General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.


Ensuring a Safe and Secure Community: How You Can Help


Dear LIVEcommunity Members,


Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun


jforsythe by Community Team Member
  • 0 replies

Resolved! Help setting up internet connection

Hi there

We're in the process of cutting over to a new internet connection and I'm trying to get our PA 2050 configured to handle to new IP range but I'm a bit stuck. We've been assigned the subnet with being the default


Log Type Unknown

How do I figure out what the log type I have is when its showing me "unknown" for the current type?

*edit* Sorry they are assumed for the IDS/IPS

Global Protect Welcome Page with ActiveX

Hi Guys,

is it possible to customize the welcome page of Global Protect with ActiveX scripts? I need this to run Active Directory login scripts automtically after a connect with Global Protect.



DirkSch by L0 Member
  • 3 replies

Global Protect too many outstanding keep alive

Hello guy's

did Someone see this kind off message in global protect agent log on windows device.

message :too many outstanding keep alive

and just after this message a logout is innitiated

the VPN session is mount conntected and after less than 2 min a


Gregoux by L4 Transporter
  • 1 replies

Resolved! PAN as an explicit proxy?

Hi all,

I have a simple question, is it possible to make my PA-3020 work like an explicit proxy ?

I configured URL Filtering and I would like to adress web requests to the PA-3020 just like if it was a real explicit proxy...

Many thanks in advance.


Alarm on device


     We've did a little bit of testing on Palo Alto device and kind of want to know something about Alarm that we still can't produce the issues such as

               - At what temperature or percent that device will generate an Alarm



Resolved! virtual-wire ARP issue


i have a topology of 2 cisco routers connected to e1/1 and e1/2 in a virtual-wire deployment. there is only 1 policy on the PA, permitting all traffic, and all VLANs are permitted through the v-wire.

the problem is that when i try to ping from R1 t


Resolved! empty user list


Device stopped to take user information from agent.Show user ip-user mapping all comes with 0 user.Passive device works shows all users.

Agent connection is fine for both device.Any idea ?

restarted user-id with debug command but did not sol


panos by L6 Presenter
  • 3 replies

Resolved! MS-RDP and t.120 -> application: not-applicable


I have a few rules that only permit ms-rdp and t.120. A new rule was implemented last week that permits ms-rdp and t.120, just different source addresses. The other rule can see the ms-rdp application but for the new rule, it shows up as applicati


Resolved! Bind multiple VPNs to a single tunnel interface?

greetings all,

I come from a ScreenOS background, and in their world, you can terminate multiple route-based VPNs onto a single logical tunnel interface.

We have 30-40 remote sites with VPN tunnels back to HQ, which will soon be a new PAN firewall.  In


  • 23679 Posts
  • 108 Subscriptions