General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Global Protect gateway configuration

Hi Guys I'm hoping someone can help me with an issue that is constantly being reported by our users. We have Global Protect rolled out to all of our users. On a regular basis, perhaps 2-3 times per week, I come across reports of slowness, poor performance, etc. Speed test download speeds with GP enabled show between 5-25Mb, but when GP is disa...

Specify IAAD for DHCPv6

Hi, I'm in the process of implementing a PA VM with full IPv6 on a Danish ISP. In order to get the /48 IPv6 prefix that they offer, I need to request it using a DHCPv6 client. However, it seems the ISP requires the DHCP request for prefix delegation to have IAID of 1. This works fine when testing with a linux running dhcp6c, where I can manu...

Ssl outbound decryption

Hello, when a client want to connect to a serveur on thé Internet ,the Palo Alto Networks device intercepts the client SSL request and generates a certificate on the fly for the site the client was visiting. In this step what will be the intermediate chain and the root chain of this new certificate? The same as the server on the internet? Which ...

Sarou22 by L2 Linker
  • 1000 Views
  • 1 replies
  • 0 Likes

Unable to register for workshops

Hi All, Whenever I try to register for an event or workshop held by Palo Alto, I'm getting an error "Sorry, you cannot RSVP to this event with this email". Kindly help me resolve this issue. Regards, Shahwaz

About undecided application.

Hello guys.I have some question about APP-ID.For session browser, PAN recognized application was UNDECIDED and traffic was passed and state was ACTIVE. so traffic was not dropped but why PAN could not recognized application properly and recognizing UNDECIDED that means PAN could not identified APP-ID for its traffic.1. Why PAN could not recogniz...

ttongfly by L3 Networker
  • 9588 Views
  • 4 replies
  • 0 Likes

Resolved! PA Active/Passive and Cisco stacking LACP

hello, we have setup Active/ Passive connected with cisco stacking 9500 with four links full-mesh as shown below: Paloalto active: PA(active) AE1 ========= cisco-1 switch (Etherchanel 10) PA(active) AE1 ========= cisco-2 switch (Etherchanel 20) Paloalto Passive: PA(passive) AE1 ========= cisco-1 switch (Etherchanel 10) PA(passive) AE1 ...

Is there a way to stop or fully prevent Palo Alto emails?

At my company we no longer use Palo Alto devices. While we find PA hardware to be good, we have moved in a different direction for our firewalls. That being said, we want to stop all Palo Alto emails (definition updates, firmware updates, everything), I have added anything PA related to our email block list, however emails still continue to sl...

Resolved! Global Protect App/Gateway Login Banner

Is it possible to setup a login banner for the Global Protect App/Gateway? I'm implementing login banners for most of our services and I see that you can implement a login banner for the Global Protect Portal, but I did not see anything for the App/Gateway. I saw another user mention that you could setup a HIP notification with your login banner...

Resolved! Quick upgrade query

We have a customer FW Pair running on 10.1.13 (which was the previous preferred maintenance release). We are looking to upgrade these to 10.2.9-h1. The upgrade notes say download and install the latest preferred maintenance release, which would be 10.1.13-h1 We have previously upgraded other customer FWs from 10.1.13 to 10.2.9-h1, back whe...

G.Blake by L0 Member
  • 1713 Views
  • 1 replies
  • 0 Likes

CVE lodash.js

Hi, Anyone can confirm if PAN OS affected with this CVE? Lodash.js 4.17.20CVE-2021-23337CVE-2020-28500

Authentication Time out - RADIUS

All of our PA 820 are unable to login with RADIUS, both SSH and the web UI will time out. I see the access accept from my NPS server when I debug the authd log, but it then says ===============AUTHD: start========================= ERROR: No such table: device DB. Because this is impacting my entire network, I fell this is something on the NPS....

  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels