General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4144 Views
  • 0 replies
  • 0 Likes

Qos statitics question

Hi,The above screenshot I took from the Qos rules under Qos Statistics .The Name field (first column ) is empty . What does it mean .?Thanks

sib2017 by L4 Transporter
  • 2568 Views
  • 3 replies
  • 0 Likes

Resolved! Application Blocking

Dear PAN Discussion Forum,I come to you in dire need of assistance. There is a battle going on within my network realm. A battle that we are losing. Some of my people have been mislead by downloading the Torch Browser application, and are now infected!The Torch Browser. Sucks in my users with an edgy-cool looking website that shows its fun to us...

Rags by L2 Linker
  • 11771 Views
  • 6 replies
  • 1 Likes

Resolved! Blocking Facebook for a group of USERS

Hello To All,We've a PA-500 which is linked to the AD. The idea is to block Facebook for a group of users.The thing is when those users will be logged (login and password), the AD update the PA-500.To block facebook for those users, What should be done?-1- Create a group of users-2- Create a Policy which include those users and a Deny rule for f...

Android VPN Split Tunneling

Hi, I have problems with Splti tuneling and Android devices using preinstalled VPN Android client. There is a workaround to solve it ? Regards, Jorge Goya.

IAC_SIC by L1 Bithead
  • 3692 Views
  • 2 replies
  • 0 Likes

Resolved! Upgrade cluste A/P and panorama

Hi, we have to upgrade a cluster active/passive and a panorama of this cluster. which are the steps to do these upgrades???1)upgrade the cluster like usual and then upgrade Panorama???2) first update the Panorama and then the cluster????advices...thanksRegards,

SOC_CSG by L4 Transporter
  • 3102 Views
  • 1 replies
  • 0 Likes

Resolved! PaloAlto firewall is sending system alert

Dear All,PaloAlto firewall is sending system alert saying "PAN-DB url filtering has expired" . But the i am using only "Bright cloud" url filtering license.Please suggest.RegardsSatish

Satish by L4 Transporter
  • 3778 Views
  • 2 replies
  • 0 Likes

Upgrade 5.0 to 6.1

Firewall device has two disk partitions:Partition 1 => 5.0.XPartition 2 => 5.0.Y (current active version)When you install now 6.0.X, it will overwrite 5.0.XSo after reboot Partition 1 will be active. Then you install the next update to 6.1.X, this will overwrite Partition 2.Partition 1 => 6.0.XPartition 2 => 6.1.X (active version aft...

Anon1 by L4 Transporter
  • 1954 Views
  • 1 replies
  • 0 Likes

Configuring Prelogon for GlobalProtect

I'm having a heck of a time getting prelogon working for global protect. I have spoke with both Palo Alto support, as well as a vendor that is a Palo Alto partner. Neither were really able to answer my questions.Here is what I have today. Two Palo Alto 3020's. One is on the west coast, and one on the east coast. I have the portal license on...

TheHuth by Not applicable
  • 8415 Views
  • 11 replies
  • 0 Likes

Change HA from A/A to A/P - techniques and known issues?

I have two PA-500's in Active/Active.We do not need to have them in A/A (in hindsight, it was a mistake) because we do not use asynchronous routing or meet the other typical A/A criteria. I think we are paying for that mistake, as you'll read below.When running software 6.0.5 I implemented a site-to-site VPN through which I ran a client-server a...

Resolved! User-ID for DNS

We have a server that has no body logged into it and all the DNS traffic from that server is showing as a certain user sending the traffic. Is there anyway to exclude this server from User-ID or another way to remove the user from this traffic?

Resolved! GlobalProtect User Information

Hi,Is there a way to see Global Protect tunnel statistics in either Panorama or the firewall itself? I'm looking for bytes in, bytes out, packet in, packet out statistics. The statistics are viewable from the client side if you open up the Global Protect agent, but I would like to see them from the Panorama/firewall side if possible.Thank you,...

stevena by L0 Member
  • 3347 Views
  • 1 replies
  • 0 Likes

Resolved! Cleaning up rules

So, I, like a number of people, converted from Cisco to PAN. We had a consultant in to help with the conversion, and he was assisting with the rule cleanup. However, a) a lot of rules came straight across as it was time-critical, so they are service based, and b) I have trouble wrapping my head around app-based policies. Is there a tool that ...

rivkin by L1 Bithead
  • 4881 Views
  • 4 replies
  • 0 Likes

Resolved! Restart daemons/services

Is there a way to manually restart daemons and services in the CLI?I have a box with sslvpn configured. The sslvpn suddenly stopped working and the portal page doesn't load. I double checked the config and the traffic logs show the traffic as being allowed and no threat/url logs being matched. I would like to try restarting just the services bef...

SDorsey by L4 Transporter
  • 20219 Views
  • 8 replies
  • 0 Likes

Error: Certificate failed to load: invalid certificate chain

Hi there,I generated a CSR with PAN-OS 6.1.3 and submitted it to our Microsoft AD CA with subordinate CA template. After uploading the certificate it shows up under the root CA certificate of our domain. But when commiting the changes I get an "Error: Certificate failed to load: invalid certificate chain" error message. What have I done wrong?Th...

cale by L1 Bithead
  • 12981 Views
  • 4 replies
  • 0 Likes
  • 24340 Posts
  • 124 Subscriptions
Top Liked Authors
Labels