General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

getting more global counters through SNMP

there are a bunch of counters available through SNMP, for example the amount of active sessions at a specific moment PAN-COMMON-MIB::panSessionActive.0 = INTEGER: 2 I am looking for the overall amount of sessions created on the firewall, with the intent to graph that in Grafana. This is reflected in the global counters: > show counter global ...

frigault by L1 Bithead
  • 1528 Views
  • 2 replies
  • 0 Likes

PA410 Version: 10.2.7-h3 does not send logs to Panorama

Hello, after upgrade to version 10.2.7 h3 the Pa410 does not send logs to panorama, I have tried several versions but in many of them it does not do the autommit because there are bugs recognized by Paloalto. Do you know any stable version for this? Thanks a lot Regards

Alpalo by L4 Transporter
  • 7055 Views
  • 14 replies
  • 0 Likes

Resolved! HA Link Monitor Issue

Hi everyone! I am having some confusion on HA Link Monitoring and Failover. I did exactly the same thing with video courses and Palo alto document guide but it still doesn't work For context, i am monitoring my eth1/2 and eth1/3 for failover. So i shut down the G0/0 interfaces of the routers directly connected to them and still there's no fail...

renzanjo11_0-1725417374901.png
renzanjo11_1-1725417398285.png
renzanjo11_2-1725417418512.png

Difference between 2FA certificate configuration methods

Hi folks - very grateful for some support on this one. I've been led to believe that establishing 2FA on GlobalProtect using credentials and certificates as the authentication methods requires setting up a certificate profile and selecting "No" on the setting "Allow Authentication with User Credentials OR Client Certificate". My questions is, sh...

Port fowarding from internet to inside server

I am trying to setup port forwading from spacific internet IPs to a server inside the firewall. This is for RDP access. We are using port 9999 to hit the firewall and translating that to 3389. Here is the NAT and Security policies I have. When I look in the logs it looks like it never hits the security rule and it says the application is incom...

RayWebster_0-1725379347129.png
RayWebster_1-1725379392373.png
RayWebster_2-1725379510648.png

Recommended PAN-OS for 5220

We are currently running version 10.2.9-h1 and i would like to know what the prefered recommended version to upgrade too? Also why does palo alto deny me access to this information when i have an account with them? I upgraded to 10.2.11 but this caused service impact. All our hosts dropped every hour on the hour until i reverted.

Request to Remove High-Risk Status and Update Website Category for ice-aec.com

Dear Palo Alto Networks LIVEcommunity Team, I am writing to address a concern regarding the domain ice-aec.com, which has been flagged as high-risk by Palo Alto Networks Unit 42 Security. After conducting a thorough review, we believe that this classification may be due to certain components on our site that could be mistakenly identified as m...

ice-aec by L0 Member
  • 1529 Views
  • 1 replies
  • 0 Likes

Export Information for a PA-460 Unit

Could someone at Palo Alto please provide the following information for your PA-460 unit (3 items total): 1. ECCN (Export Control Classification Number) 2. Harmonized Tariff Code (HTS Code) 3. CCATS information for this product - we need to see if you have a license exception on the CCATS We need to export two of these units from the USA to Mexi...

KathyG by L0 Member
  • 1575 Views
  • 1 replies
  • 0 Likes

broker vm

Hi, i want to sign in broker vm the first time. but default password !nitialPassw0rd don't work. can you help me with his problem. Thanks.

Paloalto (HA) and Fortigate (HA)

Hello All, what is the recommended connectivity for if there 4 firewalls and HA is active/passive on both devices: PA-active connected to (Fortigate active and passive) PA-passive connected to (Fortigate active and passive) Thank you

Resolved! Firewall (10.1.10-h1) Unable to connect UID agent (10.1.2)

UID agents version 7.0.8 upgraded to 10.1.2.DC (10.2.9)and Perimeter (11.1.2-h3) firewalls connected to Newly upgraded UID agent but unfortunately all branch firewalls(10.1.10-h1) couldn’t make connection to upgraded UID agent and is showing certificate error in logs.So we have downgraded the UID agent version to 9.0.5 and working fine with all ...

S.Sivan by L1 Bithead
  • 1881 Views
  • 3 replies
  • 0 Likes

Resolved! URL exeptions best practis

Hi All.I'm new in Palo Alto.My goal is to exclude some IPs (Mainly some Broadcast TV channels) from scaning and intrusion ditection, for improving throughput. Now there are some ways to achive this, but i wondwer what is the best way? Regards' Goldy

YGoldy by L1 Bithead
  • 4359 Views
  • 6 replies
  • 0 Likes
  • 24432 Posts
  • 125 Subscriptions
Top Solution Authors
Labels