General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1964 Views
  • 0 replies
  • 0 Likes

User-ID - Windows Server 2022 , not working

We are running a Windows server 2022 and PA-3220.  I have the user-agent put on a seperate Win 2022 server.  The firewall when communicating with server is getting dropped code 5986.  Under my Server Monitoring it shows Connection refused(0).  

tnewton by L0 Member
  • 3659 Views
  • 2 replies
  • 0 Likes

Resolved! CVE-2024-0010

Hi there everyone.

Could please someone clarify for me what versions are affected regarding CVE-2024-0010 as seen here?

https://security.paloaltonetworks.com/CVE-2024-0010

My inquiry goes for version 10.1.11-h5. Is it affected or not? Because I belie

...

Koulentis_0-1708063049201.png

Resolved! SSL/TLS Vulnerabilities

Dear Team , 
 
We have a customer, who found SSL/TLS Vulnerabilities on audit SSL/TLS configuration The firewall supports weak cipher mode CBC.
kindly provide the solution to remediate the weakness. 
snip attached for Refr.

lsvpn problems with connecting to gateway

We have a lsvpn architecture and we are having problems with one of the satellites connecting with lsvpn gateway. We configured and maintaining this lsvpn for the past 1 year and dealt with most of the problems. Usual one being credential cookie expi

...

Akhilb2728_1-1708033165796.png

device telemetry Failed to reload config files

Since the update from our firewalls to 10.1.10h2, i see in the system logs the event : Type: device telemetry Event: config-reload-failure Description: Failed to reload config files. The sent of the telemetry files is working. This happens every time

...

ManuDC by L0 Member
  • 6642 Views
  • 4 replies
  • 1 Likes

PA 440 dynamic updates

I am installing a PA 440 v 10.1

 

I can ping IP Addresses on the Internet using my internet interface as source

I can https inbound to the firewall after configuring a management profile 

 

under Device -> dynamic update or license check my attempt a

...

S.Byrne by L3 Networker
  • 1630 Views
  • 2 replies
  • 0 Likes

IPSEC tunnel due to timeout problem

I was configure remote 10 branchs connect to Office by IPSEC tunnel. Each branch connect to Office bandwidth  256kbps,512kbps, 1mbps. So someone branchs tunnel automatic disconnect.

Manual remote tunnel device(Cisco RV042) reconnect  to PA2020 error.

...

Amarzaya by Not applicable
  • 15528 Views
  • 7 replies
  • 1 Likes

GRE tunnel vs LSVPN which one to use for HUB and Spoke

Hi All,

 

I am researching between GRE and LSVPN tunnel for a HUB and Spoke design, basically for ISE authentication traffic from Meraki wireless to HUB ISE.

 

But i can't seem to find any document stating which one is fit for this purpose or what ar

...

Farmedi by L0 Member
  • 987 Views
  • 1 replies
  • 0 Likes

Resolved! How to clean up /dev/shm

Hi everyone,

 

Been receiving alerts for a little bit around tmpfs /dev/shm being at 99% - how should we clean up this directory? What is this directory used for?

tmpfs /dev/shm

 

Thanks!

palo 01.png

Child objects or override calue

I have been looking at the best approach to push a rule to multiple sites, but using a different value for the source address object at each site. For example, allow http from the users subnet to the internet, and the users subnet is different for ea

...

  • 24204 Posts
  • 117 Subscriptions
Top Liked Authors
Labels