General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Restore Panorama from backup

We have issues logging back to panorama and error message is authentication profile missing. I have opened a case but to me it looks most likely we have to rebuild or factory reset it. We do have the daily configuration backup .tgz file which contains xml files. What is the procedure to restore it.

raji_toor by L4 Transporter
  • 7123 Views
  • 2 replies
  • 0 Likes

Troubleshooting Panorama Push - line:51: syntax error [}]

When trying to commit to a ngfw from panorama I am getting this error. I have turned on debug for configd to try and find what specific setting has a problem. No luck getting more information. I have double checked every setting and variable for something not entered correctly with no luck. Is there a way to access that file and look at line 5...

I.Miller by L0 Member
  • 2318 Views
  • 2 replies
  • 0 Likes

Errors in S2S VPN configuration.

Hello, I am configuring a site to site VPN between a Palo Alto Firewall and un Firewall Fortinet, but despite several attempts we are not able to get it to go up either in phase 1 or in phase two in the logs of Palo Alto you can see: 2024-05-16 23:47:12.205 +0000 [INFO]: { 3: }: received IKE request x.x.x.x[500] to x.x.x.x[500], found IKE gate...

M.Ochoa by L0 Member
  • 2333 Views
  • 1 replies
  • 0 Likes

UnAuthorized Access -- CSP

Hello, I am not able to access the Customer Support Portal getting below error: UnAuthorized Access Your membership has expired or has not been approved, please contact Palo Alto Networks Support. I have contacted the NextWave <[email protected]> and they mentioned as below: I'm sorry but we are unable to assist with the ...

Resolved! Block Connections from Different Region

Hi All, We have a requirement to setup a Block rule for the users connecting to GlobalProtect from different countries. We need to allow users only from one particular region to connect to GlobalProtect. In Prisma we can use the Specific Tag and Specific Name on the rule to achieve this. But I don’t find any related document that suggests this...

Slow speed with GlobalProtect

Hi to all,We are trying to understand why the download speed is really slow vía GP.We stablish a VPN GP with IPsec without Split Tunneling. We acces to some public web to download a test file. Im downloading a 1G file.If we download without GP but through the Palo Alto we achieve 60MB/s, but vía GP we achieve maybe 6 or 10MB/s.Any idea about tha...

nanukanu by L2 Linker
  • 57293 Views
  • 16 replies
  • 0 Likes

Can you have an interface with an SFP in receive only mode?

I have a scenario where we have a data diode transmitting over fiber to an interface on our PA220R (sfp 100fx). The difficulty is that the PA considers the interface as 'down' because of the nature of the data diode, the diode only sends to the PA over this fiber but will not receive any data from the PA by design. Does anyone know a way to hard...

Extending VLAN through IPSEC + GRE

I am trying to extend the VLAN from main site to branch site using a combination of GRE and IPSEC. Below is a quick representation of the architecture, the objective is to enable remote communications between the main and the branch sites for all devices within VLAN-1. I am aware that PA does not natively provide L2 tunnels, and VXLAN ...

OELHANCHI_0-1714232289883.png

VM-50 discontinued?

Hi, We have a VM50 firewall in our business for 3yrs and have been told that the VM-50 is no longer available? As such, we need to get a VM-100 licence. Are there any other options? - since the cost is double? Thanks

cluster

Hello, Can you form a HA cluster with a PA-3020 and PA-3060? Or do models have to be identical?

Joeful by L0 Member
  • 868 Views
  • 1 replies
  • 0 Likes

Globalprotect-Need LDAP and RADIUS auth(MFA)

I am currently using Digipass Vasco OTP as RADIUS for Globalprotect. Users just put in their LDAP username and the OTP to login.I'm looking to add another factor i.e LDAP username and password before they get prompted for RADIUS token. Pls help me configure this. thanks.

What is the deal with VM Panorama mode maximum log storage space?

Hello,Documentation states that VM Panorama mode can support up to 24TB of log storage on a single virtual appliance.Each logging disk has 2TB of storage capacity for a total maximum of 24TB on a single virtual applianceSo we add 12 virtual disks with 2TB of storage to the machine. > show system disk details shows 12 disks with 2097152 MB of ...

10.0.10 code bug? LDAP auth server is up !!!

Since upgrading to 10.0.10, we've been getting system medium severity messages on our active firewalls that "LDAP auth server xxxx.xxx.xxx is up !!!". We never receive a down message though. We're not experiencing any issues with LDAP which makes me think this is a bug false alert. Is anyone else experiencing this?

jmurphy by L2 Linker
  • 9056 Views
  • 12 replies
  • 1 Likes
  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels