General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Scheduled Log Export -user keeps defaulting to admin

OS - 11.1.2-h3 Setting up the scheduled log export for traffic via scp - initial connection test OK. So I know ports are open etc... We enter the username of the user for the SCP server that is going to be used and the password. As soon as you click OK the username defaults back to admin. So the SCP transfer fails. Any idea on how to fix t...

P.Burret by • L0 Member
  • 1218 Views
  • 1 replies
  • 0 Likes

Eve-NG Palo Alto VM ARP Issue

Does anybody encounter arp problems in eve-ng on palo firewall with pan-os 11 version ? As an example, i have a small topology like clientA->routerA-> firewall<-routerB<-clientB , when i try to ping from clientA to clientB, clientA send ARP Request for clientB however firewall does not reply ARP Reqest... (it is not a policy,routing...

Failed to initiate Plugin Phase1 commit

Anyone seen this before? "Failed to initiate Plugin Phase1 commit" Process logrcvr stopped (pid: -1) - Exit Signal: SIGSEGV "debug software restart process log-receiver" did not fix it nor did a reboot.

PBF with Egress loopback interface

I may be going about this wrong, but here's what I'm trying to accomplish, and this is the way I thought I could accomplish it. I need to route all traffic from a specific zone/subnet to a routing instance, and load balance egress, with the exception of RFC1918 destinations. My thought was to create a PBF rule to forward traffic to a loopback i...

Screen Shot 2022-03-16 at 11.38.38 AM.png

CVE-2024-3400 IOC's

Hello All, Its a twitter link but will try and summarize the process. https://twitter.com/cyb3rops/status/1781294529586331650 Credit to: Florian Roth @cyb3rops We decided to share our #YARA rules to scan for indicators of the exploitation of CVE-2024-3400 in #PaloAlto's PAN-OS with the community and included some of the generic rules ...

Resolved! Help understanding Asymmetric Path issue

Hoping that someone can help me to understand my asymmetric path issue (out of sync). I have a single virtual firewall with 2 virtual routers. Interfaces: Client (in zone 'client'). Is gateway for subnet. VPN (in zone 'vpn'). Is gateway for subnet. Machines: Client-01 - (192.168.1.3) 1 interface in 'client' zone. VPN-01 - 2 interfaces, (19...

Screenshot from 2024-04-21 09-14-11.png
shyrus by • L0 Member
  • 10196 Views
  • 3 replies
  • 0 Likes

Resolved! Can't import a certificate via XML API using C#

Hello, I'm trying to import a certificate to a Palo Alto VM-50 via XML API with an App written in C# but I always get this error: <response status = 'error' code = '400'><result><msg>No file uploaded</msg></result></response> My C# code is below, I can't see where the problem is, if I use this curl com...

kittcat by • L0 Member
  • 2083 Views
  • 1 replies
  • 0 Likes

Unresponsive support @clico

Hello, We've got an issue with a PA3250 and the thing is that support went silent on us. They were supposed to provide us with an answer before 14.12.2022 and we haven't heard from them. Calling them doesn't work, as they don't pick up their phones. What's going on? How can we address this?

silviub by • L0 Member
  • 2892 Views
  • 3 replies
  • 0 Likes

Resolved! Monitoring Global Protect

I'm currently in the process of migrating my company from AnyConnect to Global Protect on our 5220s. I'm looking for your feedback on how you all "monitor" the VPN service? When comparing the "dashboard" view of Cisco's ASDM I don't really see anything which can be loaded on the Palo "dashboard" tab. It seems like the only real way is to look ...

Incomplete release notes

Hello, why do I have to go there: PAN-OS 10.2.7-h6 Addressed Issues (paloaltonetworks.com) to find some unresolved issues in 10.2.8 ? i.e PAN-242627 or PAN-246431

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature works! Why do accepted solutions matter? By marking a reply as an Accepted Solution, you cont...

JayGolf_0-1691518400714.jpeg
JayGolf by • Community Team Member
  • 12068 Views
  • 3 replies
  • 15 Likes

Basic Palo Alto configuration Help

I am very new to PA firewalls. To understand the firewalls I have setup a lab and also worked on the physical firewall. Following my topology PA - Switch - PA VLAN 100 Ip : 192.168.1.5/30 and 192.168.1.6/30 Zone WAN Mgmt profile : ping enable interface : L3 sub interface 1/1.100 - tag 100 Nothing else is configured. I am try...

gondolf by • L1 Bithead
  • 2785 Views
  • 2 replies
  • 0 Likes

Citrix Receiver on Globalprotect

I seem to have Globalprotect working fine for access to any internal resource.The one thing that does not seem to be working is the connection Citrix Receiver (PNAgent legacy version 13.3) makes to our internal Citrix Web Interface / Services site.I'm getting the error "citrix receiver could not contact the server. please check your network conn...

dieter_b by • L4 Transporter
  • 14736 Views
  • 5 replies
  • 1 Likes
  • 24462 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels