General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Help with first steps with a VM trial.

HI everyone,I'm trying to install a PaloAlto VM ESX 10.2.5, and when i have install it, i can't access with admin/admin. When I try to enter in maint mode, there are a password for advanced options, and neither admin. I try admin root password and it doesn't work. Looks like the credentials are changed, someone knows something? thanks

AlonsoRecuero_0-1720699447479.png
AlonsoRecuero_1-1720699734989.png
AlonsoRecuero_2-1720699749644.png

NGFW PA-1400 POC Guide

Hi, I am beginner for firewall configuration and will need to lead POC soon. Appreciate if you guys can share the guide, step-by-step for firewall configuration for POC purpose. The client wish to test on bundle license ATP, ADVURL, AWF and DNS and SD-WAN. Thank you in advance!

Prefered PANOS version

Dear Friends, One of my customer is facing issue with inbound connection traffic after upgrading firewall from 11.0.4-h1 to 11.1.2-h3. Where inbound traffic was not reaching to firewall although 11.1.2-h3 is the prefered version. Additionally, we couldn't see any traffic logs. Then we reverted to our previous version 11.0.4-h1. After downgradi...

Resolved! Device - certificate based authentication

I am attempting to implement this in my home lab. Has anyone done this? Basically the situation where if a device connects to the network, it should have a certificate installed from my CA. If it does not, then a security policy (or other policy) should deny the device network traffic. Some articles suggest the use of GlobalProtect but I do not ...

DHCP Realy

Hello, I have an issue related to DHCP Relay, I configured it on my Palo Alto to allow users to get IP from the DHCP server behind the Palo Alto but it not working can anyone help me how can I troubleshoot this issue to check if this issue from Palo alto side or not

amr.ali by L0 Member
  • 2056 Views
  • 1 replies
  • 0 Likes

Resolved! SSO Palo Alto Support Portal

Hi everyone,is it possible to have SSO Accounts (Azure AD) and non SSO Accounts simultaneously in the Palo Alto Customer Support Portal (CSP)?In the future, we want to have one set of SSO Accounts and a pair of Emergency Accounts (non SSO), if the ISP is not available.Kind regards.

Resolved! Can't find the "Republic of Kosovo" in the "Firewall Region Code Legend"

Hey, new to the community today! I've searched the LIVEcommunity discussions and the web, but couldn't find any solutions or anything related to such a problem. We have geo-blocked every country in the world by default and add countries to an exepction rule whenever needed. Today I was asked to grant a client access from the Republic of Kosovo...

WildFire auto update agent failed to download Wildfire version 865169-869036

Hi , i receive alert through email that the WildFire auto update agent failed to download Wildfire version 865169-869036 on April 16 2024 at 15:01:48 GMT , 23:01:48 , 16:23:01:48 but when i go through the System logs, it doesn't show the version 865169-869036 is failed to download or success to install. a newest successfully wildfire packag...

alert.png

Resolved! PAN-OS 10.2 PPPoE on Layer 3 Sub-Interface?

Is there any way to get PPPoE working on a Layer 3 sub-interface in Pan-OS v10.2? I recently purchased a PA-220 for personal/study use. My ISP, Century Link, provides Internet access via VLAN 201/PPPoE. I'm currently running an ASA 5506 at the edge, which handles this configuration just fine. I'd like to swap it for the PA-220 but it seems l...

Trial copy

Hello . How to get trail copy of panos /firewall ? for kvm shrikant pune-india Thanks

shrikant by L2 Linker
  • 1897 Views
  • 4 replies
  • 0 Likes

Issues running VPN for UI Debian distribution

Hi all, I'm running 64-bit Debian Bookworm on a Raspberry Pi 5 and if I try running sudo dpkg -I GlobalProtect_UI_deb-6.1.4.0-711.deb, I get the following output in the terminal: electing previously unselected package globalprotect. (Reading database ... 128244 files and directories currently installed.) Preparing to unpack .../GlobalProtect_U...

decrypt-unsupport-param error with no decryption

We are receiving a decrypt-unsupport-param to a specific destination with no ssl inspection applied. I created a no decrypt rule and didnt apply a decryption profile so we weren't checking for expired or untrusted certs either. There is also nothing in the decryption logs for this destination IP address (we only log on failure) If I filter and...

Claw4609_1-1687892072473.png
Claw4609_2-1687892097915.png
Claw4609 by L5 Sessionator
  • 10826 Views
  • 5 replies
  • 0 Likes

Site-To-Site VPN Question

If we deploy a Site-To-Site VPN to one of our remote locations with a Palo Alto NGFW will our main hub firewall control the Threat/URL, etc... and Security/NAT rules for the other Palo Alto?

Doubt about migrate FW to Panorama

Hello team, I have a cluster of FW and Panorama both in version 10.2Tomorrow I will migrate a FW cluster to be managed from Panorama following the following KBhttps://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZSCA0Reviewing it, I have the doubt of when I should enable the option for the FW to receive the policies and ob...

Alpalo_0-1720698871940.png
Alpalo_1-1720699039382.png
Alpalo by L4 Transporter
  • 1369 Views
  • 1 replies
  • 0 Likes

Resolved! Is there any way to apply multiple interface management profiles

I have an interface management profile that allow HTTPS, SSH and PING on an untrust interface for specific IP addresses. My ISP cannot monitor this interface because their monitoring IP addresses are not in the list of permitted IP address. I don't want to add their IP addresses because I do not want these IP addresses to have SSH or HTTPS acces...

A.Rith by L1 Bithead
  • 2132 Views
  • 1 replies
  • 0 Likes
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels