General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4136 Views
  • 0 replies
  • 0 Likes

Resolved! commit Issues

whene i try to do commit i reciver this message""""""""""""Management server failed to send phase 1 to client dhcpdManagement server failed to send phase 1 abort to client dhcpdManagement server failed to send phase 1 abort to client sslvpnManagement server failed to send phase 1 abort to client satdManagement server failed to send phase 1 abort...

Are there any sign indicating lost internet connection in GP 1.2.9

I need to know if there is any way to show the GP status as disconnected or reconnecting status when we have intermittent internet connections. Because, I have some issues with my customers when the internet connection is intermittent. The GP client appears as connected and the user tries to access the network resources but it is not possible be...

AJuarez by L0 Member
  • 2354 Views
  • 1 replies
  • 0 Likes

Proxy ID

How can you tell what proxy ID's need to be configured on a PA that has VPN tunnels to a Cisco ASA 5505?

infotech by L4 Transporter
  • 23114 Views
  • 63 replies
  • 0 Likes

How to move licensing and SN of Panorama from one VMWare environment to another

Hi GuysI need some help/thoughts on how to do the following:I have 5 Panorama servers that are virtual in Montreal.I need to move them ffrom Montreal to a different VMWare environment in ChicagoI need to know if there are any problems with doing such a thing.Is there a document that can be found to do this.I am concerned about a different CPUID/...

scantwell by L4 Transporter
  • 3738 Views
  • 3 replies
  • 0 Likes

URL filtering profile

For particular traffic, session created and security rules hitsBut URL filtering profile blocks the traffic....when allow the unknown in URL filtering profile -traffics are allowed.In Logs: Packet categorized as Unknown udp...This traffic is Tally ERP 9.0 from client-server.Can i create custom app-id? with pattern or not?..so that the particular...

Javith by L3 Networker
  • 2381 Views
  • 2 replies
  • 0 Likes

Resolved! Configure NAT Policy for Exchange Server

We are brand new to Palo Alto and are configuring our first device, a PA-3020. We've been trying to configure a NAT policy that will direct inbound email to our Exchange server. Outbound email seems to work fine. Inbound email doesn't seem to be even hitting the firewall since there are no log entries. We have a Sonicwall firewall in place now a...

OliveIT by Not applicable
  • 6842 Views
  • 5 replies
  • 0 Likes

Panorama Threat Log doesn't display Custom Vulnerability Name

I have a Custom Vulnerability (41000) with the name "NXDOMAIN Response". The name displays correctly in the Name Column when viewing the Local firewall Threat Log. However, when looking at the consolidated Panorama Threat Log, the name appears as 41000. Does anyone know if this is a bug in Panorama or is it supposed to do this?Thanks,Jeff

jwolach by L4 Transporter
  • 2165 Views
  • 1 replies
  • 0 Likes

Route outgoing gmail application received on specific internal interface out different Public IP

I'm trying to figure out the best and easiest way to route all gmail application (gmail-base and gmail-enterprise primarily) that enters on an internal port from one network and send it out using a separate pubic IP we have. Currently all internet based outbound traffic goes out a using a single IP and we are having an issue with that IP getting...

Resolved! SSL Decryption Firefox issue

I am testing SSL Decryption and have setup the certs. IE and Chrome work like expected. But firefox is having an issue with untrusted site error (Error code: sec_error_untrusted_issuer)Has anyone worked around this problem before?

markk96 by L3 Networker
  • 10325 Views
  • 11 replies
  • 0 Likes

Order to reboot devices in HA pair (passive)

We need to reboot our firewall due to some issues related to the traffic logging not working. We have already attempted debug software restart log-receiver, syncing the devices etc and none of them have resolved the issue. We are pretty new to the device and have never had to reboot them. We have two PA-500's in an HA pair config. The backup is...

bino150 by Not applicable
  • 9227 Views
  • 7 replies
  • 0 Likes

Resolved! Howto do a bulk URL category check in PANDB?

As we're migrating from proxy to direct internet access, we'd like to cross-check old URL black and white lists against PANDB. I did find the URL to check one site (with captcha) but that will not be very efficient as we have hundreds of entries.Is there a way to do a bulk check?Is there a CLI or API command to do a category lookup?Thanks

How do you setup the equivalent of Cisco DHCPD on an Trusted Layer 3 interface

How do you setup the equivalent of Cisco DHCPD on an Trusted Layer 3 interface of a Palo Alto ApplianceWe have remote Cisco VPN sites we are looking at converting to Palo Alto VPN SitesI need to be able to assign IP addresses to workstations at Remote sites even if there is no connection to the Far end of the Site to Site connection.

dnagin by L1 Bithead
  • 2114 Views
  • 1 replies
  • 0 Likes

Tunnel times

I have a tunnel that is up 8 hours and down 16 hours almost consistently any one have any ideas what would cause that?

infotech by L4 Transporter
  • 10389 Views
  • 22 replies
  • 0 Likes
  • 24340 Posts
  • 124 Subscriptions
Labels