General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Maint partition is empty

Hello,  I have two PA-2020 in an HA Active Passive scenario.  Just looking around in my CLI, I noticed that the maint partition is empty on one of my nodes, but has an older 4.0.3 on the other node.

Partition     State         Version

-----------------

...

cenders by L3 Networker
  • 2898 Views
  • 1 replies
  • 0 Likes

Upgrading 4.07 to 4.1.2 in HA environment

The following change log may be useful to all of you wondering how an upgrade goes in an HA active-passive pair. It would be nice if PAN support were to put this into a tech note. Each step is essentially a check or an observation from top to bottom.

...

Resolved! HA recovery advice after upgrading Active first

Being a newb and never having updated my Active/Passive HA pair, I took the 4.1.10 release notes at face value. There is no mention of special provisions for HA upgrades so I clicked "install" and now have a 4.1.10 Active member and a mismatched 4.1.

...

MCmgt by L2 Linker
  • 2811 Views
  • 2 replies
  • 0 Likes

Reports - i cant see source ip complete.

Hi,

I have a PAN-2050 (Software version 4.1.5) and i have configured a predefined report with diferents tops (top 5 connections, top 5 destinations, top 5 applications). The problem is that when i dowload and see the PDF with the report i cant see the

...

Agentless User-ID not processing ingore-user list

I've been working on trying to configure all the firewalls with the Agentless User-ID setup but despite several attempts to enable it I cannot get it to ignore users.

I establish a session and enter config mode and type in the command set user-id-coll

...

jfarm by L1 Bithead
  • 4285 Views
  • 6 replies
  • 1 Likes

Resolved! issue downloading release notes

I've been having issues downloading release notes regularly. The download doesn't even start, no matter if initiated from the support page or from the PA UI (Device-Software).

Not a policy issue...

Anyone else noticed that ?

dieter_b by L4 Transporter
  • 1806 Views
  • 2 replies
  • 0 Likes

Resolved! Installing an Intermediate CA

I'm getting the following error when I perform a commit on a PA-3020.  PAN-OS 5.0.1.  I know I'm doing something wrong.  I'm new to installing certs so feel free to point and laugh.

I had a certificate signed by GoDaddy for use by Global Protect.  It

...

Intermittent Group Membership problem

We are currently having a problem with a new domain where the group membership intermittently disappears.

If you run the command "show user user-IDs match-user domain\" (4.1.x) or "show user pan-agent user-IDs match-user domain\" (4.0.x) it shows use

...

rds by L2 Linker
  • 2371 Views
  • 3 replies
  • 0 Likes

Resolved! How to import device configuration into Panorama ?

Hello,

We have a customer who has installed and configured a PanOS 5.0.0 A/P cluster of devices a few time ago.

Now he has bought a Panorama licence to centrally manage and report his devices.

Is there a quick and straight way to import devices congigur

...

ldormond by L3 Networker
  • 2528 Views
  • 3 replies
  • 0 Likes

BGP Route Table

So in discussions with a few customers the BGP functionality has come up when peering with ISPs and replacing dedicated BGP equipment.  The route table size on the PAN5060 is roughly 64000 routes.  Most Universities have tables upwards of a 1/2 Milli

...

amansour by L4 Transporter
  • 2525 Views
  • 1 replies
  • 1 Likes

two factor authenticaton tokens with PAN firewalls...

I am looking for a two factor authentiction solution for PAN firewalls (Global Protect).  particularly interested in a Mobile phone base app to provide security token or OTP to authenticate users via Global Protect.  Anybody have any good or bad expe

...

sns.jon by L0 Member
  • 3613 Views
  • 5 replies
  • 0 Likes

Global Protect Client

Hi

I'm using radius (rsa) to authenticate GP users and can't get me head around the GP client configuration - specifically the section where you need to put a username and password. How can this be possible when the RSA token changes every minute?

Can

...

djrodb by L3 Networker
  • 4721 Views
  • 7 replies
  • 0 Likes

Policy Based Forwarding (PBF) problem

I’ve got problem with policy based forwarding. I have 2 ISP - traffic to the 1st ISP is forwarded by pbf, to the 2nd – via default route. PBF rule monitors the remote target’s IP and availability of nexthop address. My question is: how the pbf is che

...

How to Lock down Search Engines to Safe Searches

Here are some custom vulnerabilities and one custom application I wrote to block unfiltered (Bad) searches on the big search engine sites.

These were written in 3.1.0 software.

UPDATE: See attached for 4.0 version of these vulnerabilities and custom ap

...

u2913 by Not applicable
  • 6715 Views
  • 3 replies
  • 0 Likes
  • 23702 Posts
  • 104 Subscriptions
Top Solution Authors
Top Liked Authors
Labels