General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4224 Views
  • 0 replies
  • 0 Likes

Upgrade to 5.x - the good, the bad, the ugly?

OK, one for you guys who have upgraded to the 5.x stream.Ignoring the steady furore over the UserID agent and CPU issues, what are the advantages/disadvantages of upgrading from 4.1.x to 5.0.x?I have a single HA pair, no Panorama, no Wildfire subscription, using both IPSec and SSL/Global protect VPN's.Anyone willing to comment?Cheers

darren_g by L4 Transporter
  • 4321 Views
  • 5 replies
  • 0 Likes

PA 2000 platforms rebooting in our network

We have deployed around 10 pairs of PA 2000 platforms in different networks within our environment.These networks almost generate the same type of traffic. What we experience is that, these firewalls which ever is active, goes in for an automatic reboot. The traffic is not interrupted bcs of the passive device taking over.We see this in all the ...

User-ID on-box Best Practice

Hi,Can anyone clarify for me what the best practice recommendations are for the User-ID agent? Prior to V5 it was clear that they should ideally run on the domain controllers or servers close to them. However with the option of running on-box, is this now the preferred option, are there any limitations or side-effects of doing so?Thanks

djr by L4 Transporter
  • 9643 Views
  • 6 replies
  • 0 Likes

Shrew Soft VPN (XAuth) connected but no traffic

I can connect successfuly thru the Shrew Soft VPN but I cannot get access to the internet.I tried both "Obtain Topology Automatically or Tunnel All" and setting manually Remote Network Resource 0.0.0.0/0 but neither one worked.Any ideas?

nkavoulis by Not applicable
  • 3064 Views
  • 2 replies
  • 0 Likes

Resolved! multiple interfaces in a Zone

AllI only setup Vwire and Zone, Each zone has one interface. we have a few (5)zones. For examplezone1=interface1zone2=interface2, etcso user started ftp session, it will pass two zones Z1-Z2--->Z3-Z4---->ftp.sample.com, so we see two sessions for same connections. Two sessions will be contributed to connection tables. PA will inspect twic...

Resolved! Management CPU is 100%

Hi Guys,We are having an issue with the Palo Alto 2050 running OS 5.0.2. Earlier it happens when we do a commit or generating some reports. Then we cleared the all logs and update to 5.0.2 and now the Management CPU is always 100% even though we didn't do anything. Is this is a bug in 5.0.2 and does the next version 5.0.3 will fix this. Please h...

ajay by Not applicable
  • 18376 Views
  • 19 replies
  • 0 Likes

tunnel interface in PBF rule

Hi,Can anyone please help to resolve a small issues.1) Can we use tunnel interface in PBF rule if yes please provide a sample configuration.2) I have 2 ISP's terminated on my PA firewall, i require a failover to 2nd ISP if my Primary ISP is down by monitoring the Gateway of 1st ISP, how can i achieve it.ThanksRaj

Is there a way to search on the network monitor window for a particular subnet ?

Is there a way to search on a particular subnet range in the monitor / network monitor view ? This would be a great feature for us as we (Data Center) monitor the URL usage globally and would like to drill down to a single subnet (location) to view what problems there may be. We are a 24x7 shop and could use this a a tool to resolve issues on...

CJ by L0 Member
  • 3168 Views
  • 3 replies
  • 0 Likes

Resolved! What action does "None" perform in URL Filtering Profile?

I had a customer look at the Action types for the URL filtering profile, and he understood all options for Alert, Allow, Block, and Continue. What does the action type of NONE perform? We do not do anything? We permit the traffic, but do not log it? Thanks. SC

scantwell by L4 Transporter
  • 5747 Views
  • 3 replies
  • 0 Likes

dhcp relay

After enabled dhcp relay on a interface the client`s didn`t get a ip address, the strange thing is that de palo denied the packets. So i must create a access rule to enable traffic from the palo interface (with dhcp relay enabled) to the dhcp server.Is this normal ?

mjanssen by L0 Member
  • 4004 Views
  • 4 replies
  • 0 Likes

Admin Role & Dashboard Log Widgets

So, I'm teaching a PAN-EDU-201 class this morning and when we were discussing the Admin Roles, one of my students asked a question about the Dashboard Log Widgets. The question was, if I create an Admin Role and disable the Monitor Tab (which disables all of the log file access under the Monitor tab) would the Dashboard Log Widgets be disabled? ...

jwolach by L4 Transporter
  • 3954 Views
  • 5 replies
  • 0 Likes

Resolved! 'Failed to generate Panorama server certificate. Devices may not be able to connect.

I have done a fresh install of Panorama 4.1.10 and i keep receiving the message 'Failed to generate Panorama server certificate. Devices may not be able to connect.'I have tried all the possible options i can remember from CLI or GUI but i didn't get any success.Has anyone experienced the same problem before? Thanks

adcar76 by Not applicable
  • 5131 Views
  • 2 replies
  • 0 Likes

4.1.12 early adopters...

Am I the only one who is adopting a "once bitten, twice shy" approach when it comes to 4.1.12?The release notes claim that PAN have fixed the bugs I've been bitten by - the userID process problem, the App Override killing TCP sessions after 10 seconds and one other - but I'm wary of rushing out and just installing it.Has anyone run with 4.1.12 y...

darren_g by L4 Transporter
  • 4998 Views
  • 7 replies
  • 0 Likes
  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels