redundancy requires BGP. Between the

...

Resolved! Globalprotect terminating in its own vsys?

I'm trying to setup GlobalProtect to terminate in its own VSYS (for administrative purposes), i.e the Portal and Gateway should reside in its own VSYS and not in my external vsys.

But I would like to be able to use the same physical interface as the e

...

HansH by Not applicable
  • 1739 Views
  • 1 replies
  • 0 Likes

domain filtering

Hello, I have a big network with thousands of systems, I have 3 domains  , I want to know and log  all access from outside off my network to any inside server that the url is  different to *.mydomain.com.

If i use url filtering and in block I put * an

...

javalero by L0 Member
  • 1798 Views
  • 2 replies
  • 0 Likes

Security rule for url filtering - best practices?

I would like to know what is the impact, if any, when configuring a security policy with allow action and associate with a url filtering profile if we use application as any or application set to web-browsing.

I understand the url filtering is only ap

...

Borgiani by L0 Member
  • 1743 Views
  • 1 replies
  • 0 Likes

License for IPsec and SSL VPN

Hi all,

  I need to know if we need a license to acivate or configure site to site VPN ( i.e: between Cisco ASA and PaloAlto), and also for remote client (ssl vpn). if it's possible can someone please help me with the procedure to follow for these two

...

Lahcen by Not applicable
  • 8775 Views
  • 1 replies
  • 0 Likes

Resolved! License for IPsec and SSL VPN

Hi all,

  I need to know if we need a license to acivate or configure site to site VPN ( i.e: between Cisco ASA and PaloAlto), and also for remote client (ssl vpn). if it's possible can someone please help me with the procedure to follow for these two

...

Lahcen by Not applicable
  • 3561 Views
  • 1 replies
  • 0 Likes

Stats Discrepancy in the ACC

Has anyone else noticed this?

Go to the ACC and sort it by Bytes (I believe this trick works regardless of the sort criteria, but it’s easiest to see this way). Make a note of the top three or so values

Next, Click on one of these, I picked the top: we

...

djr by L4 Transporter
  • 2257 Views
  • 4 replies
  • 0 Likes

Reporting on User downloads and uploads

Greetings,

Disclaimer:  Our regular Network Engineer is out on short term disability so I am the Sr. Systems Administrator trying to fill in.  Palo Alto reporting is not my everyday thing so I apologize in advance if this request seems to a bit basic

I

...

Strange VPN behaviour

Hi all!

Some of my colleagues have problems accessing certain services like TFS, Intranet, and Office 365(outlook, lync) through VPN. The weird thing is that for others it might work either 100%, 50% or whatever feels right that day, it seems.
What cou

...

Palo-Alto upgradation From 5.0.x to 6.0.x

Hi All, We are having PA-5050 & and PA-3020 model running on software version 5.0.8 & 5.0.9 and we are planing to upgrade it to 6.0.2. We firewall is running in Active/ Passive cluster. Please any one help to know the processes and suggest which vers

...

Sourabh by Not applicable
  • 1469 Views
  • 1 replies
  • 0 Likes

site to site vpn qestion

We're moving from Checkpoint to PAN. For site to site vpns, I'm assuing i should set up a logical subinterface? How do you ensure its floating/shared in an HA cluster?

dvlacic by Not applicable
  • 1933 Views
  • 2 replies
  • 0 Likes
  • 24208 Posts
  • 99 Subscriptions
Labels