General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4110 Views
  • 0 replies
  • 0 Likes

Resolved! NFR Bundle License

Hi, For NFR bundle license, I see the description as below: "PA-1420, NFR bundle subscription (Advanced Threat prevention, Advanced DNS, Advanced URL filtering, GlobalProtect, Advanced WildFire, SD-WAN, Standard support), 1 year (12 months) term." Just to confirm, is it the bundle license already include support as well? So in case custome...

Resolved! User ID group mapping, not pulling groups

I have a problem, I'm setting the user ID group mapping, I can pull users, but not groups, I see 0 groups, I restarted the service, no luck, I verified all server monitoring is connected, and traffic is going to DC'd, the PAN-OS is 10.1.5, I have a similar setup in a pair of firewalls that are on pan-os 9.1.13 with no issues, any advice that po...

Resolved! GlobalProtect - Cannot connect to local gpd service

Hi there! I have a little problem with GlobalProtect and I don't know how to solve it..I use Ubuntu 18.04Each command to globalprotect (for example globalprotect help OR globalprotect connect) returns the answer:Cannot connect to local gpd service.I tried to restart gpd service (sudo systemctl restart gpd), it didn't helpCommand systemctl stat...

ogoili by L0 Member
  • 67615 Views
  • 4 replies
  • 0 Likes

Email Notifications

hi,I would like to forward an email notification for specific alerts, ONLY to the person to whom the incident was assigned to.I don't see any subtype option to the Distribution List. Has anyone found a solution to achieve this ? (slack messaging is not an option) thank you

Expedition not importing NAT or security policies from PA-3020s running PAN-OS 9.1

I'm working on a project to upgrade 2 x PA-3020s each with their own configuration into an HA pair of PA-1420s and am having trouble with Expedition. I've tried importing the devices using the API key and also by exporting the running-config.xml file as a superuser and manually importing it into Expedition. Both are giving the same results. My "...

Retrieve "User Group" using RADIUS attributes

Hello Team, I have configured a RADIUS connection with FortiAuthenticator to implement multi-factor authentication (MFA). Within FortiAuthenticator, I created two user groups: an ADMIN group and a USER group. My objective is to set security policies on our Palo Alto firewall using these Group IDs. Despite configuring the RADIUS attribute (user...

Resolved! Local IKE interface and Tunnel interface in different virtual routers

Does Palo Alto allow having the Local IKE interface in "default" virtual router and the Tunnel interface in different virtual router when setting up site-to-site ipsec tunnels ? The use case of this to achieve multitenancy and overcome situations when different customers ( with overlapping lan subnets) connecting to a Hosted Enviromnet .

viks_a by L0 Member
  • 3636 Views
  • 2 replies
  • 0 Likes

BGP session flapping with error code 3 subcode 11

Hi All, I have an issue with setting up a BGP Establish connection. On my side is a PA firewall connected to the a ISP with BGP session. The first time, the ISP side sent only the default route to PA, and there was no problem in the BGP session. And now we require the full routing table that involves 4000+ routes sent to us. And I do a Max-pre...

HenryITP_0-1716779129951.png
HenryITP_1-1716779216937.png
HenryITP_2-1716779245756.png

Error trying to assing more than 90% to Detailed Firewall Logs at Collector Group in Panorama

Hi all, We are using a Panorama VM with a local managed collector. When I try to customize how to use the assigned space, Collector Group -> General -> Log Storage and I introduce more than 90% for detailed firewall logs, red square indicates that value introduced is incorrect. Our Panorama VM version is 10.1.12 and there are free space ...

fjmjugr by L1 Bithead
  • 1203 Views
  • 2 replies
  • 0 Likes

Unable to reach management service and console

Hi, greeting all my palo alto appliance(PA-850) used virtual-wire mode already, a few days before, paloalto can passaging traffic by virtual-wire pair, but the management service unreachable. even i tried to PING / HTTPS / SSH / SNMP / Console etc. and also i tried find the ARP info by network device, the device no any ARP record from Paloalto m...

WSTW_SE by L1 Bithead
  • 6836 Views
  • 6 replies
  • 0 Likes

COMMIT FAILED

Hi everyone, When I commit on my device, I get the following error "virus_update_block" Has anyone had this error before or can anyone help me resolve it? Thanks.

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels