General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Difference between app base rule and service base rule.

Hi All,

 

Just some queries,

 

1) what is the difference between the App base rule and Service base rule?

2) For security purpose which one is a more secure app or service base rule?

3) What is the benefit of using App base rules?

 

Thanks in advance.

Resolved! SSL Certificate renewal query

We got certificate tree like this:

the public certificate (Trusted root CA) from Digicert, Intermediate cert (Digi root) and then the SSL/TLS cert (DigiVPN). This DigiVPN is going to expire soon and we use it for GP portal and GW. The server cert is b

...

VPN Tunnel Monitoring between two Palo Alto devices

Hello,

 

From what I understand, when creating a tunnel monitor between two PA devices it's best to assign IP addresses on the same segment to the tunnel interface on each side.  The monitor is then setup with the remote destination on each side.

 

Examp

...

NobleNOC by L0 Member
  • 1636 Views
  • 1 replies
  • 0 Likes

Resolved! PA HA with Port-Channel towards inside/trust connection

Hi,


We need to add secondary PA-220 to existing (production) standalone PA-220 and make it has Active/Standby. Trust interface on PA will be trunk with two sub-interfaces. Both the PA trust interfaces are going to connect downstream Core switch. Core

...

PA-HA.png

Resolved! Export GlobalProtect MSI file

Is there a way to export a deactivated GlobalProtect client MSI installer from the firewall or download a version from the support website?  A client also has a palo alto firewall, but is on a different client version than what I use internally.  The

...

Resolved! Log export error

Hello All,

 

I am facing issue to export traffic logs from the firewall in CSV format. getting the error "no jobs query found".

 

Troubleshooting:-

* Increased the CSV row number up to 1048576.

* I can export URL filtering logs, security policy, NAT policy

...

VSYS Migartion Query From DC5220 to ISP 5050

Spoiler

Hi Team,

I have below network Architecture

Upstream Internet Firewalls PA 5050 Active/Standby

Downstream Datacenter Deployment 5220 Active/Standby

Now We have 2 VYS in DC 1 is Normal 2nd DMZ Vsys.

Now i have to remove DMZ vsys to ISP can some guide

...

CLI/API command to verify Panorama push diff

Do you know of a CLI command or  a rest API call to push and  to show the changes of configuration to be pushed to a firewall from Panorama? I am trying to automate the process, but could not find any references. 

batd2 by L4 Transporter
  • 1809 Views
  • 1 replies
  • 0 Likes

Resolved! MDM Integration Service Cannot Be Started

I'm getting the following start error message on Windows Server 2019 running ID-Agent.

 

 

 

The MADebug file shows the following as well.

------------MDM Service is being started------------
11/10/20 15:52:06:552[ Info 1414]: Os version is 6.2.0.
11/10/20

...

Screen Shot 2020-11-10 at 16.01.40.png
Screen Shot 2020-11-10 at 16.02.52.png

Resolved! Route path monitoring and tunnel monitoring together?

I'm switching to route path monitoring for VPN backup failover and would like to keep my tunnel monitoring active for down/up tunnel email notifications.  I can set the tunnel monitoring to wait to recover.  Can I use both of these at the same time a

...

treese by L3 Networker
  • 2239 Views
  • 2 replies
  • 0 Likes

Resolved! Aggregate vs Zone protection profiles

We have separate zone protection profiles for each zone. And the definition of aggregate says that "all thresholds apply to the entire group of devices specified in a DoS Protection policy rule". So if we are trying to protect servers in DMZ, unless

...

raji_toor by L4 Transporter
  • 2137 Views
  • 3 replies
  • 0 Likes
  • 24211 Posts
  • 99 Subscriptions
Top Liked Authors
Labels