General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4111 Views
  • 0 replies
  • 0 Likes

DHCP Relay

I have a strange intermittent problem with DHCP relay. I have it setup on all our firewalls, PA-220, and they relay to servers in the data center (Windows 2016). At some point the relay stops sending offers. I can see the discovery packet and no offer after. The firewalls connect to a Cisco 2960 switch, nothing crazy on the config. It works...

bschaper by L2 Linker
  • 6813 Views
  • 7 replies
  • 0 Likes

connection issue about security-client

as doc descibe , Cloud connection should be connected admin@paloalto-vm-10.1.9> show ctd-agent status security-client Security Client Dlp(0)Current cloud server: dlp.hawkeye.services-edge.paloaltonetworks.com:443Cloud connection: disconnectedConfig:Number of gRPC connections: 1, Number of workers: 5Debug level: 2, Insecure connection: fa...

Resolved! Convert management-only Panorama to panorama-mode

So I've added a 2048 GB disk: admin@panorama> show system disk details Name : vdbState : PresentSize : 2097152 MB Status : AvailableReason : Admin enabled When trying to switch system mode, this happens: admin@panorama> request system system-mode panorama Server error : Failed to change system mode from management-only to panorama.Plea...

New local users created not working on FW Active but yes working on FW Passive

Hello team Currently, I have a pair of FW 1410 Version: 11.0.4-h2, passive active and I have encountered the following problem When creating new local users, with permissions, superuser I can not access via SSH to them locally but I can do it via GUI and all other users created previously.i.e. Users created some time ago in the FW are working co...

Alpalo_0-1718722651633.png
Alpalo_1-1718722724774.png
Alpalo by L4 Transporter
  • 3562 Views
  • 7 replies
  • 0 Likes

For AD user password reset option

We have seen that whenever a domain password is going to expire for the SSL VPN user, the Global Protect client on the user's system starts flashing a message that the password will expire soon. We want to know if there is any possibility to embed a password reset link as well along with such a message.Please help us on the same so that we conv...

SurajN by L2 Linker
  • 4557 Views
  • 4 replies
  • 0 Likes

Log forwarding - Filtering and Auto- tag not working

Hi there, I had setup Log forwarding profile, where I am sending All logs to syslog server. Thats working great. Then I added one more line where I am filtering threat logs for (severity eq critical) and (zone.src eq internet_zone) Checking filter results by Filter Builder and its showing exact values which I am looking for Then I add...

LogForwarding.png
MatchingList.png
filter.png
Action.png

Nested Device Logging

Hello, We have set up some nested device groups, to allow for easier policy management and, as expected, when viewing traffic in Panorama we see the logs for both device groups in the parent device group and only child device group logs in the child device group. I was wondering if there was a way to only show the parent logs in it's own DG?

Firewall is not forwarding logs to the Syslog server

Hi everyone! I am kind of bummed on why my syslog configuration is not taking effect. I have 2 pairs of firewall, PRD(2 firewalls) and DR(2 firewalls). Both are in HA setup and managed by Panorama. My syslog configuration in DR and PRD are just the same. Same server, same settings. For some reason, the syslog in my PRD is not working. So my...

Multicast - troubleshooting

Any tips/advice how to test multicast? Should I be able to do a ping from a firewall interface included in the Interface Group to a multicast address as a test? Also from Runtime Stats on the VR, I do not see anything showing under the Multicast -> IGMP -> Multicast - I thought I would, but maybe I am wrong thinking this

clewis1_0-1724153163868.png
clewis1 by L3 Networker
  • 1620 Views
  • 1 replies
  • 0 Likes

PANOS upgrade plan in excel sheet for a year

Hello Experts, I have been asked to provide a plan to upgrade Palo Alto firewalls within a year and I have almost 430 Palos in the environment. I need help creating a sample plan with timelines and what columns I should use in this plan. If someone has such a plan template kindly share.Hostname IP Location PANOS Prefered PANOS Schedule etc...

p.mohan by L1 Bithead
  • 1781 Views
  • 4 replies
  • 0 Likes

New to the community

Hello all, I am working as a Security Engineer currently and I am learning and working on Palo Alto Networks. During exploring, I came across Palo Alto LiveCommunity and I see there is so much technical content here to browse and learn. I am looking forward to connect with members here and ask my questions and learn through it. thank you

Config Audit Failure

Hello~ Does anyone know this failure message that we use Config Audit for compare configuration? Thanks! (PA-3020, v6.1.4) Failed to create config file!

image002.jpg
neilwu by L2 Linker
  • 8744 Views
  • 8 replies
  • 0 Likes

Webpages are loading very slow

Hi! Me again, I apologize. I am currently out of troubleshooting tricks. So here it is. I have configured my Source NAT, outbound-to-internet and default route. All are good. No issue. Traffic is hitting the correct Rule and NAT. The thing is, the webpages are very slow as they loads. Probably 2mins or more. Kind of frustrating and time-cons...

slow GUI

Hi,why my GUI is soo slow ? I have to wait 10-15 sec for new clicked tab to open. (Main Menu on top)Does anyone of you have the same problem?My PA is PA-2020, software version 4.0.3

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels