General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4117 Views
  • 0 replies
  • 0 Likes

Issue: New Palo Altos crashing domain controller with migrated config

Morning all!Have an odd one for y'all that has defeated us so far. We are currently attempting to side-grade from PA-5250s to new PA-3440s but have experienced a showstopper twice that caused us to revert back to the PA-5250sIssue: New Palo Alto firewalls (seemingly) crash domain controllers once load hits the network (KB5035849 is uninstalled f...

Resolved! Firewall OSPF Area configuration - range or interface specification - Area 0.0.0.0 general questions...

Configuring an area 0.0.0.0 on PAN firewall (10.2 and higher). 1. Does PAN attribute 0.0.0.0 to area 0? Is that the only way to define area 0? or other options? 2. Area IP range: in cisco world, the range command implies that all connected interfaces on the router, which fall within the range, get include as LSA's in the area and start commu...

anon4all by L2 Linker
  • 3491 Views
  • 2 replies
  • 0 Likes

Connect Before Logon + Enforce GlobalProtect for Network Access + Captive portal

Hi all, we are enforcing to our devices an always on company connection, without vpn our users cannot login to their windows desktop (no local password cache), so we have implemented "Connect Before Logon" + "Enforce GlobalProtect for Network Access" but we have problems with captive portals. Is the captive portal detection working also in the p...

Resolved! Log forwarding profile in all security policies

Is there any other way to configure Log forwarding profile in all 300+ security policies in single shot. currently there is no log forwarding profile in all 300+ policies. So below method is not applicable: Not through web interface but you can export config out.It is one single xml file. Device > Setup > Operations > Export configurat...

Panorama Software Deployment Options Missing

I have a virtual Panorama running 11.0.3-h3 and I'm trying to deploy software to PA-450s. The only option I have is to reboot device after install. I don't see an option to upload the software only without an install and reboot. Is there supposed to be?

LLDP Unsupported / Unkown TLV types

Hey Community! I have my PA5200 series attached to Cisco ACI switches and it seems that some of the LLDP TLV options that the Cisco switches advertise - are either not understood/not supported on the Palo. Is there a way I can supress the log output from displaying in the monitor tab/dashboard as it just fills the dashboard all the time: This is...

mcnairi by L1 Bithead
  • 4306 Views
  • 2 replies
  • 1 Likes

Resolved! Palo Alto Events in 2025

Hi All, Where can I find information on Palo Alto hosted events in 2025? Doesnt seem much is going on. Thank you.

roma by L2 Linker
  • 6889 Views
  • 1 replies
  • 0 Likes

Resolved! CSP access

Dear all, Apologies for opening so many community cases. but hoping someone could put me in the correct direction. I need to access my CSP, I come across the following warning message. Unauthorized Access Your membership has expired or has not been approved, please contact Palo Alto Networks Support. I need this access as I progress with f...

Shadow by L2 Linker
  • 4757 Views
  • 5 replies
  • 0 Likes

Cortex Connection Lost

Hello everyone, I'm currently conducting a survey on the various possibilities that could lead to the "Connection Lost" issue in the environment. I encourage all of you to participate in this survey. Additionally, I have a question: In the event that an endpoint loses connection and is subsequently removed from the Cortex Administrator console, ...

Yayati by L0 Member
  • 1769 Views
  • 1 replies
  • 0 Likes

GlobalProtect authentication blocked by home firewall

I use GlobalProtect to connect to my employer's network from my home Wifi. However, the GP authentication requires port 8443, and this is not compatible with maintaining the highest security firewall settings on my Xfinity Gateway. Every time I connect, therefore, I have to change the Gateway firewall to a lower security setting. For pe...

bfaull by L0 Member
  • 4087 Views
  • 4 replies
  • 0 Likes
  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels