General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Join the Fuel User Spark Event on March 19: Dealing with Threats !

 

Join us at the Fuel User Group Spark Event on March 19!

 

Get ready to ignite your cybersecurity knowledge and connect with industry experts at our upcoming Spark event hosted by the Fuel User Group. Whether you're a seasoned professional or just

...

kiwi_0-1709893724672.jpeg
kiwi by Community Team Member
  • 660 Views
  • 5 replies
  • 3 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3320 Views
  • 2 replies
  • 14 Likes

Error: Certificate failed to load: invalid certificate chain

Hi there,

I generated a CSR with PAN-OS 6.1.3 and submitted it to our Microsoft AD CA with subordinate CA template. After uploading the certificate it shows up under the root CA certificate of our domain. But when commiting the changes I get an "Error

...

cale by L1 Bithead
  • 9150 Views
  • 4 replies
  • 0 Likes

How to forward traffic (URL) to a syslog server?

The $misc variable can only be used for Threats?

How to register the URL in syslog server?

CEF Key Name: request

Full Name: requestURL

Data Type: string

Length: 1024

Meaning: URL or filename for threat logs

Palo Alto Networks Value Field: $misc

from PANOS_6

...

UNIVALI by L0 Member
  • 2046 Views
  • 1 replies
  • 0 Likes

preemption loop detected

Hi,

I have two PAN 500 in HA A/P configuration with PAN OS 6.1.3 and virtual wire configured with link detection failure ANY. I tested link failure detection in way to disconnect one side of Vwire and passive device takes over and became active. After

...

Tician by L3 Networker
  • 3867 Views
  • 1 replies
  • 0 Likes

HA A/A or A/P

Hello All,

I have such situation where considering in which mode to put HA PA configuration. As you can see on drawing, customer consider to put PAN in sandwich of VRRP cluster and vLAG virtual switch. VRRP has one virtual IP and MAC, and all destined

...

Tician by L3 Networker
  • 2588 Views
  • 3 replies
  • 0 Likes

Global Protect LDAP Child Domains

Has anyone setup Global Protect with LDAP for Child Domain or have a link to a doc on it?

Global Protect works perfect for users in the parent domain. Want authenticate users in the child domain.

ddavis1 by Not applicable
  • 2509 Views
  • 2 replies
  • 0 Likes

File blocking .doc isnt working

Hi,

We have configured a policy for File blocking in order to ask confirmation before download .doc files.

doc file: www.apd.cat/ca/media/2165.doc

This is the policy

When i try to download this .doc file, the browser stuck loading but it shows nothing, t

...

SOC_CSG by L4 Transporter
  • 4384 Views
  • 11 replies
  • 0 Likes

NTML authentcation for Captive Portal

Hi All,

I am looking for ways to configure Captive portal policy with NTLM authentication.

I have read a good number of PDFs from Palo alto but still unable to understand how do i configure it.

In short i need to know how do we configure NTLM authentica

...

ArjunDAS by Not applicable
  • 2801 Views
  • 3 replies
  • 0 Likes

Resolved! This webservice call is only available to Panorama

Dear folks,

A few weeks ago we noticed a strange error message in our Panorama management software. If we navigate to "Panorama \ Device Deployment \ GlobalProtect Client" we receive the following error message:

We close the message box but the area st

...

oschuler by L4 Transporter
  • 2366 Views
  • 2 replies
  • 0 Likes

site-to-site vpn from Sophos

IKE coming from a Sophos device is incorrectly identified as application ciscovpn instead of application ike.

Is this because Sophos uses cisco-ish protocol ? All I see in the logs is udp 500...

I'm happy allowing application ike, our other site-to-sit

...

dieter_b by L4 Transporter
  • 2142 Views
  • 3 replies
  • 0 Likes

Ignore usernames that start with sophos?

On our servers we have the User-ID being mapped as companyname.com\sophosCOMPUTERNAME

Sophos is our AV software which uses that account for getting updates. Is there anyway for me to add any names beginning as sophos to my ignore_user_list.txt?

pmc by L2 Linker
  • 1617 Views
  • 1 replies
  • 0 Likes

DShield top 20

Is anyone currently using this dshield top 20 list subscription? How well does it work/ Is anyone blocking inbound, outbound or both? What is the best way to configure it?

jdprovine by L4 Transporter
  • 3003 Views
  • 6 replies
  • 0 Likes
  • 24127 Posts
  • 100 Subscriptions
Top Solution Authors
Labels