General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! PAN OS 10, Two devices on different subnets in the same zone

We are running a Palo 5220. If we setup two different virtual interfaces with two different IP subnets in the same zone. Will I need to setup security policies to allow the two different subnets in a single zone to communicate. or will the Palo route traffic between subnets in the same zone with out any additional security policies?

MantaIT by L0 Member
  • 2909 Views
  • 3 replies
  • 0 Likes

Add OSPF Route Tags

Hi, I need to amend my routemap redistribution filter to set a tag to the routes in my referenced prefix list. My question is, when doing this on a live firewall, will this require OSPF to re-converge? Thanks

AndyFox by L0 Member
  • 1919 Views
  • 1 replies
  • 0 Likes

Defining patch management in HIP objects.

Hi All,We are configuring global protect with HIP enabled.Our requirement is, If the patch defined in the HIP object is missing in client machine then access should be denied. Below screen shows the patches (windows updates) for windows 7 machine.From above snap i want to use the highlighted update as match in HIP object (If this update is missi...

Gururaj by L4 Transporter
  • 12029 Views
  • 11 replies
  • 0 Likes

Out of memory: Kill process xxxx (mgmtsrvr) score xx or sacrifice child

This is a recurring issue, a reboot helps for time being. When attempting to update to the latest antivirus version, we see that the commit fails. System resources look normal. And looking at the techsupport file in /var/log/messages, we see that during various attempts: mgmtsrvr, devsrvr, logrcvr were the killed processes due to out of memory...

Screenshot_286.png

Palo alto PA3060 high memory usage over 60%

Hi everyone, In our performance report, it is find some Palo Alto PA3060 firewall memory usage keep high than > 60%, which trigger resource alarm refer our monitoring standard. I tried action like reboot device but memory level remain more or less the same. May advise way that can lower memory usage, say, <60% I also try to following the...

WilsonWu by L1 Bithead
  • 4580 Views
  • 3 replies
  • 0 Likes

Global Protect - SAML Authentication Complete Page

We're testing upgrading to version 2.5.x and have run into a few changes with the new features. We enabled "Use Default Browser for SAML Authentication", because you know ie, is going away. After doing this, each time our end user authenticates, they receive an "Authentication Complete" Page, with a cryptic message about opening Global Protect ...

Source NAT Dynamic Pool mapping for inbound traffic

I have configured Dynamic NAT on PA- 3260 where source address is a VLAN with a certain IP range mapped to a NAT pool (Many-to-Many NAT Policy according to PA documentation). NAT policy is working fine according to the session logs. I can see the packet IP translation taking place for the outbound traffic. The concept I wish to understand here i...

Ajay358 by L2 Linker
  • 1192 Views
  • 1 replies
  • 0 Likes

Resolved! VPN certificate is not within its validity period - but dates match

Hello, I let the self-signed root and server certificate expire on my GP portal/GW so I regenerated both the root and server certificate (again, self-signed). I am still getting the error even though the computer time falls between the start and end date for the cert. Screenshots: Error message and certificate details with computer clock. ...

HELP! Need replacment ion 1200 power supply!!

Please Help, we have field technicians that lose the power supply to ION 1200 FW shipped back to our main office. We have close to 600 units deployed to the field. We need a stock of replacement power supplies! DOES ANYONE KNOW WHAT IS A SUITABLE REPLACEMENT AND MORE IMPORTANTLY WHERE TO BUY THEM. Thank You

T.Colvin by L1 Bithead
  • 1331 Views
  • 1 replies
  • 0 Likes

Having issues with performing a factory reset on Palo Alto 3060

Hello Everyone, I went and followed a guide on a pair of Palo Alto 3060s I bought for my lab from eBay. The first unit I was able to login with the default user name and password and verify it was working no problem. The 2nd unit still had a config on it and I went and followed the guide to type maint to enter maintenance mode and do a factory r...

Resolved! How to download PanOS VM image

I am an individual(not business). I want to download Palo Alto VM image for lab test, may I know is this possible? If so, how could I do it? I have read some Internet post, it says I shall pay and get a "lab license"? If so, how much? In addition, suppose I take the "PCNSE" certificate, will I able to access VM image? or it has its own separat...

gxx11661 by L0 Member
  • 2639 Views
  • 2 replies
  • 0 Likes

Panorama Virtual disk addition for logging - legacy mode.

Hi Team, We have panorama in legacy mode. We deployed it using 8.1 ova file by default it too 80GB storage and allocated 11GB for logging. Now we want to add additional virtual disk in esxi server. When we add additional disk it by following below KB. https://docs.paloaltonetworks.com/panorama/8-0/panorama-admin/set-up-panorama/set-up-the-panora...

Resolved! Unable to download new version

PA-440 running 10.1.13 update to 10.2.0, but when I download 10.2.0-h2 ...... admin@PA-440> request system software download version 10.2.0-h2 Download job enqueued with jobid 99 admin@PA-440> show jobs id 9 <response status="success"><result>Enqueued Dequeued ID Type Status Result Completed -----------------------------------...

  • 24393 Posts
  • 123 Subscriptions
Top Solution Authors
Labels