General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Is there anything shown in the system log when the password change date for the Palo Alto firewall administrator account is about to expire?

When setting the password complexity on the Palo Alto firewall, I set only the expiration date to 60 days and locked the account. Is there a way to keep or leave related logs in the system log before the expiration date? If there is any content, please also provide a link to a site where I can refer to it.

CPU - SMP OIDs

The customer is unable to accurately monitor Data-Plane and Management CPU/memory utilization on Prisma SD-WAN ION 1200-S-C5G-WW (Tenant ID: 1285229497, Firmware 6.5.3-i-b10) via NetSpyGlass because previously provided OIDs for these metrics return 'No such object', and required ION-COMMON-MIB and ION-SMI files are not recognized; initial issues...

Upgrade VM300-500 needs to readded in panorama?

I have a cluster in Panorama. We are going to upgrade these 2 machines from VM300 to VM500. So i understand the SN will change and we will need to readded in panorama? is that right? i understand that being a different model i wont user command "replace old SN new SN" in panorama to readded. Right?

BigPalo by L4 Transporter
  • 601 Views
  • 1 replies
  • 0 Likes

Resolved! Device Security license

Hello everyone, I have an active Precision AI Network Security Subscription Renewal Bundle for a firewall. However, when I log in to the Customer Support Portal and navigate to Products > Assets, then select the firewall, I do not see a Device Security license listed. I found the following document, which mentions Device Security: https://d...

Using firewall's own loopbacks as dummy Panorama servers

Hello, was trying to find if anyone has ever dealt with something similar, but couldn't find anything (so, hopefully this isn't a duplicate post). Some info to put things into perspective: I was tasked to migrate 6 HA (active-passive) clusters from soon-to-be-decommissioned Panorama (hosted in Azure) to our on-prem Panorama (hosted in DC) ...

salzmant by L1 Bithead
  • 213 Views
  • 4 replies
  • 0 Likes

GlobalProtect Release for Ubuntu 26.04 LTS ?

Hello together.recently was the new Ubuntu 26.04 LTS release, until now the provided GlobalProtect client supports only Ubuntu 24.04:https://docs.paloaltonetworks.com/compatibility-matrix/reference/globalprotect/where-can-i-install-the-globalprotect-app?otp=linux#linux When can we expect the new GlobalProtect version for Ubuntu 26.04 ? Best re...

User-id mapping domain name issue

Hi everyone, I recently set up GP user-id mapping in our network. It's showing domain.local\username in the logs. I was also told to set up User-ID mapping using the windows agent as well since our users would need to disconnect from GP occasionally. The logs that we get from the windows agent is domain\username. Issue now is that when we se...

Resolved! Factory reset

If I perform a factory reset on PA500 OS 8.1, eill I loose the licensing?

Ladynet by L1 Bithead
  • 9150 Views
  • 7 replies
  • 0 Likes

Palo Alto Networks NGFW Best Practice Assessment (BPA) via the Posture API

Palo Alto Networks NGFW Best Practice Assessment (BPA) via the Posture API Client & Partner Implementation Guide — Windows PowerShell Workflow Purpose This guide provides a practical end-to-end procedure for generating an on-demand Best Practice Assessment (BPA) from a Palo Alto Networks firewall configuration using the Strata Cloud Manager ...

JeanPaul222_1-1786098312985.png
JeanPaul222_2-1786098327651.png
JeanPaul222_3-1786098347950.png
JeanPaul222_5-1786098493750.png

HA1 question

Hi, I have HA1 link traversing 2 upstream routers - if one of the routers goes down, both FW lose HA1 and thus; both become Active. Is it possible to configure HA1 backup over an existing LAN side link? i.e. not using a dedicated port for this but using a sub-interface / existing L3 interface etc? thanks.

No proposal chosen ikev1

After upgrading to panos preffered version 12.1.7-h3 my ikev1 ipsec tunnel with ipsec crypto md5,3des,nopfs is not coming up , knowing that ike phase 1 is successful but ike phase 2 is giving no proposal chosen error , the algorithms matches the other peer and i tried downgrading the tunnel came up, i would appreciate any help

  • 24439 Posts
  • 125 Subscriptions
Labels