General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.

General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 515 Views
  • 0 replies
  • 2 Likes

about transparent

sorry for bothering you all. I'm new to computer networking. And while I'm building my own system, I'm having some trouble.

MODEM (internet) --- Firewall Palo Alto --- Laptop. This is the model I'm building myself. I was going to use transparent mode

...

GlobalProtect Android version 13 issue

Global Protect login continues to fail on Version 13 Android.

 

It seems to have been caused by Android security enhancement issues.
 
created it with SHA 384 but I can't log in.
 
"The network connection is unreachable or the portal is unresponsive,
...

qmso475_0-1701243435266.png
qmso475_1-1701243590189.png
qmso475_2-1701244110530.png
qmso475 by L3 Networker
  • 1755 Views
  • 10 replies
  • 0 Likes

Site to Site VPN

Quick question on setting a site to site vpn, using tunnel mode. If I have a site "A" peer going and connecting with a site "B" peer for a VPN, can both sites have the same IP address subnet, or will that conflict? 

 

Scenario:

  Site A: 192.168.20.5

...

ITSMC24 by L1 Bithead
  • 175 Views
  • 3 replies
  • 0 Likes

Replace with advanced License

Hello

 

Threat Prevention License
DNS Security License

 

These two licenses are coming up for EoS on June 16, 2025,
Is there any problem in replacing the licenses to Advanced, or is there a little work that needs to be done when replacing the licenses?

...

n-tomo by L1 Bithead
  • 139 Views
  • 2 replies
  • 0 Likes

PA 445 ZTP

Hi Team,

I am planning to configure the new firewall using ZTP and also planning to manage this firewall completely via SCM.

Add a ZTP Firewall to Strata Cloud Manager

Following the above link to add teh ZTP FW to SCM.

> Need to know where will i get

...

Palo Alto Global Protect

Hello. 

   I am looking to setup and use Palo Alto's Global Protect feature; The question I have is if I have only 1 egress port (WAN) port that is public-facing, can I setup my Global Protect on that egress port or do I need to use another port for

...

ITSMC24 by L1 Bithead
  • 234 Views
  • 2 replies
  • 0 Likes

For those that seek to get SSH Proxy working

Searching the internet it seems that people are looking to enable SSH Proxy and not finding answers. I managed to get it working but must say that the current supported SSH decrytion parameters for all PAN-OS versions aren't the most secure ones so y

...

Untitled1.png
Untitled1.png
Untitled2.png
Untitled2.png
Han.Valk by L2 Linker
  • 176 Views
  • 1 replies
  • 0 Likes

GlobalProtect access to local LAN devices

I am fairly new to Palo Alto devices.  We are in the process of testing the GlobalProtect client and have set it up without split-tunneling.

I have confirmed this works for web browsing (get the PA NAT address), but we are still able to get to all lo

...

rgreens by L2 Linker
  • 15461 Views
  • 12 replies
  • 0 Likes

Broker VM rejects SSL certificate

Hello PAN community,

 

I am trying to import a SSL certificate into our #BrokerVM
I can upload the private key, but the Server Certificate gets rejected with the Error: "failed to set custom ssl certificate"

I tried .cer and .pem files and none were a

...

Onboarding to Passive HA to Panorama

Hi Everyone,

I need advice on how to onboard the passive HA to Panorama. The Primary is already on Panorama but upon checking, it doesn't belong to a device group yet. I have read some documentation on how to onboard a local firewall to panorama, but

...

N.MANTUA by L1 Bithead
  • 167 Views
  • 2 replies
  • 0 Likes

Resolved! Replicating vSwitch NIC status to a NGFW VM (ESXi)

Greetings all,

 

I wanted to see if anyone has successfully replicated the status of a host NIC attached to a vSwitch to a Palo Alto NGFW VM in ESXi 8? 

Right now, all ports always remain up because the virtual switch they are attached to remain up. I

...

Resolved! Deep Packet Inspection and SSL Certificate

Hello, newbie here. One of our clients asked me: 

 

"We have an exchange server which is on site.  We need to renew the ssl certificate, I was told that if the Palo Alto firewall performs deep packet inspection, we need to supply the ssl certificate

...

N.MANTUA by L1 Bithead
  • 422 Views
  • 4 replies
  • 0 Likes
  • 23730 Posts
  • 110 Subscriptions
Top Solution Authors
Top Liked Authors
Labels