General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 193 Views
  • 0 replies
  • 0 Likes

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 875 Views
  • 0 replies
  • 0 Likes

Resolved! Site to Site IPSEC Clarification

I'm moving from a Cisco ASA to a Palo Alto firewall for the first time. I've imported the config to Expedition and am prepping it for import to the firewall, but I noticed only the first of my crypto peers for each tunnel was imported to an IKE gatew

...

Palo Alto Search Filtering in Contains

Hello,

 

I write a basic python code for 'contains' filtering in in rule name search. And I want to share with community also community can give an advice for me.

 

The code: 

"""""""""""""""""""""""

def generate_output(numbers) :
    output_strings
...

tombombadil_0-1706780527481.png

Global Protect Asymmetric routing issue

Hey team hope someone can help me. I am pretty new to Palo and I am trying to setup Global Protect PreLogon in our corporate environment. I have managed to get it all working in the lab (awesome) now doing that in the live environment is different ba

...

Shadmin by L1 Bithead
  • 4122 Views
  • 4 replies
  • 0 Likes

Radius Group for GP authentication

Hi All,

We need to setup a specific user group in Radius should only access the GP. No other users should access GP. Currently authentication method set for GP is Radius and in the same radius we need a specific group of users only to authenticate.

M

...

Resolved! PAN-OS Uprage PATH to 11.0.2-h3

Confirming the Upgrade Path - Currently version 10.2.3-h2 upgrade to 11.0.2-h3 1.

Download 11.0 2. 

Download and install 11.0.2-h3  

 

Am I correct? do I need to reboot twice for this OS upgrade?

 

NGFW 

Azure AD SSO with customer portal

Hi 

Can anyone help out with setting up a 3rd Party Identity Provider on Customer Support Portal?

I've read through provided instructions (https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sZ8mCAE), however, I'm stuck at Enabl

...

Radius Authentication and NPS

Hello everyone,

I'm having trouble configuring palo alto with a Radius NPS server. Basically we do not want to use chap protocols to avoid enabling reversible password. So we wanted to use EAP-TLS but it does not seem compatible with Palo Alto. Then

...

zakergfx by L1 Bithead
  • 1501 Views
  • 1 replies
  • 0 Likes

VM-Series 30-day trial not correct login prompt

VM-Series 30-day trial not correct login prompt

 

only seeing PA-HDF prompt

 

I am aware there are 3 prompts for login during the initialization phase and the VM seems to keep getting stuck at the second one (PA-HDF). I know the initialization can ta

...

One isp to multiple isp site to site tunnel

Hi Team,

 

We want to configure ipsec site to site tunnel between two locations as per below details

 

1) Location A having single ISP address i.e Wan address  (1.1.1.1/30) will connect to location B having 2 ISP address (2.2.2.1/30 & 3.3.3.1/30) and

...

Disable IoT Service as workaround of PAN-216043

We are having a problem in our PA cluster. One of the firewalls is restarted and HA is activated. This problem occurs approximately every 3 weeks and the error I found is from Wifclient and according to the paloalto documentation the workaround is to

...

EliasCoranti_1-1706792909590.png
EliasCoranti_0-1706792814014.png

Resolved! Show hit count in CLI

I was searching this forum and official documentation, but I can't find the following:

Is there equivalent to Cisco ASA "show access-list acl_name" command in the PAN-OS CLI. I am looking for the command that will show hit count for every configured

...

Resolved! Point to site VPN on pan 0S 11+ (Client to remote VPN server)

I remember reading some where Palo Alto firewalls works like a client to access remote VPN servers 

 

eg I can setup the PALO to access a OpenVPN server and give access to user on my palo managed local network to access that remote resource, than use

...

din100 by L3 Networker
  • 1599 Views
  • 3 replies
  • 0 Likes

Impact of run tcpdump on every interface.

Hi,

 

We need to execute tcpdump in PA-VM for a specific reason. We need to TCPdump data from firewalls for 15 minutes at various intervals; there is no specified source or destination. When we run tcpdump from every interface, we want to know if it

...

  • 24009 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Posts
Top Liked Authors
Labels