General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 314 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3660 Views
  • 2 replies
  • 14 Likes

PAN-2020 site-to-site with Meraki Cloud managed firewall

Hi all,

Has anyone had success establishing a site-to-site tunnel between an PAN firewall and a Cisco Meraki Cloud managed firewall?  I've been messing with it for most of the day and have not found much luck.  I've added a third party peer on the Mer

...

cmateam by L3 Networker
  • 7464 Views
  • 7 replies
  • 0 Likes

Cisco SFP+ Twinax Copper Cables to PA-5050

Hello.

Has anyone tried connecting Cisco SFP+ Twinax Copper Cables (sfp-h10gb-cu1m) to PA-5050 device? I've tried to find some info about it on PA KB but wasn't successful. Is there any document issued by PA listing all the supported 3rd party devices

...

santonic by L6 Presenter
  • 9386 Views
  • 6 replies
  • 0 Likes

Resolved! DHCPv6 client support?

Is there an option to have the PA act as DHCPv6 client (DHCPv4 client on an interface is obviously supported)?

I get a /56 prefix from my provider and my DSL router offers me the option to assign a /64 prefix via DHCPv6 (IA_PD), but I cannot find an o

...

ctr_ts by L1 Bithead
  • 4533 Views
  • 2 replies
  • 0 Likes

Resolved! VM series and SR-IOV

Hi,

Is it possible to setup the VM series NICs as SR-IOV passthrough NICs, the main issues I see is you would need physical e1000 NIC driver support for the NIC card you are using inside the VM series kernel?

Just in case anybody asks why...latency

Che

...

Active Active Setup PA-500

Hello

Could someone direct me or provide me with instructions on setting up twp PA-500's in an Active Active configuration?

Much appreciated and Thank You

RyanA. by L0 Member
  • 3601 Views
  • 2 replies
  • 0 Likes

GlobalProtect commit fail on PAN-OS 7.0

help me please.

config ip pool for client access but commit fail

commit log message

Operation CommitResult Failed
Detailsmissing ip pool from both dynamic ip pool and authentication server ip pool for config 'default' in gateway GP-Gateway (tunnel GP-Gat...

Dent by L1 Bithead
  • 4798 Views
  • 5 replies
  • 0 Likes

Strange Behavior with SIP traffic related to ALG

I'm running into an issue where specific NAT and Security policy names or numbers change then the SIP traffic stops working. I found that if I clear the sessions post change then everything starts working again. I believe this is related to ALG, lik

...

No management access https since upgrading to 6.0.1

I have upgraded several devices from 5.0.8, but of course the last one has to give me grief. Since upgrading from 5.0.8 to 6.0.1, I can no longer ssh or https to the management port (or any other interface on the firewall). The only way I can get on

...

froggyj by Not applicable
  • 6395 Views
  • 6 replies
  • 0 Likes

Resolved! Clientless Remote Access VPN

Hello,

We've just purchased a PA-3020 in order to replace an old Checkpoint. We have a few site-to-site VPN, and some other VPNs using a Checkpoint client. I would like to get rid of the clients and use some king of clientless VPN, so I won't be bothe

...

SNMP and ARP

Is there a way to pull the ARP table from a firewall using SNMP?

We have tools that utilize the ipNetToMediaPhysAddress (OID repository - {iso(1) identified-organization(3) dod(6) internet(1) mgmt(2) mib-2(1) ip(4) ipNetToMediaTable(22) ipNe…) on othe

...

hkp by Not applicable
  • 6465 Views
  • 5 replies
  • 0 Likes

Captive Portal with Radius and groups of users

Hello

I'd like to consult with You one problem. My users authenticate with Radius on Captive Portal web page.

Problem that comes to me is how to assign access according to groups of users. My FreeRadius has only one group of users, I can add more but h

...

_slv_ by L4 Transporter
  • 6360 Views
  • 6 replies
  • 1 Likes

Resolved! BFD yet?

Has PaloAlto implemented BFD yet? I searched the previous discussions and found a thread from 2011 that indicated it might be looked into.

VPN Tunnel down - Troubleshoot

Hi Admins,

I need some help to troubleshoot our problem with the VPN Tunnels. We installed a Cisco to PaloAlto VPN tunnel. The PA in passive mode. But constantly the tunnels go down.

Here are some log outputs:

less mp-log ikemgr.log

2014-04-23 09:21:54

...

Hithead by L4 Transporter
  • 11481 Views
  • 24 replies
  • 0 Likes

VPN with overlapping subnets

We have recently acquired 3 companies and all are using 192.168.1.0/24 as their local subnet.  Now in a perfect world I could just go on-site and and change the addresses, but as well all know it's not and they have critical services running on AS400

...

nthen by L3 Networker
  • 6044 Views
  • 6 replies
  • 0 Likes
Labels