General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 73 Views
  • 0 replies
  • 0 Likes

Join the Fuel User Spark Event on March 19: Dealing with Threats !

 

Join us at the Fuel User Group Spark Event on March 19!

 

Get ready to ignite your cybersecurity knowledge and connect with industry experts at our upcoming Spark event hosted by the Fuel User Group. Whether you're a seasoned professional or just

...

kiwi_0-1709893724672.jpeg
kiwi by Community Team Member
  • 675 Views
  • 5 replies
  • 3 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3322 Views
  • 2 replies
  • 14 Likes

Resolved! Can I get all managed devices to show in Panorama Maps?

Do anyone out there know if it is possible to display all managed devices in Panorama in either the Threat or Traffic Maps?

We have branch firewalls in locations all over the country and it would be nice to see which were getting hit with more traffic

...

test security-policy-match

Hi

Somebody help me write command test security-policy-match....... which WORKS and search that rule:

     VIP-TEST {

        from zone-v586;

        source any;

        source-region any;

        to zone-v8;

        destination 192.168.81.81;

        destin

...

Wbm by L2 Linker
  • 3789 Views
  • 6 replies
  • 1 Likes

Resolved! PAN-OS Upgrade with HA

Has anyone found a really good tech note that goes over performing a PAN-OS upgrade on an HA pair?  Both Active-Passive and Active-Active?

cindyb by Not applicable
  • 3311 Views
  • 2 replies
  • 1 Likes

Resolved! Mgmt Plane Always high CPU

I have a PAN fw at a client site that always has the mgmt plane cpu at 100%. The data plane CPU barely ever goes above 10%. Is there an easy way to troubleshoot the cause of this or what is taking up so much CPU usage?

SDorsey by L4 Transporter
  • 6744 Views
  • 10 replies
  • 0 Likes

Has anyone taken a look at panug.com ?

I stumbled across a site that I think aims to be similar to https://www.cpug.org - sort of the community's independent forum where discussions about Palo Alto can take place. Kind of a neat idea, but I'm not sure how much community momentum it has.

Ch

...

Resolved! Can't download GP client from the portal

We are setting up GP for SSL VPN. For testing purposes , we have created a local db account on the box and setup GB. The portal comes up and when u log in , u never go beyond the login page . It keeps trying to connect and never does . It eventually

...

usvi by L3 Networker
  • 2458 Views
  • 4 replies
  • 0 Likes

Certificate for Secure Web GUI creation

Hello

Which attributes shall an external CA certificate have to be accepted as a Secure Web GUI Certificate?

I have imported one, but SSL Management doesn't work with it. These are its attributes:

   Version: 3 (0x2)
        Serial Number:
            15:

...

Best practice for OWA and OMA

Hi

I'm getting rid of our old ISA server which we used to expose OWA and OMA and want to use our PA-500 to allow domain users access to OWA and OMA (for their iPads etc).

I've noticed that the application 'Outlook-web' is used for OWA and its dependanc

...

TDC by L1 Bithead
  • 3643 Views
  • 4 replies
  • 0 Likes

Commit Error (sslvpn)

Hi,

I am recieving the following error when issuing a commit,

Management server failed to send phase 1 abort to client sslvpn

Management server failed to send phase 1 to client useridd

Commit failed

The only change in configuration is adding new local use

...

rsaber by L1 Bithead
  • 3839 Views
  • 4 replies
  • 0 Likes

Inbound SSL Decryption and monitoring

Hello,

I'm trying to setup inbound SSL decryption. It is a pretty basic setup.  Two layer 3 interfaces on a PA-500.  One interface is in an 'Outside' zone, the other is in a 'DMZ' zone. In the DMZ zone is a web server with a signed SSL certificate.  T

...

Cisco IPSEC VPN client connecting to PAN 4.1

Hi folks,

there were no way to establish a ipsec connection between a Cisco VPN client and PAN. I was "inspired" by the globalprotect guide but wasn't enought.

  • At the cisco vpn client side, I had configured just the ip address, the group and pwd, and n
...

robclav by Not applicable
  • 5491 Views
  • 7 replies
  • 0 Likes

Static route on Management Interface

Hi all,

how can I define an additional static route on the Management Interface?

I have a setup with a customer were the communication from the management interface to two specific IP addresses has to be routed over another next-hop which is not the de

...

Resolved! TAP Mode and IPv6

Hello Everyone,

Is it possible to monitor mirrored IPv6 traffic in TAP mode?  I have a PA-500 and it has been enabled for IPv6 firewalling.  Apart from checking this option, is there anything else that has to be done to monitor IPv6 traffic?  If it is

...

  • 24124 Posts
  • 100 Subscriptions
Top Solution Authors
Labels