General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.

General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 491 Views
  • 0 replies
  • 2 Likes

Mulit-Vsys setup with Wildfire

Hi Friends,

 

We are planning for a multi-vsys PA setup, where one vsys will have only L3/L4 policies and second vsys will be in L2 bridge mode with Threat prevention features only.

Vsys1 will only scan L3/L3 policies while vsys2 will scan traffic fo

...

advanced url filtering question

https://www.paloaltonetworks.com/apps/pan/public/downloadResource?pagePath=/content/pan/en_US/resources/datasheets/advanced-url-filtering

how can i configure the firewall with Advanced URL filtering license to protect the following item

> Antievasion

...

Martin_Chung_0-1735897242147.png

PA-VM sysd_construct_sync_importer

We got a customer that runs into this issue recently, it's a known issue (not public) for versions 11.0.0, 10.2.3, 10.2.2-h1 (and also to us 10.2.3-h2, 10.2.2-2).

When you run into this, means that there's a hardware issue, please go to TAC in order

...

Palo FAIL TO LOGIN.png
Gabeeh by L0 Member
  • 8127 Views
  • 9 replies
  • 3 Likes

When will PAN-OS start supporting modern SSH ciphers?

I'm running PAN-OS 11.1 and an Ubuntu 24.04.1 server which runs OpenSSH 9.6p1.

I had to tune my sshd_config to support really ancient stuff like aesXXX-ctr and hmac-sha1 just to allow for SSH decrytion...

 

Please Palo Alto update the supported ciphe

...

Han.Valk by L2 Linker
  • 126 Views
  • 1 replies
  • 0 Likes

PaloAlto Passive Firewall Monitoring in HA Setup

Hi everyone,
Greetings!

I’m currently using OpManager to monitor a Palo Alto firewall in an HA Active/Passive setup, and the Link State of the interfaces on the passive device is set to auto.
While OpManager is able to correctly pull interface details

...

USER111 by L0 Member
  • 162 Views
  • 1 replies
  • 0 Likes

Resolved! PA-1420 QinQ

Does the PA-1420 support QinQ tagging terminating at the Firewall? We have a L2 connection with an ISP to Azure and they require QinQ tagging. We do not have an ISR or other router to do it for us at this time.

 

Thanks,

Steve 

smzr34 by L0 Member
  • 144 Views
  • 1 replies
  • 0 Likes

Replicating vSwitch NIC status to a NGFW VM (ESXi)

Greetings all,

 

I wanted to see if anyone has successfully replicated the status of a host NIC attached to a vSwitch to a Palo Alto NGFW VM in ESXi 8? 

Right now, all ports always remain up because the virtual switch they are attached to remain up. I

...

EST Enrollment over Secure Transport

I use certificate based IPSec VPN Tunnels that rely on Certificates.  The Certificate Authority i use supports EST to allow for automated enrollment similar to SCEP.  Is there a way to configure Pan-OS to work with EST instead of SCEP?  I have not be

...

unable to open a case

I have a new support account, but there appears to be a problem.  URL is https://support.paloaltonetworks.com/Error/Error.

 

I need to open a case for a critical issue.

Resolved! Regarding Security Advisory CVE-2024-3393

Hello Team,

   I have recently upgraded my pa-1410 firewall to panos ver. 11.1.4-h7, because its preferred version so far.

Today I have received this advisory link ...

https://securityadvisories.paloaltonetworks.com/CVE-2024-3393

I have DNS Security

...

Resolved! OS Upgrade path to 10.2.10-h9

Hello.
I am currently using PAN-820.


The OS is 10.1.9-h3. What is the correct way to upgrade? (I will upgrade to 10.2.10-h9.)

1. Upgrade to 10.1.14-h6, then upload 10.2.0, then upgrade to 10.2.10-h9
2. Upload 10.1.14-h6 and 10.2.0, then upgrade to 10.2

...

danudan by L0 Member
  • 133 Views
  • 1 replies
  • 0 Likes
  • 23717 Posts
  • 110 Subscriptions
Top Solution Authors
Top Liked Authors
Labels