General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Replace SFP Process

Hi we have a PA-850. Port 5 has a RJ45 SFP adapter, internet connection. We are upgrading our Internet connection (bandwidth increase only, no IP changes) and the new handoff from the ISP is single mode fiber, so I purchased a PAN-SFP-PLUS-LR to support the connection. I plan on simply removing the old SFP adapter and inserting the new one. My q...

MikeGill by L1 Bithead
  • 3303 Views
  • 2 replies
  • 0 Likes

TLS 1.3 has General Protocol Error

Hi all, Fairly new to PAN OS and have just enabled decryption on my 10.2.3-h4 VM-300 firewall. In my decryption logs, all entries for TLS 1.3 are having a 'General Protocol Error'. When running a v11.0.1 firewall (that I had to downgrade due to dataplane freezing issues - another story) I didn't get these errors. Anything I'm doing wrong or am...

Certificate Expiry

Hi All, I am trying to import the Azure SAML certificate to use it in the Identity Provider Certificate as it is expiring this Thursday. But i am getting the attached error. Does it mean do i need to delete the existing one and then import it? I have the Pem format and Base64 format but error is same when i import. Certificate extention is .cer....

Resolved! RTP traffic not matching App-ID Rule

I have a strange issue where I have a configured rule to allow the "rtp" and "rtcp" App-IDs with application-default service from any-to-any. Below that rule I have a generic permit-any rule with application service any. Screenshots below. The behavior I am running into is that positively identified rtp and rtcp sessions are not matching my high...

IanGraham_0-1704745546729.png
IanGraham_3-1704745826139.png
IanGraham_2-1704745786416.png

Global Protect "Single Sign on" with Windows Hello on Windows 10

Hi everyone,I have a situation as described in the title of this post. As you probably know Global Protect installs his own Credential Provider in Windows which has to be chosen by the user. It is also possible to force the Global Protect Credential Provider, but the point is, it has to be used in order to enable single sign on for the user.This...

Remo by L7 Applicator
  • 20851 Views
  • 5 replies
  • 5 Likes

VPN tunnel is getting dropped

we are seeing tunnel drop with below error message.IKE phase-1 SA is deleted SA: 1.1.1.1[500]-2.2.2.2[500] cookie:191098e4ef6db35d:eba9ee89ff200b07

transition from trial to purchased license

Hi All, We are in a scenario where we are running firewalls on trial licenses. We have purchased the licenses. Can you help me with following queries :1. When firewall transition from trial -> purchased license, will firewall drop the network traffic ? 2. Any recommendation on scheduling downtime for it ?

BRI-IT by L0 Member
  • 942 Views
  • 1 replies
  • 0 Likes

Resolved! 2 Tunnel With 2 IP Public. Secondary one is filtered ?

I have two IPSec tunnels with 2 ISPs:ISP 1 is PrimaryISP 2 is Secondarywith a Failover scheme. But when I set the metric for ISP 1 to 10 and ISP 2 to 200, it seems that the public IP of the second ISP cannot ping the second tunnel's peer gateway, with a message saying the packet is filtered. How can I configure it to keep both tunnels active, ...

ariiero by L1 Bithead
  • 1915 Views
  • 2 replies
  • 0 Likes

URL logs missing for Traffic through alert only URL category / profile.

Hi All, Software Version 11.1.2-h3 We have a strange situation: Some URL filtering log entries for valid visits to web sites are missing. The traffic goes through a security rule which has a URL filtering profile with only alert and block categories. We have both Pan-db and Advanced URL filtering licenses. We can see the traffic in ...

Resolved! VM PA Firewall on esxi

Hi Team, I am trying to install a vm pa firewall on esxi host. Downloaded the ova of 11.2.0 base image and installed. When I configure management interface it comes up. But none of the data plane interfaces are coming up. Reinstalled once again and still the same. I see many people reinstalled and it worked. From the esxi side security policy s...

Change of models managed by panorama

Cordial greetings Team I currently have a PA 220 managed from panorama and we want to upgrade it to a PA440. The idea is to keep the same configurations of the 220 device in the 440. The question is, how should this process of device change be done? We have added the new device to panorama and when adding the same template and DG that the 220 ha...

aalfaro by L2 Linker
  • 5859 Views
  • 9 replies
  • 0 Likes

Pre-established BGP connection to HA?

All,I'm looking to set up established BGP connections from the upstream routers (Cisco Nexus) to the HA unit in our A/P setup for faster failover times, and to not make it look weird when trying to determine if adjacencies are up to the primary unit from the router side. I know there's some things that can be established, LACP and the like, but ...

Resolved! DNS sinkhole , some questions

I'm a SOC analyst, and we receive firewall logs regarding DNS sinkhole alerts. I'm trying to understand them better. I have received multiple logs of this type, and I want to make sure I understand them correctly. In this log, the domain that was queried was "s.w.org," right? I received multiple logs, and "generic:sr7pv7n5x.com" was present in a...

Brand new PA-1040 interface 1 & 2 in red link state problem

Dear All, I got a brand new PA-1040, and i have choice standard mode rather than ZTP mode from the beginning and i found that interface 1 & 2 are in red link state, even i connect a network cable into these port and i still see there is no green light show in the PA portal just wonder is there is something to do with the ZTP...

piaakit by L1 Bithead
  • 1224 Views
  • 1 replies
  • 0 Likes
  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels