General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 292 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3629 Views
  • 2 replies
  • 14 Likes

Newbie: VPN on PanOS 10

Hi everyone,

 

This is probably trivial, but I am fairly new to this so bear with me:

I would like to set up the PA firewall as a VPN server for users to connect to (ideally, using only the built-in windows client). After authentication they should have

...

PANOS 9.1 know issue PAN-83610 network processor

PAN-83610

In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
Workaround: In PAN-OS 8.0.6 and later releases, you can persist

...

VLim by L2 Linker
  • 2427 Views
  • 1 replies
  • 1 Likes

Maintenance mode

When we try to access maintenance mode keeping "M" press the device just stop booting and nothing appears on console. Then if I press the M after some seconds just normal boot. We also try typing "maint" but no luck

 

v-ealva by L0 Member
  • 2298 Views
  • 2 replies
  • 0 Likes

VWire Radius (NPS) via Mgmt

Happy 2022 ! 


We've just setup VWires for our branches firewalls (A/A Layer 2), no ip address on any interfaces except :

- Mgmt (routable and managed by Panorama)

- HA1-3 (non-routable address) 

 

Most of the device management (SNMP, NTP and etc via Mgmt

...

annielee by L2 Linker
  • 2140 Views
  • 4 replies
  • 1 Likes

Downgrade from 9.1.12.h3 version to 9.1.9

Hi All,

 

I have decided to upgrade my Palo Alto 850 from version 9.1.9 to 9.1.12.h3 but after the secondary Palo Alto upgrade facing an issue where interface are not getting up so my team decided to roll back to version 9.1.9. Should my configuration

...

PANOS 8.0.x restart IPSEC tunnels from GUI

Dear all,

 

we found out that we are not able to restart VPN tunnels in PANOS 8.0.x from GUI because its grayed out and it is an expected behavior as you can see the message "Restart disabled because OK".

 

The conclusion is that on version 8.0.x it's no

...

Rboehme by L2 Linker
  • 3478 Views
  • 3 replies
  • 0 Likes

Remote backup issue

I am trying to backup the config from a remote backup server. The backup file is generating but no config showing in the file. Instead when I open the xml file, I can see this    " <?xml version="1.0"?>  -<response code="403" status="error">  -<resul

...

Kerberos SSO for Captive Portal

Been working through options for gathering userID data on non-domain-joined machines lately, so here's another complete option using Kerberos (krb) SSO.

 

Create a user in AD (my example, username: krb.palo), check the boxes for:

  • User cannot change pass
...

jbworley_0-1641995839136.png
jbworley_1-1641995839170.png
jbworley_2-1641995839174.png
jbworley_16-1641997811010.png
jbworley by L1 Bithead
  • 3455 Views
  • 1 replies
  • 5 Likes

Resolved! user-id not mapping

Hello community,

I'm facing an issue with user-id agentless.

i did the following configurations 

  1.  Create LDAP Server Profile
  2. LDAP/Group Mappings configured on FW
  3. User-ID Group Mapping Settings.
  4. server monotoring is connected
  5. Include network set
  6. User ID on
...

Resolved! about session offload

Hello

the purpose is to minimze the cpu consomption but in wich way ?

how the offload work exactly?

thank's

Gregoux by L4 Transporter
  • 15111 Views
  • 7 replies
  • 0 Likes

Resolved! HA Firewall Device Migration/Hardware Swap

Need to replace an HA pair of Panorama managed, currently deployed firewalls (PA-5220s) with a different pair of Panorama managed  firewalls (also PA-5220s), with minimum/no downtime; device licensing is different between #1 & #2 pairs, necessitating

...

Resolved! Log collector drive bays question

Hey all,

I need to replace a disk on a Palo Alto M600 log collector There are no disk labels on the device. Could anybody here confirm which bays are A1/A2 and B1/B2? I've attached a photo. I'm guessing A1 starts the top left but I' not sure.

 

#m600

Screenshot 2022-01-12 at 11.09.51.png
Modo2016 by L1 Bithead
  • 2039 Views
  • 3 replies
  • 0 Likes

Resolved! Missing PANGPS Virtual Ethernet Adapter

When launching Global Protect for the first time, the computer will prompt for the portal to connect to. The portal information will be enter and when hitting connect it will only display "Connecting...". It will not get to the username and password

...

  • 24181 Posts
  • 100 Subscriptions
Top Liked Authors
Labels