General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1939 Views
  • 0 replies
  • 0 Likes

Broken capture in SASE workshop registration

I'm not sure of the best location for this. I'm trying to register for a SASE workshop (and I'm not sure if it's online or not, but that's another conversation), and I need to complete a captcha. Unfortunately, I can't see most of it (see the attache

...

BillC by L0 Member
  • 706 Views
  • 1 replies
  • 0 Likes

Resolved! Paloalto Images not available

Hello Gents,
I noticed, Paloalto has removed access to the VM resources.
I dont see "Updates" tab in the menu.
Earlier I used to download KVM/QCOW2 from my personal account (Not Organizational Account).
But now its not available, can anyone help me downl

...

ssgilani by L0 Member
  • 846 Views
  • 1 replies
  • 0 Likes

Bulk changing target device in policy set

I have several policy sets which have between 500-900 rules each and are being re-used for a firewall migration. Each of the sets has the old 850 palo set as the target device. To save time on migration night I am looking to change the target to "any

...

MAllen_0-1756208384619.png
M.Allen by L1 Bithead
  • 710 Views
  • 1 replies
  • 0 Likes

S2S VPNs using Self-signed Certificates

What is the procedure for configuring Site-to-Site VPNs using self-signed certificates?

For example, we need to establish a VPN between Firewall A and Firewall B.

The documentation describes how to create a self-signed Root CA certificate, but it doe

...

ET by L2 Linker
  • 799 Views
  • 2 replies
  • 0 Likes

Cloud NGFW Credits issue

Hello All,

I recently purchased Cloud NGFW for azure and purchased paloalto credits as well.

my Azure NGFW shows as PAYG ( Pay us you go) instead of showing license with my credit.

is it possible to change my PAYG license to credit based.

M.vyas by L0 Member
  • 842 Views
  • 3 replies
  • 0 Likes

Resolved! Creating CSR with SAN via API calls

Hi,

I am trying to create CSR via API calls with subject alternate name for hostname and ip address, but I cannot find it in documentation. Simple creation of CSR works for me
https://10.XX.XX.XX/api?type=op&cmd=<request><certificate><generate><certif

...

nm2025 by L0 Member
  • 1298 Views
  • 2 replies
  • 0 Likes

Type: INNR in session id detail.

Hi team,

 

What does INNR represents in type when looking at the session ID details.

I know that this happens at child session, when parent session ID belongs to the HTTP/2 ID.

If you guys have any idea about what INNR represents, let me know.

 

 

 

 

Mgmt Traffic over VPN

Hi All,

 

  I am looking to deploy a few (4) PA-440's into the field. What is the best way to configure my remote firewalls to send MGMT traffic 3.3.3.3/24 (using loopback) over a vpn to central firewall to pass along to panorama MGMT (10.10.10.10/24

...

jQuery vulnerability on management interface of PA-3220

Hello all,

 

Our customer is currently using PA-3220 running PAN-OS 11.1.
During their recent vulnerability scan, the following CVEs were reported that jQuery used on the Web management interface;

 

CVE-2018-8046
CVE-2007-6758

 

Questions:
1. Do these v

...

kawai818 by L0 Member
  • 425 Views
  • 2 replies
  • 0 Likes

spanning tree portfast for cisco to palo links

I am moving some palo interfaces to a new cisco switch. 

What is the recommended spanning tree configuration on both palo and cisco sides when connecting these devices?

 

PA(config-if)# spanning-tree port type ?
edge Consider the interface as edge por

...

M.Allen by L1 Bithead
  • 819 Views
  • 1 replies
  • 0 Likes

wrong traffic matching rule

Hi this maybe a simple or dumb question, but I have a rule shown below that has specific sources defined. I thought the rule would only match on those host listed in the source, but when looking at the logs, I can see other source IP's are matching o

...

palo-rule.jpg
palo-logs.jpg
E.Hinkle by L0 Member
  • 676 Views
  • 1 replies
  • 0 Likes

Resolved! How to add switchport trunk allowed to AE interfaces?

I have a cisco switch which has a trunk to a PA device. On the switch it is configured switchport trunk allowed vlan 120,766,767. How do I add the corresponding configuration on the PA end?

The AE2 int already has the .120, .766 and .767 sub interfac

...

M.Allen by L1 Bithead
  • 1431 Views
  • 3 replies
  • 0 Likes
  • 24197 Posts
  • 117 Subscriptions
Top Liked Authors
Labels