General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 269 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3591 Views
  • 2 replies
  • 14 Likes

Local admin account locked

I have a cluster of two Panorama systems.  When I try the local admin account on the primary-active node the system generates a log entry saying that 'failed authentication for user admin.  Reason: User is in locked users list.  The same account name

...

birish by L0 Member
  • 8458 Views
  • 1 replies
  • 0 Likes

BGP "no enforce neighbor-as" option?

Hi,

 

Is there a configuration avaialble to not enforce the requirement of a BGP peer including their AS in the advertised path?

 

This is required in peering exchanges where there are central route servers which function transperantly by advising of nex

...

CMG by L2 Linker
  • 1257 Views
  • 0 replies
  • 0 Likes

Resolved! test custom-url command with Panorama deployed rules.

I'm trying to test a few urls in a custom url category I have deployed on my FW, but am unable to get to work.  All my rules/objects are pushed out via Panorama and it seems as though the command only allows you to test locally defined rules (i get a

...

chrisp by L3 Networker
  • 3699 Views
  • 5 replies
  • 0 Likes

SSL Inbound Inspection


Hi,

I have setup a decryption policy to decrypt inbound SSL traffic for the Exchange web mail server. However, when I check the logs I see only some traffic as decrypted and some arnn't. Refer below screenshots,

Why isn't the policy not decrypting all

...

Shayan by L1 Bithead
  • 5097 Views
  • 6 replies
  • 0 Likes

GlobalProtect with X-Auth split tunnelling

Hi guys,

I'm working on a GP portal and gateway configuration, in order to provide to the customer full compatibility with the old vpn clients (ex: cisco) I enabled X-Auth support on it.

 

The client with a third party software authenticates but it alwa

...

HTTP2 and PAN?

Do PAN firewalls  support inspection of HTTP2 traffic in the same way as they do HTTP1.x?  I am curious because HTTP2 has three main improvements in this version, and I could see these the following two features potentially causing issues for HTTP1.x

...

mgentile by L2 Linker
  • 2136 Views
  • 0 replies
  • 1 Likes

Resolved! Problem with access to WF-500 Appliance

Hello,

 

I try to access to the WF-500 via the Mgmt interface but I found the error message in the attachement.

 

What is the reason of this issue ? what should i do to resolve this problem?

 

I will appreciate all your helps.

wildfire.JPG
RCHAIBI by L2 Linker
  • 2939 Views
  • 5 replies
  • 0 Likes

Resolved! RFC 3021

Does the firewall support RFC 3021 IP Space aka 255.255.255.254 mask on routed point to point interfaces?

Thanks,

Ray.

rholman by Not applicable
  • 5296 Views
  • 5 replies
  • 1 Likes

Panorama Logging

We're running a Panorama M-100 with hundreds of PA-200s.  All changes to endpoints are made from the Panorama appliance.  However, my config logs in Panorama do not show the affected host's information (IP address, hostname, etc.) making it very diff

...

Hot fixes for 7.0.8

Hello,

 

There are two hotfixes released for 7.0.8.  Anyone from PAN TAC can share the detail about what got fixed?

 

Thanks,

 

~E

IPSec VPN issue between Palo and MS Azure

Hi Guys,

 

Having problems with a site2site VPN connection on a palo alto firewall. It seems to randomly drop and stop working. Sometimes it will stay up for days then drop and other times it stays up for about an hour and then drop. I have followed va

...

VPN logs.png

Default Ping Size

 

Is there a way to change the default ping size from 56 bytes? I know there is a switch to change the size but I'm interested in knowing if the default can be changed.

RFalconer by L3 Networker
  • 1801 Views
  • 2 replies
  • 0 Likes
  • 24173 Posts
  • 100 Subscriptions
Top Liked Authors
Labels