General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 301 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3645 Views
  • 2 replies
  • 14 Likes

Resolved! Export/Import Named Configuration Snapshot

Hi everyone!

 

Can someone confirm that the subject can only be done by "superuser" account?

I can't find any documentation that says so. I'm wondering because "export device state" is visible for superuser account, when using a "device administrator

...

Resolved! Proxy ID's and routes needed?

Team,

 

If I am building a tunnel to a Policy Based device and I configure Proxy ID's do I need to add routes for the VPN as well on the Palo?

 

Or just Proxy IDs?

SCEP for firewall device cert?

We do not currently have SCEP set up in our environment nor are we familiar with it. But if we did have it set up would our PA firewalls be able to request a cert that we could then use in a SSL/TLS service profile to have a secure connection between

...

Claw4609 by L4 Transporter
  • 974 Views
  • 1 replies
  • 0 Likes

Resolved! URL Blank in Traffic Logs

The traffic logs for our PAs almost never actually show a URL, despite the URL category getting properly assigned. The only time I ever see a URL show up in the logs is if it is specifically denied because of the URL category, which is fairly rare. I

...

Resolved! Accessing A New Palo Alto Firewall In The GCP

Experts.,

 

We have a virtual Palo Alto firewall (BYOL) in the GCP and were able to change password using the initial access and the ppk file.

We provisioned one more VM firewall in same GCP setup, however this time we are unable to recreate the steps w

...

kgsd2019 by L1 Bithead
  • 4762 Views
  • 7 replies
  • 0 Likes

Resolved! About User-ID Agent

Hello,

 

I've been practicing Palo Alto lately, I'm having trouble setting up "User-ID Agent"...
This is my simple structure :

I set up "AD server" and "User-ID Agent" on the same Winserver

I also added Win10 to domain, and gave it an account (michae

...

young19918_1-1681749791819.png
young19918_2-1681750176934.png

Connect same VLAN to multiple V-SYS

Hi All,

 

We have a PA-5220 firewall cluster which has running multiple V-SYS itself. The firewall is connected to the up stream router thru a port channel. On the up-stream router VLAN 10 is allocated to the WAN-IP range. I need to extend that VLAN

...

QoS: only ever matches default-group

I'm obviously missing something simple here, but nothing I've tried makes a difference.

 

Creating a QoS Profile to configure the 8 classes:  works great.

Creating a series of QoS Policies to classify AppIDs, URLs, users, etc into difference classes:

...

fjwcash by L4 Transporter
  • 3262 Views
  • 8 replies
  • 0 Likes

PBF not working with DNAT policy for server

Dear Team,

 

We have 5 ISPs and we have configured PBF for a group of IPs/networks.

 

We observed while routing the server from X ISP to Y ISP, the server which is published on X ISP becomes inaccessible.

 

Request you please help to resolve the issu

...

VINAYAKJ by L0 Member
  • 603 Views
  • 1 replies
  • 0 Likes
  • 24183 Posts
  • 100 Subscriptions
Top Liked Authors
Labels