General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Commit error After PANOS10.1.10 upgrade

After upgrading from PANOS 10.1.8-h2 to 10.1.10 we start getting the following commit error.

  • profiles -> spyware -> sink-alert -> botnet-domains -> dns-security-categories is invalid. Missing pre-defined DNS security category

Any idea to correct th

...

Lance by L2 Linker
  • 171 Views
  • 2 replies
  • 0 Likes

Understanding Static NAT

Hi All,

When it comes to Static NAT it will be one to one NAT in vendors like Checkpoint and Cisco ASA. I am bit confused with the NAT configuration in Palo Alto. Went through config guide and examples of NAT as well but still confused.

We have a sce

...

Resolved! Can log in PAN OS VM

I get this error when i try and log in

OZ3-06-05 06 : 11.0Z5 -0700 Error :
sysd_construct_sync_importer(sysd_sync .c : 360): sysd_sync_register() failed: (111) Unknown

file blocking profile not working for SFTP

Hii

we are trying to access our internal storage using SFTP from internet. after applying file blocking profile we are able to access mentioned files but firewall not restrict the file. we found that file blocking is not happening.

 

Please advise ho

...

Resolved! unknown command during SSH script

by testing a ssh skript i get an "unknown command" error from the CLI

 

user@host:~/> cat reset.sh ssh -t -t fw.domain.de << EOF set cli pager off show user ip-user-mapping all type CP debug user-id reset captive-portal ip-address 1.2.3.4 quit EOF ...

mhuels by L3 Networker
  • 138 Views
  • 1 replies
  • 0 Likes

Intune MDM

We want to deploy Cortex XDR agents to our Intune managed mobile phone devices (both ios & android). Is there any guide available to do that?

disk partitions in Panorama VM not being properly used

Dear Community,

 

I have added to Panorama VM (mode VMware ESXi) 3 extra disk units: 2TB, 2TB and 12TB. 

 

The Panorama is acknowledging all the disk units and partitioned the 12TB unit in 6 x 2TB units, until here all good. But 4 of the partitions /

...

Resolved! Running Security LifeCycle Review SLR for a NGFW

Hi All,

I have access to the PA HUB and want to run a SLR review for a client's NGFW (i have a statsdump file)

however it is asking me to activate this service and requires a cortex data lake instance of which i don't have one, is this still doable?

...

Ants by L1 Bithead
  • 148 Views
  • 2 replies
  • 0 Likes

Certificates not appearing in XML running configuration

Dear colleagues,

 

I am having trouble with the custom Nagios plugin check_paloalto, specifically with the "certificates" check.

The rest of the checks are working fine.

 

Basically, the "certificates" check leverages the API calls and parse the XML

...

GGarolla by L1 Bithead
  • 132 Views
  • 2 replies
  • 0 Likes

Palo HA with LACP to Cisco Stack Switch

Hello Everyone,

 

Im trying to find a Palo KB that talks about recommended/best practise when setting up Palo HA with LACP to a stack switch (e.g. Cisco stack). 

 

Can anyone guide me on this ?

 

 

For some background, we are weighing the Pros and Co

...

adm2tech by L1 Bithead
  • 248 Views
  • 5 replies
  • 0 Likes

Query for routing table

Hello, everyone.

One query.

In Palo Alto Firewalls, what is the correct command in the CLI, to "validate" if I have or don't have a route, to reach a particular destination?

The correct command is "show routing route" or "show routing fib" ???

What i

...

Matlu_NN by L1 Bithead
  • 452 Views
  • 13 replies
  • 0 Likes