General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! SSL Connection Error During Panorama-Orchestrated HA Upgrade

Hi all, First time posting, so bear with me. We manage fairly large fleets of devices across multiple clients, so the new HA upgrade orchestration from Panorama looked like a big time-saver. We decided to test it with one client but ran into the issue shown in the screenshot: "Download error: SSL connection error". Has anyone encountered this — ...

return traffic being dropped, not being sent through the vpn tunnel

issue: 1 server behind PA being accessed through 2 different tunnels tunnel 1 = working tunnel 2 = incoming traffic working, the return traffic is being grabbed by interzone-default = deny, and on the PA seen as a new session being initiated, for which there is ofc no security rule in place to allow anyone with an idea why the return traffic ...

20f2c37f-cc78-4da5-bea8-6c2fc3fb4fe3.png

Resolved! Static Port Address Translation question

This configuration issue seems like it should be very easy to figure, but I have not performed this in the past and I cannot seem to figure it out. We will have multiple devices on the trusted network, and I need to NAT them all to a single Public IP address using a different port number for each private device. All devices will utilize port 44...

JohnSturk_0-1695407774096.png
JohnSturk_1-1695407912202.png

Is It Possible to Distribute Client Certificates to iOS Devices Using GlobalProtect SCEP Without MDM?

I would like to ask whether it is possible to distribute a client certificate to an iOS device at the time of GlobalProtect authentication by using SCEP, without relying on any MDM solution. My goal is to enable client certificate–based distribution and authentication for GlobalProtect on iOS, and I am currently exploring approaches that do not ...

Panorama continuously pulling expired Strata Logging Service License

I have a customer here who is running into an issue when applying their new Strata logging Service License on Panorama. The old license expired awhile ago and the new license was never applied. They have now lost all visibility of their cloud services from Panorama and so are trynig to apply the new license. In GUI we can pull the new licens...

IPSEC to Azure establish but cannot use traceroute

Hi All We have PA 410 and has established an ipsec tunnel to Azure.We testing from PA-410 to cloud that ping, SSH, and traceroute are working normally.However, when testing from cloud to PA-410, ping and SSH work as expected, but traceroute does not function. A packet capture was performed and it was observed that the traffic UDP was dropped ...

Feature Request List

Hi community In a lot of topics there are discussions and questions about PAN-OS enhancements and missing (not yet implemented) features. So far the PaloAlto Feature Request list isn't available to the public but in a lot of these existing topics feature request IDs (FR ID) are mentionned. Even knowing that PAN-OS is already a feature rich fir...

Remo by L7 Applicator
  • 119546 Views
  • 151 replies
  • 21 Likes

Search for old KB kA10g00000PLW6

I am looking for a this KB that I bookmarked in 2022. KCSArtcleDetail?id=kA10g00000PLW6 Can you someone point me to the new KB? Thanks, Jay

wuj by L1 Bithead
  • 1067 Views
  • 4 replies
  • 0 Likes

How to add Wildcard Domains as a destination for Firewall policy PA1420

Dear all, I have blocked the Port 80 in my network so any clients try to access the internet over the port 80 should not be allowed. But the thing is that some of the micorsoft IPs and Domains runs over the port 80. Now I want to add a new firewall rule to my palo alto 1420 to allowlist Miscrosoft IPs and domains over the port 80 and 443, ...

About side scrolling in the UI

Hi. I'm used to do side scrolling in Chrome by using this combination: shift + mouse wheel. But when I try that (for example in the Policies tab) i get "diagonal" scrolling. I think that current implementation of scrolling relies on javascript. You should look for modifiers and prevent vertical scrolling if shift was pressed. Thanks

Resolved! How to upgrade to PAN-OS 12.1 on PA-3400 (not shown in GUI)

Hello Experts, We are currently setting up a PA-3400 series firewall and would like to upgrade PAN-OS to version 12.1. Current version: PAN-OS 11.1.13 We understand that PAN-OS 11.1 may be more stable, but since it is approaching EOS within about a year, we would prefer to deploy 12.1. However, when we check under Device > Software in the G...

Quest Asc - TSF Upload take forever

I am trying to upload a TSF to the Quest Asc tool, The TSF is 120 MB. When I upload no error but it keeps spinning. I have tried it few times and no luck. I have a good stable internet and good upload/download speed. Tried different browser but no luck. The only thing I can think off is Netskope but don't see any blocks either.

ArunKu by L0 Member
  • 970 Views
  • 3 replies
  • 0 Likes

Resolved! why PAN‑OS version 12 is often considered not recommended

I would like to ask why PAN‑OS version 12 is often considered not recommended.Is it mainly due to stability concerns during the first year following its release?New PAN-OS 12.1 Release Cycle & 4-Year Support Policy | Palo Alto Networks>During the initial Innovation Phase (the first 12 months), we will deliver two targeted Feature Releases...

Resolved! What PAN‑OS version should we choose as the recommended release today?

Hello everyone, I have a question regarding the recommended PAN‑OS versions. In the past, Palo Alto Networks provided a web page that clearly indicated which PAN‑OS versions were considered recommended or preferred. However, recently it seems that some of those pages are no longer accessible, or at least I can no longer find them through the sam...

  • 24432 Posts
  • 125 Subscriptions
Top Solution Authors
Labels