General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4135 Views
  • 0 replies
  • 0 Likes

Dual ISP Failover with site to site VPNs

Hey everyone,Just started with Palo and was researching the optimal way of configuring ISP failover to include automatic failover of site to site tunnels.Is there a reason to use PBF over static route removal?Based on the reading date I was doing today, SRR appears less convoluted than PBF and seems the most similar to Cisco's SLA configuration ...

Evahi21 by L0 Member
  • 4394 Views
  • 4 replies
  • 0 Likes

Ultra super mega slow reboot/update time?

Hey people, so I am currently upgrading one of our PA-820 Cluster from 10.1.6 to 11.1.2-h3. Is it is normal that 1 upgrade step takes around 20 minutes per Firewall? I feel like updating our Palos is taking sooooo long compared to our Fortis. In the same time where I do 1 update on 1 Firewall I could probably do 2 upgrade steps on both Forti Clu...

HTTP Header Insertion

Hi! I tried configuring the HTTP Insertion Header via this link https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/objects/objects-security-profiles-url-filtering/http-header-insertion However, it seems like I there's no changes. Can I ask how to test this one if configured it correctly? Regards, Renz

Palo Alto to Sonicwall

Team I have a new SonicWALL and I'm configuring the SonicWALL with the same config as the palo alto. I'm confused with the Interface 1/2 setup. It has no IP and it says assign interface to vlan: Office-Lan. How do I set up this on the SonicWALL. Pls help

Where to download PAN-OS for VM for my lab

When I go to Updates --> Software Updates --> I don't have the PAN-OS for VM options. I only see PAN-OS for the actual FW hardware that I have in my DC's. I want to setup a lab and need a VM, where do I get it?

Help with first steps with a VM trial.

HI everyone,I'm trying to install a PaloAlto VM ESX 10.2.5, and when i have install it, i can't access with admin/admin. When I try to enter in maint mode, there are a password for advanced options, and neither admin. I try admin root password and it doesn't work. Looks like the credentials are changed, someone knows something? thanks

AlonsoRecuero_0-1720699447479.png
AlonsoRecuero_1-1720699734989.png
AlonsoRecuero_2-1720699749644.png

NGFW PA-1400 POC Guide

Hi, I am beginner for firewall configuration and will need to lead POC soon. Appreciate if you guys can share the guide, step-by-step for firewall configuration for POC purpose. The client wish to test on bundle license ATP, ADVURL, AWF and DNS and SD-WAN. Thank you in advance!

Prefered PANOS version

Dear Friends, One of my customer is facing issue with inbound connection traffic after upgrading firewall from 11.0.4-h1 to 11.1.2-h3. Where inbound traffic was not reaching to firewall although 11.1.2-h3 is the prefered version. Additionally, we couldn't see any traffic logs. Then we reverted to our previous version 11.0.4-h1. After downgradi...

Resolved! Device - certificate based authentication

I am attempting to implement this in my home lab. Has anyone done this? Basically the situation where if a device connects to the network, it should have a certificate installed from my CA. If it does not, then a security policy (or other policy) should deny the device network traffic. Some articles suggest the use of GlobalProtect but I do not ...

DHCP Realy

Hello, I have an issue related to DHCP Relay, I configured it on my Palo Alto to allow users to get IP from the DHCP server behind the Palo Alto but it not working can anyone help me how can I troubleshoot this issue to check if this issue from Palo alto side or not

amr.ali by L0 Member
  • 1845 Views
  • 1 replies
  • 0 Likes

Resolved! SSO Palo Alto Support Portal

Hi everyone,is it possible to have SSO Accounts (Azure AD) and non SSO Accounts simultaneously in the Palo Alto Customer Support Portal (CSP)?In the future, we want to have one set of SSO Accounts and a pair of Emergency Accounts (non SSO), if the ISP is not available.Kind regards.

Resolved! Can't find the "Republic of Kosovo" in the "Firewall Region Code Legend"

Hey, new to the community today! I've searched the LIVEcommunity discussions and the web, but couldn't find any solutions or anything related to such a problem. We have geo-blocked every country in the world by default and add countries to an exepction rule whenever needed. Today I was asked to grant a client access from the Republic of Kosovo...

WildFire auto update agent failed to download Wildfire version 865169-869036

Hi , i receive alert through email that the WildFire auto update agent failed to download Wildfire version 865169-869036 on April 16 2024 at 15:01:48 GMT , 23:01:48 , 16:23:01:48 but when i go through the System logs, it doesn't show the version 865169-869036 is failed to download or success to install. a newest successfully wildfire packag...

alert.png

Resolved! PAN-OS 10.2 PPPoE on Layer 3 Sub-Interface?

Is there any way to get PPPoE working on a Layer 3 sub-interface in Pan-OS v10.2? I recently purchased a PA-220 for personal/study use. My ISP, Century Link, provides Internet access via VLAN 201/PPPoE. I'm currently running an ASA 5506 at the edge, which handles this configuration just fine. I'd like to swap it for the PA-220 but it seems l...

  • 24340 Posts
  • 124 Subscriptions
Labels