General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

FWs no longer forwarding logs to Panorama

Not sure what happened but it seems that all my firewalls stop sending logs to panorama (local log collector). I have a ticket open with PAN support but not really getting anywhere. Recently upgraded PANORAMA to 11.1.13-h3 and added additional collector disks to PANORAMA. Also forwarded logs from PANORAMA log collector to our syslog serv...

drewdown_0-1788476521190.png
drewdown_2-1788476742998.png
drewdown_1-1788476583659.png
drewdown_3-1788476808559.png
drewdown by L4 Transporter
  • 37 Views
  • 0 replies
  • 0 Likes

VPN with two subnets

Hello, We are using globalprotect for users to connect to our network, but recently we have another set of users that we would like to put them on a separate network. We created another profile on the Gateway specifying that if certain users, we have connection with SAML, should receive the IP address of the secondary subnet. We moved this p...

YParreno by L1 Bithead
  • 92 Views
  • 2 replies
  • 0 Likes

Is there anything shown in the system log when the password change date for the Palo Alto firewall administrator account is about to expire?

When setting the password complexity on the Palo Alto firewall, I set only the expiration date to 60 days and locked the account. Is there a way to keep or leave related logs in the system log before the expiration date? If there is any content, please also provide a link to a site where I can refer to it.

Resolved! Step to change standalone for both device

Hi All, All our PA is managed by Panorama and there are a couple of HA pairs in our environment. we just want to change one of the HA pair to standalone. Currently our set up is active passive. We would like change to standalone on both device. Is there any steps to make this happen? Thanks !!

Shutting down/disabling subinterfaces

I am very new to the PANOS world so I will apologize in advance if this is obvious, however my search of documentation and knowledebase did not yield anything. I have been looking for a way to administratively shut down sub interfaces. Is this possible? While it's easy enough to shutdown a physical interface by assigning it's link-state we're no...

scourge by Not applicable
  • 37094 Views
  • 16 replies
  • 0 Likes

Upgrade VM300-500 needs to readded in panorama?

I have a cluster in Panorama. We are going to upgrade these 2 machines from VM300 to VM500. So i understand the SN will change and we will need to readded in panorama? is that right? i understand that being a different model i wont user command "replace old SN new SN" in panorama to readded. Right?

BigPalo by L4 Transporter
  • 609 Views
  • 1 replies
  • 0 Likes

Resolved! Device Security license

Hello everyone, I have an active Precision AI Network Security Subscription Renewal Bundle for a firewall. However, when I log in to the Customer Support Portal and navigate to Products > Assets, then select the firewall, I do not see a Device Security license listed. I found the following document, which mentions Device Security: https://d...

Using firewall's own loopbacks as dummy Panorama servers

Hello, was trying to find if anyone has ever dealt with something similar, but couldn't find anything (so, hopefully this isn't a duplicate post). Some info to put things into perspective: I was tasked to migrate 6 HA (active-passive) clusters from soon-to-be-decommissioned Panorama (hosted in Azure) to our on-prem Panorama (hosted in DC) ...

salzmant by L1 Bithead
  • 236 Views
  • 4 replies
  • 0 Likes

GlobalProtect Release for Ubuntu 26.04 LTS ?

Hello together.recently was the new Ubuntu 26.04 LTS release, until now the provided GlobalProtect client supports only Ubuntu 24.04:https://docs.paloaltonetworks.com/compatibility-matrix/reference/globalprotect/where-can-i-install-the-globalprotect-app?otp=linux#linux When can we expect the new GlobalProtect version for Ubuntu 26.04 ? Best re...

User-id mapping domain name issue

Hi everyone, I recently set up GP user-id mapping in our network. It's showing domain.local\username in the logs. I was also told to set up User-ID mapping using the windows agent as well since our users would need to disconnect from GP occasionally. The logs that we get from the windows agent is domain\username. Issue now is that when we se...

Resolved! Factory reset

If I perform a factory reset on PA500 OS 8.1, eill I loose the licensing?

Ladynet by L1 Bithead
  • 9166 Views
  • 7 replies
  • 0 Likes

Palo Alto Networks NGFW Best Practice Assessment (BPA) via the Posture API

Palo Alto Networks NGFW Best Practice Assessment (BPA) via the Posture API Client & Partner Implementation Guide — Windows PowerShell Workflow Purpose This guide provides a practical end-to-end procedure for generating an on-demand Best Practice Assessment (BPA) from a Palo Alto Networks firewall configuration using the Strata Cloud Manager ...

JeanPaul222_1-1786098312985.png
JeanPaul222_2-1786098327651.png
JeanPaul222_3-1786098347950.png
JeanPaul222_5-1786098493750.png
  • 24442 Posts
  • 125 Subscriptions
Labels