General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4223 Views
  • 0 replies
  • 0 Likes

Hide Global Protect redirection

Hello team We have already hidden the global protect pages so that our users can only access through the client, however, we have detected that when we type the ULR or IP in a browser there is an automatic redirect that adds /global-protect/login.esp and we do not want this to be so, because we do not want that from the outside can be seen that ...

Alpalo by L4 Transporter
  • 1313 Views
  • 1 replies
  • 0 Likes

Resolved! Remove Device Certificate

We would like to remove the device certificate from a couple of our firewalls. We don't use or need the device certificates at this time and would prefer them not be installed. I tried to do a factory reset and the certificate automatically downloaded and installed itself.

jwill2 by L2 Linker
  • 7529 Views
  • 6 replies
  • 0 Likes

For assessment retake

i want to retake my palo alto cyber security final assessment because of some internet issue i dint took the assessment properly so kindly help me

MTU size clarification at Interface and Sub-Interface level

Hi All, If we set mtu value as 9192 in interface and 9072 as sub-interface, which one the sub interface choose. If it will choose 9072, would that mean 9072 size packet can be sent. Similarly, If we set mtu value as 9192 in interface and kept the sub interface blank, what mtu will be choosen.

Sujanya by L3 Networker
  • 8372 Views
  • 2 replies
  • 0 Likes

Does anyone have any experiences or "gotchas" they'd like to share when they've implemented Riverbed Steelhead appliances behind PA firewalls?

I see that there's a 'riverbed-rios' app listed in Applipedia, which gives me some hope.Specifically what I am concerned about is discussed here (with configuration examples for PIX/ASAs):http://www.dslreports.com/faq/16494The Riverbed appliances we have take advantage of TCP option 76 for autodiscovering other Steelhead appliances that are in-p...

Traffic logs doesnot have a corresponding URL log

I am trying to perform some forensics into a user activty but Palo Alto logs are not really helping me a lot. I mean, I see a traffic for some IPs but when I click the maginifying glass icon, I see the category in it but not the actual URl. I have checked the URL filtering profile and it is set to alert.has anyone observed this?

Resolved! Different Temperature Sensors

I need to know what is the difference between those three sensors please,S1 CPU Die temperature sensor S1 U9 temperature sensorS1 U66 temperature sensor After adding the temperature reading of PA device to PRTG the above indicators were shown and I need to know the indication of each one.

Waly by L1 Bithead
  • 2399 Views
  • 1 replies
  • 0 Likes

Resolved! Unable to Authenticate to GP using SMAL

On PA 8.1.19 we have configured GP portal and Gateway for SAML authentic in Azure.We have imported the SAML Metadata XML into SAML identity provider in PA.Authentication FailedPlease contact the administrator for further assistanceError code: -1When I go to GP. url. I get authentic on my phone and I approve it then I get this error on browser. P...

MP18 by Cyber Elite
  • 25469 Views
  • 14 replies
  • 0 Likes

Resolved! Cluster config question

Hi to all, I have a question regarding the cluster config tab (i have attached a picture). There we are adding the peers only, or we have to add also the same device I am a configuring. For example I have 3 devices, That table of devices should be three (3) or only the peers which are two(2) at every cluster member.

kvagenas by L1 Bithead
  • 2233 Views
  • 2 replies
  • 0 Likes

Resolved! Unable to Upgrade from 11.1.3 to 11.1.13

Hi, I am having a problem to upgrde, with the objective of upgrading my PA-460 standalone from 10.1.13 to 11.2.0. I performed the following: Download 10.2.0 install and reboot; then maintenance release then the last 10.29 -h? release and reboot. Download 11.0.0 install and reboot then maintenance release 11.0.x (last ) and reboot. ...

Resolved! PAN OS 10, Two devices on different subnets in the same zone

We are running a Palo 5220. If we setup two different virtual interfaces with two different IP subnets in the same zone. Will I need to setup security policies to allow the two different subnets in a single zone to communicate. or will the Palo route traffic between subnets in the same zone with out any additional security policies?

MantaIT by L0 Member
  • 2797 Views
  • 3 replies
  • 0 Likes

Add OSPF Route Tags

Hi, I need to amend my routemap redistribution filter to set a tag to the routes in my referenced prefix list. My question is, when doing this on a live firewall, will this require OSPF to re-converge? Thanks

AndyFox by L0 Member
  • 1822 Views
  • 1 replies
  • 0 Likes

Defining patch management in HIP objects.

Hi All,We are configuring global protect with HIP enabled.Our requirement is, If the patch defined in the HIP object is missing in client machine then access should be denied. Below screen shows the patches (windows updates) for windows 7 machine.From above snap i want to use the highlighted update as match in HIP object (If this update is missi...

Gururaj by L4 Transporter
  • 11636 Views
  • 11 replies
  • 0 Likes
  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels