General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4131 Views
  • 0 replies
  • 0 Likes

Resolved! Unable to Upgrade from 11.1.3 to 11.1.13

Hi, I am having a problem to upgrde, with the objective of upgrading my PA-460 standalone from 10.1.13 to 11.2.0. I performed the following: Download 10.2.0 install and reboot; then maintenance release then the last 10.29 -h? release and reboot. Download 11.0.0 install and reboot then maintenance release 11.0.x (last ) and reboot. ...

Resolved! PAN OS 10, Two devices on different subnets in the same zone

We are running a Palo 5220. If we setup two different virtual interfaces with two different IP subnets in the same zone. Will I need to setup security policies to allow the two different subnets in a single zone to communicate. or will the Palo route traffic between subnets in the same zone with out any additional security policies?

MantaIT by L0 Member
  • 2737 Views
  • 3 replies
  • 0 Likes

Add OSPF Route Tags

Hi, I need to amend my routemap redistribution filter to set a tag to the routes in my referenced prefix list. My question is, when doing this on a live firewall, will this require OSPF to re-converge? Thanks

AndyFox by L0 Member
  • 1788 Views
  • 1 replies
  • 0 Likes

Defining patch management in HIP objects.

Hi All,We are configuring global protect with HIP enabled.Our requirement is, If the patch defined in the HIP object is missing in client machine then access should be denied. Below screen shows the patches (windows updates) for windows 7 machine.From above snap i want to use the highlighted update as match in HIP object (If this update is missi...

Gururaj by L4 Transporter
  • 11485 Views
  • 11 replies
  • 0 Likes

Out of memory: Kill process xxxx (mgmtsrvr) score xx or sacrifice child

This is a recurring issue, a reboot helps for time being. When attempting to update to the latest antivirus version, we see that the commit fails. System resources look normal. And looking at the techsupport file in /var/log/messages, we see that during various attempts: mgmtsrvr, devsrvr, logrcvr were the killed processes due to out of memory...

Screenshot_286.png

Palo alto PA3060 high memory usage over 60%

Hi everyone, In our performance report, it is find some Palo Alto PA3060 firewall memory usage keep high than > 60%, which trigger resource alarm refer our monitoring standard. I tried action like reboot device but memory level remain more or less the same. May advise way that can lower memory usage, say, <60% I also try to following the...

WilsonWu by L1 Bithead
  • 4103 Views
  • 3 replies
  • 0 Likes

Global Protect - SAML Authentication Complete Page

We're testing upgrading to version 2.5.x and have run into a few changes with the new features. We enabled "Use Default Browser for SAML Authentication", because you know ie, is going away. After doing this, each time our end user authenticates, they receive an "Authentication Complete" Page, with a cryptic message about opening Global Protect ...

Source NAT Dynamic Pool mapping for inbound traffic

I have configured Dynamic NAT on PA- 3260 where source address is a VLAN with a certain IP range mapped to a NAT pool (Many-to-Many NAT Policy according to PA documentation). NAT policy is working fine according to the session logs. I can see the packet IP translation taking place for the outbound traffic. The concept I wish to understand here i...

Ajay358 by L2 Linker
  • 1122 Views
  • 1 replies
  • 0 Likes

Resolved! VPN certificate is not within its validity period - but dates match

Hello, I let the self-signed root and server certificate expire on my GP portal/GW so I regenerated both the root and server certificate (again, self-signed). I am still getting the error even though the computer time falls between the start and end date for the cert. Screenshots: Error message and certificate details with computer clock. ...

HELP! Need replacment ion 1200 power supply!!

Please Help, we have field technicians that lose the power supply to ION 1200 FW shipped back to our main office. We have close to 600 units deployed to the field. We need a stock of replacement power supplies! DOES ANYONE KNOW WHAT IS A SUITABLE REPLACEMENT AND MORE IMPORTANTLY WHERE TO BUY THEM. Thank You

T.Colvin by L1 Bithead
  • 1242 Views
  • 1 replies
  • 0 Likes

Having issues with performing a factory reset on Palo Alto 3060

Hello Everyone, I went and followed a guide on a pair of Palo Alto 3060s I bought for my lab from eBay. The first unit I was able to login with the default user name and password and verify it was working no problem. The 2nd unit still had a config on it and I went and followed the guide to type maint to enter maintenance mode and do a factory r...

Resolved! How to download PanOS VM image

I am an individual(not business). I want to download Palo Alto VM image for lab test, may I know is this possible? If so, how could I do it? I have read some Internet post, it says I shall pay and get a "lab license"? If so, how much? In addition, suppose I take the "PCNSE" certificate, will I able to access VM image? or it has its own separat...

gxx11661 by L0 Member
  • 2437 Views
  • 2 replies
  • 0 Likes
  • 24337 Posts
  • 124 Subscriptions
Labels