General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! New user creation error

Hey everyone, wanted to ask for some help, I created a new user with wrong email for SSO, is there a way to eliminate this user it is not showing under manage users so I was wondering where I can edit that. Thanks

arces01 by L0 Member
  • 1144 Views
  • 3 replies
  • 0 Likes

Issue with routing possibly?

Needing a little help. I have a PA 5220 within a secure enclave (so no connection to the internet). I can ping a gateway in another enclave without any issue but when I ping the network beyond that gateway I get no reply. My GW external interface and

...

NFS sessions undecided after fail-over

Situation:

NFS Client src:828 dst: 2049 --> PAN 7050 HA Cluster --> NFS Server (NFS Session is up and connected without issue)

 

Palo alto cluster fail-over occurs (upgrade/issue - doesn't matter)

 

NFS Client src:828 dst:2049 -->PAN (Session is marked as

...

Resolved! Clarification on http2 traffic and decryption

Hi all,

 

I was hoping to get some clarification on http2 and firewall interaction. I understand that generally http2 works without issue as long as it's being decrypted. I also understand disabling inspection/decryption (Strip TLS ALPN) on http2 tra

...

KGDrake by L0 Member
  • 1264 Views
  • 1 replies
  • 0 Likes

Resolved! Adding IP's on Policies on panorama

Hi All,

 

Needing your suggestions i'm adding a list of ip addresses on policy that I created on branch and when I push it I got an error on NAT ISP 1, NAT is not a problem I knw because everything is working correctly. I notice that this has been ad

...

weezy by L2 Linker
  • 875 Views
  • 2 replies
  • 0 Likes

Layer 3 sub interfaces on Hyper-V

Hi all,


I am trying to get Palo Alto VM series (10.2.3) to work with layer 3 sub interfaces on Hyper-V (2022).
I configured interface/subinterface from the documentation (https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRkCA

...

pa_subinterface.png

Resolved! Implementing Applications Over Services

We recently completed a migration and I am in clean up mode.  I would like to utilize applications but we do some no decryptions exceptions rules that bypass decryption.  I am concerned that without decrypting, the rule will break and traffic won't f

...

Access PA-440 MGMT Interface via Cisco Switch

Hi Guys,

I am working with below scenario and would like some help.

 

As shown in diagram:

A cisco switch IE3400 is connected with PA-440 with trunk connection and also one of the interface of switch is connected to MGMT port of PA-440.

There are mu

...

Janmejay_Dave_1-1687412475430.png

Resolved! Packet drop in the Firewall

Recently, we did a Migration activity, From the Juniper SRX to Palo Alto.

 

After successful Migration, we can notice that one drop over the PA firewall.

We did troubleshooting from our end and in the global counter can see below error with drops

 

flow_f

...

Traffic redirects to captive portal

We currently have a policy in place that allows all HTTP and HTTPS traffic from a test server (Trust) with a static IP address to reach untrusted networks. However, when accessing the server from a browser, it automatically redirects to a captive por

...

Bijesh by L1 Bithead
  • 932 Views
  • 1 replies
  • 0 Likes

URL Profile Known Bad Categories

What are the known bad url categories that palo checks is blocked? We currently block all the categories in this document but AI-Ops still flags it. Is there a way to see specifically what its failing? 

 

Malicious URL Categories (paloaltonetworks.co

...

Claw4609_0-1687291149037.png
Claw4609 by L5 Sessionator
  • 1162 Views
  • 3 replies
  • 0 Likes
  • 24130 Posts
  • 102 Subscriptions
This widget could not be displayed.
Top Solution Authors
Top Liked Authors
Labels