General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Migration of Palo Alto VM series from one host to another

Two PaloAlto Virtual appliances has been deployed in HA mode on Customer site.

   Device models: VM-200

We plan to migrate the virtual firewalls to another host via VMWare Vmotion
feature.

   Issue is: the status of licenses of the firewalls.

   We have i

...

Radmin_85 by L4 Transporter
  • 3932 Views
  • 2 replies
  • 0 Likes

Traffic flow

Is there a good way to determine if the traffic flow through you firewall is optimal and the most efficient?

jdprovine by L4 Transporter
  • 3591 Views
  • 8 replies
  • 0 Likes

Resolved! Configure second ISP with failover and aggregation

Hi all,

 

I'm newbie on Palo Alto systems an i have a question bout a configuration point.

 

I have a PA-220 with one Internet connection (100 mbps). I have a second Internet connection from the same ISP (with the same bandwith => 100 mbps).

 

Now, I need

...

feelgood by L2 Linker
  • 5504 Views
  • 5 replies
  • 0 Likes

Resolved! Outputs Limit! Service restart loop @ 30+

So the title is a slight misnomer.

Have a dev server with 59 miners, 42 procs, and 32 outputs, works fine.

Have a prod server with 58 miners 41 procs and 29 outputs, does not work fine.

 

The two devices are set up with "identical" configs the dev server

...

0isac0 by L1 Bithead
  • 4390 Views
  • 5 replies
  • 0 Likes

Block outbound NTLM auth

With CVE-2018-0950 from Microsoft, if an outlook user clicks on an OLE object in an RTF email, the client will send credentials try to logon. Our security group is quite concerned about this.

 

While allowing ports 445, 137 and 139 out to the internet

...

Resolved! Antivirus Dynamic Update fails PAN-OS 8.1.0 Cluster

Hi Community,

 

I have a PA-850 Cluster with PAN-OS 8.1.0 and a valid Threat license.

The active firewall is configured to download and install antivirus updates and sync them to his peer.

 

Unfortunately, the update failed lately, so we were 4 days behin

...

Chacko42 by L4 Transporter
  • 11895 Views
  • 10 replies
  • 1 Likes

Resolved! Disabling Indicator Expiration

@lmori, thank you for your help so far.

I am migrating my data to the "stdlib.localDB" miner, per your suggestion here.

I have two questions now:

First, I noticed that the default expiration for indicators added to this miner is just one day. How can

...

Resolved! TAP mode interface drop

 

Hi. I have a question about TAP deployment

 

I set the TAP mode which I used just one interface, set the zone TAP

Security policy TAP-TAP any any permit.

 

Then, regularly I'm checking the global counter, but I don't know why the drop packet occured.

When

...

drop-count.PNG

IKEv2 renegotiation on acceptor gateway reboot

Hi community,

 

I have a site-to-site IPSec connectivity with Palo Alto gateway (PA-VM 8.0.5 on kvm hypervisor - CentOS 7 host) on one end as initiator and Vyatta OS based gateway on the other end as acceptor.

 

When IKEv2 and IPSec (and BGP) are in esta

...

rameshgi by L0 Member
  • 1627 Views
  • 2 replies
  • 0 Likes
  • 24197 Posts
  • 100 Subscriptions
Top Liked Authors
Labels