General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4442 Views
  • 0 replies
  • 0 Likes

Resolved! App version mismatch

Hi All,My dashboard shows a "App Version Mismatch" in a HA setup. The active is supposed to download the app version and sync it to the passive.To confound the issue as per the following the "active" firewall is running the older version causing the mismatch:admin@(active)> show high-availability all | match Application Application Conte...

BTS_MS by L2 Linker
  • 33503 Views
  • 13 replies
  • 0 Likes

Fuel Spark Event Discussion: Web Proxy and SD-WAN (July 25, 2024)

Delve into Fuel User Group, the sister community to LIVEcommunity, tailored for Palo Alto Networks users. Free membership in Fuel brings a myriad of benefits tailored to your interests and needs, particularly if you're immersed in cybersecurity or IT operations within the domain of Palo Alto Networks offerings What’s really cool about Fuel Use...

jforsythe_1-1721672468799.jpeg
jforsythe by Community Team Member
  • 1328 Views
  • 0 replies
  • 1 Likes

After Upgrading our PA-820 to 11.0.2, we're seeing lots of data on dns-base application.

After Upgrading our PA-820 to 11.0.2, we're seeing lots of data on "dns-base" application. In a 24-hour period, I'm seeing 5PBs+ of data coming through, which is way over our limits for our internal network (two DNS servers at 1GB NIC each) and external network. Our ISP bandwidth is 500/500 Mbps. So it's going way over our MAX capacity. Howe...

Resolved! Factory reset

If I perform a factory reset on PA500 OS 8.1, eill I loose the licensing?

Ladynet by L1 Bithead
  • 8663 Views
  • 8 replies
  • 0 Likes

Cortex XSOAR community edition

Hi all, I signed up via this link (https://start.paloaltonetworks.com/sign-up-for-community-edition.html) for Cortex XSOAR community edition about 1-2 hours. But still did not receive any mail or link to download. How long should I wait for mail or link?Thanks in advance!

CPU MP, DP and Memory Threshold

Hello all, i have manage a firewall appliance and iwant to make a preventive documentation, so i need to do the health check. i found several docs about the health check and the threshold (temperature, etc). But i didn't find a docs about CPU DP , MP and memory threshold like picture below. is there any docs from palo alto that state about this?...

DennyChanditya_1-1668530658176.png
DennyChanditya_0-1668530929615.png

Resolved! PA not be able to access internet

Dear All, I have a PA-1410 and the box do not have internet connectivity and below are the configuration, when i do trace route i see the next hop is showing 192.168.1.1 (mgmt interface) instead of 192.168.1.100 (ethernet1/1) and under monitor - taffic tab i do not see any traffic coming from trust to untrust, is it true that the...

piaakit_0-1721201899741.png
piaakit by L1 Bithead
  • 5401 Views
  • 6 replies
  • 0 Likes

Globalprotect 6.3 - CIE and Embedded browser

According to the notes on globalprotect 6.3, CIE should now be compatible with the embedded browser, but I cannot get it to work. I see the requirements for the feature is PANOS 11.2 or later - we use Prisma, so not sure if Prisma is not compatible with it? Has anyone had any luck with Globalprotect + CIE + Embedded browser + Prisma? This is ...

change the name on a GP portal and gateway

Is is possible to rename an repurpose a global protect portal and gateway? I have one named student that is not being used but I want to repurpose the IP's and save myself from rebuilding a new one by just renaming and reusing student portal and gateway but the name is greyed out

jdprovine by L4 Transporter
  • 13613 Views
  • 11 replies
  • 0 Likes

Password changed for user admin

Hi all,Yesterday we noticed a line in the Monitor tab that made concerns:But none of the administrator changed the password for user admin.When checked the logs if this user has logged in on Monitor tab, there was no login with this username admin in front of this password change.Could a commit or other system auto-commit make this log line? Tha...

changed_password_admin.png

Resolved! IPv6 on public interface

Dear all, I'm ttrying to get IPv6 up and running but so far without much success.My ISP assigend a /48 range to me and they are saying I need to use DHCP. AFAIK, DHCPv6 is not supported, but NDP is.Assume my IPv6 prefix isabcd:1234:5678::/48 So I enabled IPv6 on the public interface and set the interface IP toabcd:1234:5678::/48Enabled Interfac...

New Public IP Block-NAT

We have our PA connected to our ISP via /30's and they gave us a /28. We have a SilverPeak sdwan appliance behind the PA and are NAT'ing it's WAN interface from 10.5.1.2 to x.x.x.50. We can reach the SilverPeak on 443, but when we noticed it's not trying to establish underlay tunnels with the other SilverPeaks. I tried to manually configure a...

jasongorman_1-1721182677357.png

Dual ISP Failover with site to site VPNs

Hey everyone,Just started with Palo and was researching the optimal way of configuring ISP failover to include automatic failover of site to site tunnels.Is there a reason to use PBF over static route removal?Based on the reading date I was doing today, SRR appears less convoluted than PBF and seems the most similar to Cisco's SLA configuration ...

Evahi21 by L0 Member
  • 4565 Views
  • 4 replies
  • 0 Likes
  • 24375 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels