General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Email Notifications

hi,I would like to forward an email notification for specific alerts, ONLY to the person to whom the incident was assigned to.I don't see any subtype option to the Distribution List. Has anyone found a solution to achieve this ? (slack messaging is not an option) thank you

Expedition not importing NAT or security policies from PA-3020s running PAN-OS 9.1

I'm working on a project to upgrade 2 x PA-3020s each with their own configuration into an HA pair of PA-1420s and am having trouble with Expedition. I've tried importing the devices using the API key and also by exporting the running-config.xml file as a superuser and manually importing it into Expedition. Both are giving the same results. My "...

Retrieve "User Group" using RADIUS attributes

Hello Team, I have configured a RADIUS connection with FortiAuthenticator to implement multi-factor authentication (MFA). Within FortiAuthenticator, I created two user groups: an ADMIN group and a USER group. My objective is to set security policies on our Palo Alto firewall using these Group IDs. Despite configuring the RADIUS attribute (user...

Resolved! Local IKE interface and Tunnel interface in different virtual routers

Does Palo Alto allow having the Local IKE interface in "default" virtual router and the Tunnel interface in different virtual router when setting up site-to-site ipsec tunnels ? The use case of this to achieve multitenancy and overcome situations when different customers ( with overlapping lan subnets) connecting to a Hosted Enviromnet .

viks_a by • L0 Member
  • 3869 Views
  • 2 replies
  • 0 Likes

BGP session flapping with error code 3 subcode 11

Hi All, I have an issue with setting up a BGP Establish connection. On my side is a PA firewall connected to the a ISP with BGP session. The first time, the ISP side sent only the default route to PA, and there was no problem in the BGP session. And now we require the full routing table that involves 4000+ routes sent to us. And I do a Max-pre...

HenryITP_0-1716779129951.png
HenryITP_1-1716779216937.png
HenryITP_2-1716779245756.png

Error trying to assing more than 90% to Detailed Firewall Logs at Collector Group in Panorama

Hi all, We are using a Panorama VM with a local managed collector. When I try to customize how to use the assigned space, Collector Group -> General -> Log Storage and I introduce more than 90% for detailed firewall logs, red square indicates that value introduced is incorrect. Our Panorama VM version is 10.1.12 and there are free space ...

fjmjugr by • L1 Bithead
  • 1380 Views
  • 2 replies
  • 0 Likes

Unable to reach management service and console

Hi, greeting all my palo alto appliance(PA-850) used virtual-wire mode already, a few days before, paloalto can passaging traffic by virtual-wire pair, but the management service unreachable. even i tried to PING / HTTPS / SSH / SNMP / Console etc. and also i tried find the ARP info by network device, the device no any ARP record from Paloalto m...

WSTW_SE by • L1 Bithead
  • 7599 Views
  • 6 replies
  • 0 Likes

COMMIT FAILED

Hi everyone, When I commit on my device, I get the following error "virus_update_block" Has anyone had this error before or can anyone help me resolve it? Thanks.

Resolved! PA 3050 password

We have bought a used Palo Alto PA3050 for development purposes and did not know the password. We have done a factory reset but the credentials of username admin and password admin, do not work. When we boot into maintenance mode, we cannot set the IP address and the screens say to contact Palo Alto. Any help please to reset the password so we c...

andrewk by • L0 Member
  • 3085 Views
  • 1 replies
  • 0 Likes

Which CA is your Suggestion/Recommendation for SSL Decryption

Hello Live, I was wondering which certificate athority network administrators choose to buy their certifcates from. I am currently using a self signed certificate distributed via GP for the SSL decryption feature. I am hoping to replace this self signed certificated with one from a trusted CA. Will this type of certificate work for decryption? I...

daperez by • L0 Member
  • 2884 Views
  • 1 replies
  • 0 Likes

HA Condition - Link Monitor Recovery - Time to retake Active Link Monitor role

HA Condition - Link Monitor Recovery - Time to retake Active Link Monitor role Hello Community, how is everything going, I hope it's going well. I have the following questions regarding HA. Details of the environment. Active - Passive A/PPrincipal PA - PA-52XX-01-HA - Priority 50Secondary PA - PA-52XX-02-HA - Priority 100Preemtive activeLi...

Metgatz by • L4 Transporter
  • 2101 Views
  • 1 replies
  • 0 Likes

HA sync fail, not normal

Need sync help. About two months ago we noticed our passive 3250 would slowly not respond. It finally died, no console response. Opened ticket, had one RMA, powered it up. Imported the saved config we took before it died. Checked ip's, management setting, etc and wired it up. Configs not in sync, expecting that. Sync to peer from active to passi...

Active_HA_no_ip.png
Passive_HA_no_ip.png
  • 24460 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels