General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 778 Views
  • 0 replies
  • 0 Likes

Resolved! Upgrade path and reboots

hi,

 

I need to upgrade from version 10.1.6 to version 10.2.6.

According to the upgrade path article I need to:

first download and install the latest 10.1.11-h6 and REBOOT.

than download and install 10.2.0 and REBOOT

than download and install 10.2.6

...

arnona by L1 Bithead
  • 1779 Views
  • 3 replies
  • 0 Likes

Oracle Replication Failed

We have a case  where the Oracle connection failed during the replication to the DR , the replication process start for one to three hours then it failed ,  Oracle admins opened a ticket with oracle support and oracle support recommends to disable  t

...

Unsupported protocol "IPv6 Control Protocol Error"

Hello PaloAlto users!

 

I have 11.0.2-h2 installed on my PA-820 and configured the WAN port in a subinterface through vlan 20 tagged, due ISP configuration, the line comes through VLAN 20.

 

Every 3-5h the ISP line comes down. Checking the system mon

...

Jlsierra_0-1710403785241.png
Jlsierra by L1 Bithead
  • 844 Views
  • 1 replies
  • 0 Likes

Looking for Manufacturer Part Number Information

Hello Palo Alto Networks,

 

I wonder why you hide Manufacturer Part Number of SFPs.
There are two points I want to ask.

 

## DOC 810-000077
https://live.paloaltonetworks.com/t5/operations-documentation/hw-accessory-cross-reference-810-000077-0be-update

...

emr_1 by L5 Sessionator
  • 1463 Views
  • 2 replies
  • 0 Likes

Resolved! PaloAlto Predefined IP Lists not appearing

After rechecking licenses, rebooting, checking multiple things, I am unable to get the EDL Predefined IP List dropdown to populate with PA lists (Bulletproof IPs, High risk IPs,. etc.). The Predefined URL List populates with the Authentication Portal

...

Cutom reports IPs not domains names

Hello Bro,

              We are currently on PANOS ver 10.2.7-h3 on PA-3220 firewall.

I have created a custom report, and receive it daily, it went Ok.

but the received PDF report for example "Top blocked websites" mostly include IP addresses and not

...

Resolved! Security rule says disabled no for an enabled policy

I have 2 firewalls with identical config running same PANOS. The policy in question is enabled on both the firewalls.

But one firewall has an extra line in cli( which is picked in daily diff)

set rulebase security rules "rule name" disabled no - So i

...

Duplicated IP for different Users

Hi team

I'm currently having an issue with GLOBAL PROTECT VPN users whose IP has been duplicated, as showed in the next picture:

 

As you can see, there is no big time difference between the log generated for the user sprbun\johnfc and the user sprb

...

DanielPaz_0-1710274242054.png
DanielPaz_1-1710274470327.png
DanielPaz_2-1710274494198.png
DanielPaz_3-1710274883250.png

Resolved! Site Access

I am in the process of locking down access to certain sites on the internet and We have certain AD groups that are designated for access. I was wondering if there was a way to create one rule that will allow AD Group1 and AD Group 2 to their respectr

...

Getting commit error

vsys -> vsys1 -> application-status -> tiktok 'tiktok' is not a valid reference
vsys -> vsys1 -> application-status is invalid
Commit failed

 

Getting error after new content version installed but when reverted issue fixed.

Saurabh1 by L1 Bithead
  • 2535 Views
  • 6 replies
  • 0 Likes

xqualsystem.org wrongly categorized as spyware

Dear Team , 

 

The Website xqualsystem.org wrongly categorized as spyware  on DNS Security and as per them the site is cleaned .

Could you let us know whom to contact in paloalto to understand why the xqualsystem.org wrongly categorized as spyware ?

...

VineethM by L0 Member
  • 620 Views
  • 1 replies
  • 0 Likes

Resolved! DNS proxy setup

Hi,  I have a firewall rule on my Palo Alto to NAT a public IP to a private IP on the DMZ.  The external users who don’t work for my company can hit the public IP by DNS name, get onto the website, and view the content etc.  This is all working fine.

...

ohareka by L1 Bithead
  • 1444 Views
  • 3 replies
  • 0 Likes

Importing routes between VR

I know we can exchange routes between VR using BGP but is there any other built in method?  Cisco and Juniper offer route leaking functions which let you import/export routes between VRF's without needing to establish a full routing protocol

 

Thanks

GP Not Transitioning to Internal Network Correctly

Hello! I have a GP environment with one all in one NFGW (Portal/Ext GW/Int GW). It works great. Recently I added a second site with a similar setup for redundancy. The same DNS name points to both portals, the portals are setup to suggest both GWs eq

...

MeCJay12 by L2 Linker
  • 836 Views
  • 2 replies
  • 0 Likes
  • 23986 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Authors
Labels