General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4239 Views
  • 0 replies
  • 0 Likes

Resolved! I am having Pan-OS integarted user Id

For some reason the Agent stopped working on the end user computer. when i checked the event log i came with an error for the id 10036 ( The server-side authentication level policy does not allow the user domain\user SID (X-X-X-XX-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXX-XXXXX) from address xxx.xxx.xxx.xxx to activate DCOM server. Please raise the activa...

PavanT by L1 Bithead
  • 84429 Views
  • 18 replies
  • 2 Likes

Replacing PA-5220 with a PA-3410 and need the best practice to migrate over configuration

Replacing PA-5220 with a PA-3410 and need the best practice to migrate over the configuration. Obviously the network interfaces are different and will require some cleanup, that and I know to match the PAN OS in the devices to avoid possible complications. Having not done this before what else should I look out for? Thank you!

Scolan by L0 Member
  • 4117 Views
  • 6 replies
  • 0 Likes

Resolved! trouble with GRE tunnel to Netskope

Scenario: Panorama managed VM-700s. 10.2.9-h1. using template stack. Netskope is a cloud web proxy. We setup new tunnel interface, GRE tunnel, static route, network monitor, allow rule, no-NAT rule, and PBF. We use a PBF because Netskope requires it. Clients don't go down the tunnel. I can't ping the probe IP from the clients nor from the f...

Filter manged devices summary by tag in Panorama

Do you know of a way to filter the searches of Manged Devices | Summary in Panorama. You can assign tags to devices, but it is not very useful, if you cannot filter by exact tag tag. You can search by the tag name, but it will only show any other results, e.g. device group or templates, which match the string. We have a few hundred devices and i...

2020-11-23_11-17-50.jpg
batd2 by L4 Transporter
  • 3875 Views
  • 4 replies
  • 0 Likes

Global Protect gateway configuration

Hi Guys I'm hoping someone can help me with an issue that is constantly being reported by our users. We have Global Protect rolled out to all of our users. On a regular basis, perhaps 2-3 times per week, I come across reports of slowness, poor performance, etc. Speed test download speeds with GP enabled show between 5-25Mb, but when GP is disa...

Specify IAAD for DHCPv6

Hi, I'm in the process of implementing a PA VM with full IPv6 on a Danish ISP. In order to get the /48 IPv6 prefix that they offer, I need to request it using a DHCPv6 client. However, it seems the ISP requires the DHCP request for prefix delegation to have IAID of 1. This works fine when testing with a linux running dhcp6c, where I can manu...

Ssl outbound decryption

Hello, when a client want to connect to a serveur on thé Internet ,the Palo Alto Networks device intercepts the client SSL request and generates a certificate on the fly for the site the client was visiting. In this step what will be the intermediate chain and the root chain of this new certificate? The same as the server on the internet? Which ...

Sarou22 by L2 Linker
  • 945 Views
  • 1 replies
  • 0 Likes

Unable to register for workshops

Hi All, Whenever I try to register for an event or workshop held by Palo Alto, I'm getting an error "Sorry, you cannot RSVP to this event with this email". Kindly help me resolve this issue. Regards, Shahwaz

About undecided application.

Hello guys.I have some question about APP-ID.For session browser, PAN recognized application was UNDECIDED and traffic was passed and state was ACTIVE. so traffic was not dropped but why PAN could not recognized application properly and recognizing UNDECIDED that means PAN could not identified APP-ID for its traffic.1. Why PAN could not recogniz...

ttongfly by L3 Networker
  • 9342 Views
  • 4 replies
  • 0 Likes

Resolved! PA Active/Passive and Cisco stacking LACP

hello, we have setup Active/ Passive connected with cisco stacking 9500 with four links full-mesh as shown below: Paloalto active: PA(active) AE1 ========= cisco-1 switch (Etherchanel 10) PA(active) AE1 ========= cisco-2 switch (Etherchanel 20) Paloalto Passive: PA(passive) AE1 ========= cisco-1 switch (Etherchanel 10) PA(passive) AE1 ...

Is there a way to stop or fully prevent Palo Alto emails?

At my company we no longer use Palo Alto devices. While we find PA hardware to be good, we have moved in a different direction for our firewalls. That being said, we want to stop all Palo Alto emails (definition updates, firmware updates, everything), I have added anything PA related to our email block list, however emails still continue to sl...

  • 24358 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels