General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4220 Views
  • 0 replies
  • 0 Likes

OCSP Service Temporarily Unavailable

Hi team, I have configure an OCSP responder on my Panaroma, I do all the step of the documentation https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/certificate-management/certificate-revocation/online-certificate-status-protocol-ocsp. But when I generate an OCSP request, I recieve this :openssl ocsp -issuer cert.pem -cert cert.pem -...

Threat logs from DNS Proxy zone not showing source IP

We use DNS Proxy on 3 of our zones with the firewall IP as the address that the traffic is proxied to. In other words, the firewall proxies the network traffic with it's own IP address. However, in the threat logs, we have some threats that do not show the original source IP and instead show the firewall's IP as the source address, due to the ...

Doubt about Minemeld version 0.9.70

Hi team We currently have deployed a server (Minemeld version 0.9.70), Company Systems requires us to upgrade the operating system of this server. It is running Ubuntu Linux 16.04. We are asked to deploy a version that runs Ubuntu Linux 22.04. Is it possible to upgrade the system or deploy a new OVA with this need fulfilled? Regards

Alpalo by L4 Transporter
  • 1139 Views
  • 1 replies
  • 0 Likes

creating a customer account

I am attempting to create a Palo Alto customer account so that I may transfer a Palo Firewall that it I have purchased to it. I do not have a sales number for the purchase so I cant create an account. I am buying the unit from a partner. It is a unit to be used for training. How can I create an account????? Thanks in advance for shared wi...

Device Certificate not showing

Hello Guys, I have problem with device certificate, i have create the device certificate, but is not showing in GUI Palo Alto.but when i try to import configuration the certificate is showing.anyone can help me why device certificate is not showing in GUI ?

dwi.nur by L1 Bithead
  • 21168 Views
  • 14 replies
  • 0 Likes

ECCN for PAN-OS

Hello, I require the ECCN for your software, PAN-OS. I do not have access to the 'HW Accessory Cross Reference' link I have seen posted. Alternatively, please provide an email address to your Trade Compliance team so I can contact them directly. Thank you.

ECJTBBAE by L0 Member
  • 1553 Views
  • 1 replies
  • 0 Likes

Packet drops with Unknown-TCP

Hi Team, Need your suggestion on below. We have created a policy to allow access to a site with URL filtering. Created new category to the specific set of URL and then allowed the same in URL Filtering Profile and called the same in ACL. Source is set to LAN Range, Destination is set to Any, Application is set to Any, Service is set to Any, URL ...

Allow only global protect from trust to untrust.

Hi Everyone Greeting. I need to allow only the GlobalProtect application from the trust to the untrust zone, by allowing: First security policies : source trust -> destination untrust -> Application DNS -> Allow Second security policies : source trust -> destination untrust -> The Paloalto-shared-services application, by openi...

ariiero by L1 Bithead
  • 1705 Views
  • 2 replies
  • 0 Likes

Explicit proxy chaining

Hello, I like the explicit proxy functionality but missing option to use proxy chaining and forward all the explicit proxy requests to an upstream proxy. Some ideas how to archive this? Thanks for any recommendations Lumir

itsnoc by L1 Bithead
  • 1989 Views
  • 3 replies
  • 0 Likes

PA-440-LAB purchase without going thru my employer

Anyone know where and how I can purchase the PA-440-LAB bundle without going thru my companies account and vendor? I did that with the 220 and it was a nightmare. I want to setup an individual PA account for support and licensing and acquire the lab bundle directly. Thank you

millc5 by L0 Member
  • 7827 Views
  • 3 replies
  • 1 Likes

QoS: only ever matches default-group

I'm obviously missing something simple here, but nothing I've tried makes a difference. Creating a QoS Profile to configure the 8 classes: works great. Creating a series of QoS Policies to classify AppIDs, URLs, users, etc into difference classes: works great. Creating multiple QoS Profiles to limit bandwidth for separate networks: nothing ...

fjwcash by L4 Transporter
  • 9512 Views
  • 9 replies
  • 0 Likes

Globalprotect SAML Auth with Azure and MFA not prompting for MFA after reconnect

Hi All, There are a few topics on this.. I read most of them still unable to resolve this.. we have panorama with managed FWs (10.2.6) and GP portal and GW setup pointing to SAML profile that integrates into Azure and Azure IdP for MFA at first logon, i was prompted for MFA and connected successfully. log off, log back in again and does not pr...

PA_nts by L4 Transporter
  • 12088 Views
  • 5 replies
  • 0 Likes

Prisma global protect

Bonjour, Lorsque l'on configure la gateway global protect sur Panorama, que doit on renseigner dans la partie " IP de la gateway externe" sachant qu'on se connecte à une gateway France North ou France south dans prisma? Pareil que doit on mettre pour l'IP du portail?

Sarou22 by L2 Linker
  • 1606 Views
  • 3 replies
  • 0 Likes
  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels