General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Clientless VPN and Java/Javascript

Hi

 

We have a clientless VPN and app set up to use https on tcp 8443 but the page is not displaying at all. Connectivity has been proven end to end so all the rules are in place.

The app points to a webserver that hosts a portal and uses Javascript.

 

So

...

Resolved! CDP Connection Issues w/HTTP application incomplete

I have a remote 820 that is connected to a 5250 via an IPsec tunnel. My CDP is directly connected to the 5250.

 

820<=====>5250<+++++>CDP

 

When I restart the IKE phase on the tunnel, I see the port 80 traffic on my 820, but is says the application i

...

PA-HDF login: on a PA200

I am new to PA and bought a device and configured it but forgotten my password.

i went to maint mode and did factory reset to restart my config again

my device entered PA-HDF login: i tried admin/admin and getting incorrect password

any advise how to

...

Dalton by L0 Member
  • 2362 Views
  • 1 replies
  • 0 Likes

The FQDN issue could not be refreshed.

Hello all,

We were using two FQDNs that get the same IP from 9.1.14 version.

And I recently deleted one FQDN. Then there was an issue where FQDN was applied intermittently.

In addition, the GUI confirmed that Refresh was applied through Commit, but it w

...

Resolved! Break up Active/Passive HA Cluster

Hello,

 

we have a PA-3020 Active/Passive HA Cluster.

 

Because of cost cutting I have to break up our cluster and just use one of the firewalls as standalone. The thing is, the license of the passive firewall will last longer than the one from the a

...

Veentjer by L0 Member
  • 2598 Views
  • 5 replies
  • 0 Likes

FTP Inbound Decrypt Issues

Ok, I'm at my wit's end with TAC.. after 7 months of explaining the issues, collecting logs, and then starting over when a new agent takes the case, I'm hoping the community can help me.

 

I've had inbound decryption set up for our FTP server for some

...

jsalmans by L4 Transporter
  • 2540 Views
  • 3 replies
  • 0 Likes

Resolved! ECMP Preferred Route

Hi All,

 

Does anyone have the answer as to how the Palo Alto choses the "preferred route" when ECMP is configured?

 

 

 

As per the runtime stats, the referred route for all these routes is 172.16.8.226. (* flag) Both routes in each of the three destinati

...

0.png

User-ID, consistent naming

Greetings! Over time we have collected a variety of user naming formats. For example, domain\user, subdomain\user, user, user@domain and so on. Is there a way to make these names consistent, allowing us to use policies for them effectively?

Thanks!

R

...

cloughr by L2 Linker
  • 1416 Views
  • 2 replies
  • 0 Likes

Palo's behaviour as a Route reflector

We have Nexus 9k routers "R1 and R2" connected to a silverpeak device which is learning routes from the remote sites. The R1 and R2 are also connected to a Palo Alto firewall which is acting a Router reflector for R1 and R2. We are doing BGP in this

...

pahee87 by L0 Member
  • 1222 Views
  • 2 replies
  • 0 Likes
  • 24211 Posts
  • 99 Subscriptions
Top Liked Authors
Labels