General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4234 Views
  • 0 replies
  • 0 Likes

Upgrade from 9.1.x, to 10.1.x, 10.2.x, 11.x

Upgrade to from 9.1.X, to 11, 10.2.X, 10.1.X ? Hello, good afternoon, how are you? I have a question regarding which is the recommended version to update from PAN-OS 9.1.X. Personally I consider that version 10.1.X ( 10.1.8-h2 ) is the recommended version, I feel that version 10.2.X is very recent and version 11, well you know, is much, much m...

Metgatz by L4 Transporter
  • 20027 Views
  • 5 replies
  • 0 Likes

How to remediate overly permissive any- any rule

We have an overly permissive rule with Source, destination and ports as Any. We are working to remove this rule but this is widely used. Please suggest what's the best way to identify the traffic using this rule and to create rules with specific source, destination and ports.

How to setup No-IP Dynamic DNS on Palo Alto PAN-OS 9.0.12

Good day all, I spent quite some time figuring out how to setup the No-IP dynamic DNS service on my PA-220 running PAN-OS 9.0.12 and I want to share how I did it as it wasn't a straightforward process for me and I am sure it isn't for others either. Why do you want to do this?This will allow you to use a fully qualified domain name (FQDN) to ref...

Capture1.PNG
No-IP Dyanmic DNS Menu.PNG
Hostname list.PNG
noupdates.PNG
Adam1981 by L1 Bithead
  • 45806 Views
  • 18 replies
  • 18 Likes

Clientless VPN 404 error

Hello everyone, i installed the clientless vpn and up to the login page everything is fine, but when i click on one of the apps i set it gives me the error "404 page not found", I don't have any kind of traffic log that I can analyze, the globalprotect vpn and clientless packages are correctly installed. The security policies are correct, I...

porq91 by L1 Bithead
  • 21085 Views
  • 16 replies
  • 0 Likes

Resolved! Traffic logs not showing since last PA update to 11

Hello, Sorry I'm a web developper not a OS nor PA expert. The University I work for started using PA 1 year ago and everything was fine. Then my boss upgraded PA to 11 + rebooted 2 weeks ago or so and since then, the traffic logs are missing. And -as you can guess- we need them badly at the moment. My boss says it is not a licensing problem ...

Susana by L1 Bithead
  • 4465 Views
  • 5 replies
  • 0 Likes

How do people manage certificates for the MGMT interface at scale?

Wondering how other manage the SSL/TLS Service profile that you attach under Device>Setup>Management>General Settings at any sort of scale. We manage quite a few firewall, via panorama, and the intent would be for each firewall to have a unique certificate for this? Is there a way we can template this would using SCEP in some way? The...

Claw4609 by L5 Sessionator
  • 4266 Views
  • 4 replies
  • 0 Likes

checkpoint R77.30 to palo450 migration

I plan to migrate checkpoint R77.30 firewalls (40 firewalls) to Palo450 devices. checkpoint is configured in a full mesh fashion. Can someone share some ideas on the SD-WAN configuration that is required between all Palo Firewalls, with the Palo backbone designated as SD-WAN. I'm thinking like For a seamless transition, we will set up tunnels ...

PAN-OS System Log - Max MIB size reached: LLDP neighbor addition failed...

Since upgrading to 9.0.X we have been seeing these messages in the system log: subtype eq lldpseverity eq higheventid eq 'too many neighbors'description contains 'Max MIB size reached: LLDP neighbor addition failed for <REDACTED> on interface 715' What do these messages represent? Why are they a severity of "high"? How do I resolve? TIA...

Resolved! QoS on Tagged VLAN Sub-interface

Hi there,I try to implement QoS on Tagged VLAN sub-interface. Found some configuration on main interface but not sub-interface one.Any suggestion? ^^Thank you

Amnuay by Not applicable
  • 11832 Views
  • 6 replies
  • 1 Likes

HIP logs to Panorama

I am looking to export HIP logs to Panorama. Firewalls are in Active-Passive mode. Since firewall sync HIP logs in between them I was getting two logs in panorama for each log entry (one from each firewall). Even though I configured active firewall only to send HIP logs to panorama, it is getting synced with passive firewall and there by passive...

Rajesh12 by L3 Networker
  • 2190 Views
  • 1 replies
  • 1 Likes

Recommended PAN-OS version

Hello, I'm running a PA-VM with PAN-OS version 10.2.X and need to check the TAC guidance for preferred / recommended version of PAN-OS I have tried to access: https://live.paloaltonetworks.com/t5/customer-resources/support-pan-os-software-release-guidance/ta-p/258304 however, it returns an "Access Denied" error. Regards,

ahammad by L0 Member
  • 6379 Views
  • 1 replies
  • 0 Likes
  • 24358 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels