General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.


Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:


Rules and Best Practices


  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion

JayGolf by Community Team Member
  • 0 replies

WildFire - What sort of hit rate do you see?

I enabled WildFire a month or so back.

I know it works as I download files regularly from the PAN "random wildfire test file" site and sure enough a little while later an alert pings in and it shows in the dashboard.

In production it seems that everyth


Admins linked with AD


recently am creating an admin and linking it with my ad, whenever i click ok i got the attached error,i checked my ldap settings group-mapping auth_profile all correct with no spaces or characters that which could be be a reason, username and passw


Resolved! Global protect error message


I've got a user trying to connect to my PA through a Global protect VPN, and the firewall is giving me the following error message

GlobalProtect gateway client configuration failed. User name: <xxxx>, error: Assign private IP address failed.

I know


darren_g by L4 Transporter
  • 12 replies

Resolved! Cant Syslog off of Panorama ?

My PA-4020's are busy to say the least. They do send traffic, threat and URL Filtering logs to Panorama. I want to be able to create a Log Forwarding profile on Panorama to send these logs off to a Syslog Server. Under Server Profiles Syslog, I creat


jhickey by L3 Networker
  • 5 replies

Resolved! LDAP profile broken after upgrading to 5.0.10


I upgraded my firewalls to PANOS 5.0.10 yesterday, and after the upgrade the LDAP profile fails with "invalid credentials". I have tried resetting the password for the account used, but the error still persists.

Have anyone else encountered this is


as-mg by L3 Networker
  • 13 replies

Palo Alto Virtual Firewall Platform

Is anyone using one of these but as an internet facing firewall vs. firewalling the VM's on the host the firewall is running on?

From the pricing and specs and the amount of HA that vSphere can provide, I'm trying to understand what the "catch" is vs.


Resolved! Captive Portal SSL Certificate Error

We're running 5.0.10 with Captive Portal.

We have an SSL certificate installed for * and have several internal DNS entries that point to various physical interfaces on the Palo Alto.

We recently revoked and rekeyed our w


attacking site and PAN


Few days ago I discovered site with some information about VMware Update Manager. I had a problem with it and I was searching for solution.

This site is

I have PA with all licences but PAN so


_slv_ by L4 Transporter
  • 13 replies

Opt-out page for HTTP ?

We would like to have a web response page that is presented to the user when the user launches their browser for the first time that asks them if they abide by the AUP rules. Basically same concept as the https opt-out page. Is this possible? If so,


Resolved! Can't clear session from CLI

Running PANOS 6.0.1. I can't seem to clear a session from the CLI. Just tested on a PA-500 running 6.0.0-b42 and I have the same problem.

Anyone knows if this is a bug?

admin@PA-vm> show session all filter destination 212.x.x.x



bdeschut by L4 Transporter
  • 8 replies

Disable an IPSec Tunnel

I want to disable an IPSec VPN. I have currently blocked traffic both directions to the tunnel by using a Security Policies, but there should be a way to disable the tunnel in the IPSec configuration (or alternatively, disable the tunnel interface).


blandis by Not applicable
  • 5 replies

Decryption: sec_error_reused_issuer_and_serial

Hey all,

I am having problems with decryption. The PA decrypts https websites, but when I surf to that website a few hours later, I receive the following error in firefox:

I haven't tried yet in IE or Chrome. I have this problem for various websites, n


bdeschut by L4 Transporter
  • 9 replies
  • 23839 Posts
  • 112 Subscriptions
Top Liked Authors