General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4112 Views
  • 0 replies
  • 0 Likes

Resolved! Verify EDL is working after applying a Certificate Profile to the list

I have EDLs configured and applied to security policies. The List Entires is populated. Since I get warnings about no certificate, I am configuring a certificate profile to apply to each of these EDLs. Warning message in Commit log: "External Dynamic List Microsoft Worldwide Required Skype and Teams IPv4 is configured with no certificate pr...

TERRIBLE GlobalProtect OSX mac application is SPAM

I don't understand how anybody uses the GlobalProtect VPN on macs without pounding their head into a wall. I only need a VPN when I'm working from home. When I'm in the office and connected via ethernet I don't want to use the VPN because it's obviously slower. However, every time I'm in the office, despite already being on the network, it never...

jschoewe by L0 Member
  • 1765 Views
  • 3 replies
  • 1 Likes

Netflix issue

Good day, Just got off a meeting with one of our users. We have a standing policy wherein Netflix is blocked within the campus premises. We explicitly created a rule to block all banned applications right on top of the security policy stack, netflix amongst them. Rule had been in place for more than a year. It was reported that users were st...

Resolved! Cannot Change Application Risk Level in ACC

HELP! I'm running PA-200 ,10.1, virtual machine, Setting an applicaiton (FTP) risk level from 5 to 1 manually, and it showing up correctly in the application's open window details; however, it is still a level 5 risk application in ACC. I have committed my change, and even reboot my PA-200 i also tried to use CLI like this: set shared over...

pa200-2.PNG
pa200-3.PNG
pa200-1.PNG

PA 3430 is not detecting DAC cable

Hi, We have a lab with two PA3440 ina cluster. We are connecting the interface HA with a DAC cable. The Palo detects the SFP but not the cable. If we take these SFPs and DAC cables in a PA 5220 everything is being detected. So is there any incompatibility in DAC cables in model 3430??? is there any document to check what cables support PA3440?...

BigPalo by L4 Transporter
  • 5228 Views
  • 4 replies
  • 1 Likes

Resolved! Authorization Codes: Issued

I registered a device a few weeks ago, and I still haven't received the authorization codes. I don't remember it taking this long before. Does anyone have any ideas or know what the normal wait time is? Thanks, Sean

sruddy by L1 Bithead
  • 1329 Views
  • 2 replies
  • 0 Likes

Join Us For a Fuel Workshop on Threat Protection Best Practices (APAC Region Aug 27-28)

RSVP for this event now! Fuel Workshop on Threat Protection Best Practices We are pleased to announce a new series of Fuel Workshops! Over the next two days, we will be going over several components of the NGFW and allowing the attendees to ask questions about the device. Please note the start times for these sessions are set around APAC t...

jforsythe by Community Team Member
  • 1081 Views
  • 0 replies
  • 0 Likes

failed Factory reset and bootstrapping due to pan_oldlogs(PA-5220)

Do you guys have any idea? When I try to Factory reset and format panlog, it goes to first menu. and the maint says the reason I entered the maintenance mode is the failure of FSCK panlog. but it is impossible to do it. it force to go to entering menu like first menu. I tried to purge OS, and bootstrapping to another sysroot, and also Factory re...

H.Song by L1 Bithead
  • 809 Views
  • 1 replies
  • 0 Likes

Resolved! Passive firewall PA-7080 HA state: non-functional with state reason Necessary slots down: 6 7

Hi All, I have PA 7080 in HA mode . We got alert the passive firewall is state: non-functional with state reason Necessary slots down: 6 7 check the chassis , found at slot 7 LFC card status failure. my question is Can we configure exception for module “LFC failure” on HA failover scenario ? because i thinks it should be non-mandatory, si...

Resolved! ARP entries count per interface of DHCP binding.

Hello, I have now paloalto pa-1410 in my network and software panos:11.1.2-h3. I wanted to know how many arp entries "IP <--> mac address" can be stored in the firewall, because I cant see it listed here. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cli3CAC TIA

PAN OS Upgrade recomendation on latest 10.2.11 released 8/13/24 Currently Monitoring

Hi all, The PAN OS we used now is in 10.2.8. I have information from the link: https://live.paloaltonetworks.com/t5/customer-resources/support-pan-os-software-release-guidance/ta-p/258304, and it said that the latest release 10.2.11 release on 13 Aug 2024 currently under monitoring (believ it is not "preferred" version yet). May I know is i...

PA VM Interfaces Not Appearing

Hello Community, I'm in the process of building a new PA VM. I've added the interfaces in ESXi and rebooted. However, the interfaces still don't appear when I issue the command show interface all, see images below. Can someone let me know what I'm doing wrong? Regards Carlton

interfacept1.png
interfacept2.png

Resolved! PAN-OS 10.2.5 is not working with EVE-NG

Hi Everyone, I received the PAN-OS 30-day trial version, I uploaded it successfully in Eve-ng, but it is not processed further after HDF Login, Please advise the solution if anyone is experiencing the same issue.

Commit Failed on Passive Paloalto-3250-admin-role -> AdminRole -> role -> device -> webui -> objects -> packet-broker-profile unexpected here

Hi , Please help , after installed dynamic update of antivirus on Active & Passive PaloAlto-3250, commited successfully on Active but not able to commit on passive.. after commit failed on passive try another way made appication & threat shaedule none in dynamic update but again commit failed, getting below messages. DetailsValidation E...

  • 24333 Posts
  • 124 Subscriptions
Top Solution Authors
Labels