General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Policy not matching actual traffic

Hi All,

 

I have a security rule to allow ip "A" to ssh to ip "B". I can see the traffic actually hitting the fw but it gets dropped with interzone-default. The test policy match also verifies that it matches the traffic.

 

IP "B" is actually the firewal

...

olloczky by L1 Bithead
  • 3980 Views
  • 3 replies
  • 0 Likes

Why tcp aged-out?

Hi all,

Our developers are connecting from Zone1 to Zone2 with tcp (on ports between 2000 and 3000)

The tcp session timeout on firewall is 3 hours.

The security policy allows any application, any port from Zone1 to Zone2. But there are all default secur

...

Global protect Notification

Hi,

 

When I connect global protect Gateway. Once is connected I received this notification.

I have check the internet connectivity it's working fine.

 

Can you please let me know how to avoid this notification 

 

 

Joshan_Lakhani_0-1614493398995.jpeg

Need help with logging in case of App-Id

Hi,

 

I have below rule in my Palo Alto and another default rules which are Intra-zone and Inter-zone.

Source: 10.0.0.0/8

Source Zone: Trust

Destination: Any

Destination Zone: Untrust

Application: ssl, web-browsing, dns, Facebook-base, YouTube-base, etc

Serv

...

GlobalProtect and RDP

Hi All,

 

I have made a change to our GlobalProtect app config to cater for RDP connections by amending the "User Switch Tunnel Rename Timeout" value to 60 seconds. 

 

I was hoping to be able to confirm this setting had been applied to the GP clients via

...

IanBroadway_0-1614336060587.png

Resolved! Is it possible to write a rule matching any IP ending in .xx

Hi all,

I have a question, is it possible to write a rule that matches only a part of the IP address? For example match any IP ending in .51? Using wildcards this would be  *.*.*.51


Put another way, i would like to match all IP's that are x.x.x.51 wher

...

Saqib by Not applicable
  • 4941 Views
  • 8 replies
  • 0 Likes

How to add static routes on panorama M-600

Hello ,

 

We have M-600 Panorama device and we need to get 2 seperate networks :

MGT : for firewalls administration and to receiving logs ( this network is isolated from internet)

Ethernet 1/2 : a new interface just to make panorama reach internet for up

...

Elwess by L0 Member
  • 1559 Views
  • 1 replies
  • 0 Likes

opcmdhistory log missing in PanOS9.1

I noticed that the “opcmdhistory” log disappeared in Panorama after upgrading to PanOS9.1.It was there in 9.0 and previous  versions.

 

Do you know why it changed and if the information is in another log file? I was using it for troubleshooting and det

...

batd2 by L4 Transporter
  • 1338 Views
  • 1 replies
  • 0 Likes

Resolved! Getting LDAP Error

Our client is having issues with LDAP connectivity.

We are trying to configure "Group Include List" in the Group Mapping Settings in User Identification but when we click on the Base DN to browse available groups, we get "Connect error".
 
Same thing sh
...

  • 24196 Posts
  • 100 Subscriptions
Top Liked Authors
Labels