General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! TCP & UDP Floods from trusted zones

Hi everyone, We receive TCP or UDP Flood threat logs from time to time on different firewalls of ours. In the image below you can see that the source and destination zones are the same, i.e. "zoneTrust", and this the case for all threat logs of this type. Is this information regarding zones reliable? and if yes, how can we find the host(s) respo...

Arman_Zaheri_0-1722255506276.png

App id

Hello, I have a question about app id. The App-ID description contains a Deny Action description of the action taken. Whatever action is imposed by the security policy, the flow will follow the action of the App Id?

Sarou22 by L2 Linker
  • 2079 Views
  • 3 replies
  • 0 Likes

How to Deny or Drop Replies in Allowed UDP Sessions

Hi All, I'm trying to address a hypothetical scenario where some solutions act only as listeners and do not need reply to the sender. For example, a SIEM system listening on UDP port 514 does not reply to the log sender. In such a case, we configure rule as follows:- Source: Log source- Destination: SIEM server- Service: UDP/514 However, I’m con...

Resolved! SYSTEM ALERT : medium : MLAV: Unknown error

Repeatedly receiving the above alert on 4 separate PA firewalls throughout the evening, can't find much information online relating to it. Has anyone else received this message before? If so, what steps should I take to troubleshoot and resolve the message. currently running versions 10.2.6-h3 and 11.0.3-h10. Thanks

KirkH by L0 Member
  • 10630 Views
  • 15 replies
  • 6 Likes

Resolved! Can't get AD and SMB to work from Azure to On-prem server

Hi, I'm working on a newly created Azure environment with very little networking set up. Our setups are as follows: Azure: Working S2S VPN Route table pointing to the on-prem subnet A VM for testing with an NSG allowing all traffic both inbound and outbound On-Prem: Necessary firewall rules (Palo Alto) to allow AD, SMB, RDP, and ping A domain...

Resolved! Application override

Hello, Application Override to a custom application will force the firewall to bypass Content and Threat inspection I've read several documents but I still don't understand the point of doing this. What's the point? Thanks

Sarou22 by L2 Linker
  • 2289 Views
  • 3 replies
  • 0 Likes

Resolved! Single pass parallel processing

Hello, I don't understand why it is said that the single pass parallel processing performs operations once per packet.What does this mean? Firstly, the single-pass software performs operations once per package. Thanks

Sarou22 by L2 Linker
  • 2770 Views
  • 3 replies
  • 0 Likes

Resolved! Palo alto candidate configuration vs running conf

Hello, I don't understand the difference between candidate configuration and running configuration. Before committing when I'm making changes it's the running configuration and when I commit it becomes candidate configuration? Another question. I've made a commit and I'd like to rollback how do I do it?

Sarou22 by L2 Linker
  • 8572 Views
  • 2 replies
  • 0 Likes

Tunnel Monitor - PAN-OS SDWAN

I've had an issue recently where randomly I've had members of my VPN mesh start to have the tunnel monitors going up and down constantly which causes BGP to never be able to establish with the peer since the static routes to the loopbacks are pulled from the route table. This has happened randomly to 2-3 sites back to either of the hubs. When ...

PA-220 disk space issues

As most with a PA-220 have experienced, regardless version running (currently latest 10.2.3-h2) root partition fills up all the time and have to run the disk-usage cleanup commands manually and tried enabling aggressive-cleaning as well, it just continuously hits level/ But it just fills up all the effin time:-) With the root disk issues seemi...

Configuration Sync is not happening on HA,Server error : Failed to synchronize running configuration

Running configuration sync is not happening between HA peers(PA-5050). We tried manually from Passive firewall CLI by the command request high-availability sync-to-remote running-config but I are getting the error Server error: Failed to synchronize running configuration with HA peer; operation not allowed: URL Database mismatch.I have restarte...

NijithPN by L1 Bithead
  • 17729 Views
  • 10 replies
  • 0 Likes

Resolved! PA-445 Passive Device LED status

Dear Team, I noticed something unusual during my testing. PA-445 was configured as HA. The front LED of typical firewall hardware is orange when in the passive state. However, for the PA-445, both Active and Passive Devices are green. As a result, active and passive cannot be distinguished visually. The PAN-OS version in use is 11.1....

Destination NAT Mismatch error

Hi I'm configuring a new PA-500 and have it working for source NAT going from Tusted to Internet. Now I want to create a destination NAT rule to allow traffic in to a web server located on the trusted net. I have created a rule almost exactly as it shows in the Admin guide but I'm getting the error - “nat rule “Incoming Web”: Mismatch destinatio...

Resolved! Issues with pushing out 10.2.9-h1

There is not a community discussion for issues implementing 10.2.9-h1 We have a maintenance window to push out 10.2.9-h1 Thursday evening and with recent issues with 1.2.7.h3 and other roll outs i am starting this thread for the community.

  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels