General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4121 Views
  • 0 replies
  • 0 Likes

Resolved! Active/Pasive HA with LAG to Virtual Chassis = Dropped Packets?

Good afternoon,I tried to deploy a Active/Passive cluster yesterday with only partial success!Things didn't work as expected. Sessions were forming but servers would work intermittently. At times it would change so that what was working, stopped, and what wasn't, started. Some services worked fine for some people throughout. And for others nothi...

vwire unequal packet/bytes count

Hello!So, we have a very simple lab topology with virtual-wire and a single "allow all" policy.I think it is important to note that on the egress interface is a single host that should not be generating any traffic (or minimum traffic). The ingress port is connected to a span port on a switch. I am aware that it is a strange setup , but that's h...

Alternatives to Panorama for log collecting?

Hi.After a recent failure HD on my normally active firewall, it appears I'm going to lose close on 12 months of logs because Palo Alto has no defined process to get the logs off a failed hard drive (where the log partition is still accessible) onto the replaced drive.Yes, I have tried scp log export/import - I've swapped the old HD in and gotten...

darren_g by L4 Transporter
  • 6657 Views
  • 5 replies
  • 0 Likes

export config through cli

Hey all,Is there a way to export the (running) config through cli?Output should be a config file we can IMPORT back into a new device.- NOT using SCP (we have restrictions on this)- NOT using the API (php/rest/browse.php/export::configuration) (we only have ssh access) 1) "show config running" or under configuration-mode "show" -> this will o...

mr.linus by L4 Transporter
  • 26147 Views
  • 9 replies
  • 0 Likes

Allowing access (read only) to docs.google.com/viewer without allowing access to Online Personal Storage categorized sites

We have a situation where a site categorized as "computers and internet" (allowed for all users in our environment) references a pdf located on Google Docs (which is categorized as online personal storage). An example is docs.google.com/viewer?url=http://www.netapp.com/us/media/ds-3546-0114.pdf&embedded=true. This uses the app Google-Docs...

Art by L3 Networker
  • 4094 Views
  • 1 replies
  • 0 Likes

PAN as a DNS Forwarder to resolve External DNS Names

I'm looking on how to configure DNS proxy on PAN and found below link that provide great information.https://live.paloaltonetworks.com/docs/DOC-3637https://live.paloaltonetworks.com/docs/DOC-3522https://live.paloaltonetworks.com/docs/DOC-4633However, it does not cover the design that I want for DNS resolution and protect our internal DNS servers...

Resolved! HA Group 1: Dataplane is down: packet descriptor leak detected on slot 1 dp0

Hi Guys,Just encountered a failure on 4000 in an HA setup.First error is tasks: DP packet descriptor leak detected on slot 1 dp0HA Group 1: Dataplane is down: packet descriptor leak detected on slot 1 dp0HA Group 1: Moved from Active to state Non-Functional.Running recently upgraded to 5.0.12.Has anyone seen something this or something similar?...

x by L1 Bithead
  • 11495 Views
  • 3 replies
  • 0 Likes

Resolved! What happens when the ARP table is full?

Hello Guys,What happens when the ARP table is full? Does the firewall clear old entries?Just trying to figure out if what's causing an issue with our wireless is due to the ARP table being full. Thanks, Chris

x by L1 Bithead
  • 7892 Views
  • 4 replies
  • 0 Likes

Resolved! telnet

How do you telnet from the PA firewall on port 500 to and external IP address?

infotech by L4 Transporter
  • 2950 Views
  • 2 replies
  • 0 Likes

VMotion on ESXi

Hi PA-Admins,we installed a VM-100 (version 6.0.2) in our ESXi environment. By accident we forgot to disable vmotion for the VM and the VM moves from one host to others...I thought vmotion is not supported but our VM-100 is still running and the licenses are valid.from the Virtualization_Admin_Guide_6.0: System Requirements and Limitations This ...

Hithead by L4 Transporter
  • 7717 Views
  • 6 replies
  • 0 Likes

Assistance: my palo is not accessible.

Assistance: my palo is not accessible. I n is happening more access to my palo, after having placed in demo for a client, only the power LED lights. I try dy by console access and management, but it did nothing.----------------------------------------------------------------------------------------------------------------------------je n est arr...

camagate by L1 Bithead
  • 7780 Views
  • 10 replies
  • 0 Likes

Resolved! GlobalProtect authentication problem

Hello,The group I use to authenticate GP connections doesn't work properly.I followed the advice on this thread: https://live.paloaltonetworks.com/thread/8661It was necessary to place the NETBIOS domain name in the LDAP server profile. Output from the CLI now clearly displays the logon format with domain\user, unlike before, for GP clients.The...

TheBest by L1 Bithead
  • 4211 Views
  • 4 replies
  • 0 Likes

TLS Syslog cert import

Hi all,Certificates, can anybody help?I have a cert syslog-ng.cert that ArcSight logger auto-generated and I want to import this on to the firewall as a "Certificate for Secure SYSLOG"It imports OK as Base64 encoded PEM format, with the option to import a private key disabled (if I choose this I need to give a Key File or a Passphrase...which I ...

unable to redirect web traffic towards Websense

hi I am planning to deploy Paloalto firewall in my network, but my biggest challenge is how to redirect web traffic towards Websense which I am using as a web content filtering engine.can any one one help me regarding this to how I can do so.Regards,Om@Spicejet

om by Not applicable
  • 3065 Views
  • 1 replies
  • 0 Likes

Resolved! How to configure PaloAlto to Fail-over to another ISP on a remote location

I'm new in using PaloAlto Firewall. We have to sites that have it's own dedicated ISP connections and I've been task to configure the PAN firewall to route the Internet connections to another ISP if the main internet connections encounter a connectivity problem.HQ1 RT1-------PAN FW--------Internet RTR------------------ISP1||| -> Connections ...

  • 24336 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels