General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4231 Views
  • 0 replies
  • 0 Likes

How do you setup the equivalent of Cisco DHCPD on an Trusted Layer 3 interface

How do you setup the equivalent of Cisco DHCPD on an Trusted Layer 3 interface of a Palo Alto ApplianceWe have remote Cisco VPN sites we are looking at converting to Palo Alto VPN SitesI need to be able to assign IP addresses to workstations at Remote sites even if there is no connection to the Far end of the Site to Site connection.

dnagin by L1 Bithead
  • 2137 Views
  • 1 replies
  • 0 Likes

Tunnel times

I have a tunnel that is up 8 hours and down 16 hours almost consistently any one have any ideas what would cause that?

infotech by L4 Transporter
  • 10645 Views
  • 22 replies
  • 0 Likes

SSL Decryption

Want to enable this feature.. is there a guide I can follow to start configuring and testing?

rrau by L3 Networker
  • 2537 Views
  • 2 replies
  • 0 Likes

logdb export very slow then fails

Hi,I have a PA-500 which is running PAN-OS 5.0.9 and a Panorama server running PAN-OS 5.1. The Panorama is new and I would like to get all the historic traffic logs from the 500 to the Panorama. I have used scp export logdb user@server:logdb to export the logdb off the 500. To begin with the ssh sessions were timing out before the file had finis...

Gareth by L1 Bithead
  • 5433 Views
  • 8 replies
  • 0 Likes

Active/Passive HA Sync Issues

I'm in the process of testing out two PAN-M-100's in the lab and more specifically testing the HA functionality at this point.The issue that I am running into:I have changed the Primary to Passive and the Secondary to Active, made a change to the Active/Secondary and then reverted the M-100's back to Active/Primary - Passive/Secondary. After doi...

DaveCorwin by Not applicable
  • 14560 Views
  • 24 replies
  • 0 Likes

Resolved! Active/Pasive HA with LAG to Virtual Chassis = Dropped Packets?

Good afternoon,I tried to deploy a Active/Passive cluster yesterday with only partial success!Things didn't work as expected. Sessions were forming but servers would work intermittently. At times it would change so that what was working, stopped, and what wasn't, started. Some services worked fine for some people throughout. And for others nothi...

vwire unequal packet/bytes count

Hello!So, we have a very simple lab topology with virtual-wire and a single "allow all" policy.I think it is important to note that on the egress interface is a single host that should not be generating any traffic (or minimum traffic). The ingress port is connected to a span port on a switch. I am aware that it is a strange setup , but that's h...

Alternatives to Panorama for log collecting?

Hi.After a recent failure HD on my normally active firewall, it appears I'm going to lose close on 12 months of logs because Palo Alto has no defined process to get the logs off a failed hard drive (where the log partition is still accessible) onto the replaced drive.Yes, I have tried scp log export/import - I've swapped the old HD in and gotten...

darren_g by L4 Transporter
  • 6740 Views
  • 5 replies
  • 0 Likes

export config through cli

Hey all,Is there a way to export the (running) config through cli?Output should be a config file we can IMPORT back into a new device.- NOT using SCP (we have restrictions on this)- NOT using the API (php/rest/browse.php/export::configuration) (we only have ssh access) 1) "show config running" or under configuration-mode "show" -> this will o...

mr.linus by L4 Transporter
  • 26497 Views
  • 9 replies
  • 0 Likes

Allowing access (read only) to docs.google.com/viewer without allowing access to Online Personal Storage categorized sites

We have a situation where a site categorized as "computers and internet" (allowed for all users in our environment) references a pdf located on Google Docs (which is categorized as online personal storage). An example is docs.google.com/viewer?url=http://www.netapp.com/us/media/ds-3546-0114.pdf&embedded=true. This uses the app Google-Docs...

Art by L3 Networker
  • 4124 Views
  • 1 replies
  • 0 Likes

PAN as a DNS Forwarder to resolve External DNS Names

I'm looking on how to configure DNS proxy on PAN and found below link that provide great information.https://live.paloaltonetworks.com/docs/DOC-3637https://live.paloaltonetworks.com/docs/DOC-3522https://live.paloaltonetworks.com/docs/DOC-4633However, it does not cover the design that I want for DNS resolution and protect our internal DNS servers...

Resolved! HA Group 1: Dataplane is down: packet descriptor leak detected on slot 1 dp0

Hi Guys,Just encountered a failure on 4000 in an HA setup.First error is tasks: DP packet descriptor leak detected on slot 1 dp0HA Group 1: Dataplane is down: packet descriptor leak detected on slot 1 dp0HA Group 1: Moved from Active to state Non-Functional.Running recently upgraded to 5.0.12.Has anyone seen something this or something similar?...

x by L1 Bithead
  • 11568 Views
  • 3 replies
  • 0 Likes

Resolved! What happens when the ARP table is full?

Hello Guys,What happens when the ARP table is full? Does the firewall clear old entries?Just trying to figure out if what's causing an issue with our wireless is due to the ARP table being full. Thanks, Chris

x by L1 Bithead
  • 7994 Views
  • 4 replies
  • 0 Likes

Resolved! telnet

How do you telnet from the PA firewall on port 500 to and external IP address?

infotech by L4 Transporter
  • 2998 Views
  • 2 replies
  • 0 Likes
  • 24357 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels