General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Setting static Management interface IP in Azure VM NGFW

Is there any way to set a static Management interface IP with PanOS 12.1 in Azure VM? There are no options in the GUI, just a show DHCP client information window. From the CLI, a static IP/GW/DNS can be set in the config and commits without error, but it does not apply to the interface. Any attempt to "set deviceconfig system type static" result...

Resolved! Unable to activate Precision AI network security bundles license

HiHow to activate Precision AI network security bundle for my 400 series firewall?Previously I was using core bundle since 2024. For this renewal, my partner provided Precision AI bundle. I have already received the auth code, but I’m unable to activate it on both the firewall and CSP portal.The error message is showing “use email link” or fail ...

zinkt101 by L1 Bithead
  • 4608 Views
  • 2 replies
  • 0 Likes

Config admin using radius group.

I have VM-100 running panos-11.1.13. currently i have local admins for msp -superusers and 1 customer user with a customer -admin-role profile. customer wants to have mutiple admins controlled by their radius. so radius profile and auth profile is configured. how can i attach admin user group(listed under auth profile) to admin role profile. I s...

Resolved! Is DoS Protection Detection Possible in TAP Mode?

I would like to ask whether DoS Protection detection can be configured in TAP mode. Since this is TAP mode, I understand that traffic cannot be controlled or blocked. However, what I want is simply to detect whether there are any internal DoS attacks. I have confirmed that TAP mode is included under Zone Protection. However, it is still not clea...

Resolved! Explicit allow to Microsoft Update services

I've read through a dozen questions and the scores of answers to those questions, and I'm finding a mix of outdated information, bad information or just unrelated options... I suspect this is going to send down a rabbit hole, so I'll try to compartmentalize based on my testing. I never progressed far enough to get close to a resolution. So, ...

bhelman by L2 Linker
  • 43708 Views
  • 8 replies
  • 1 Likes

Detection of AI Agent Run Time via XDR

Hi everyone, I’m curious about XDR’s capability to detect AI agent runtime activity. My understanding is that XDR is quite effective at identifying post-incident artifacts, C2 IPs, and similar indicators. is it also possible to detect AI agent runtime behavior?

D.Ciftci by L0 Member
  • 3596 Views
  • 4 replies
  • 0 Likes

User-ID mapping without ldap across an enterprise

Hi All, not having the best day with thinking 😞 Palo Alto Scenario: PA FW CLuster in HQPanorama Log Collector only in HQStandalone PA FW in SiteAStandalone PA FW in SiteBStandalone PA FW in SiteCStandalone PA FW in SiteD No Panorama mgmt in place. All Sites have L3 connectivity back to HQ FWs are configured to send logs to log collector...

PA_nts by L4 Transporter
  • 3055 Views
  • 3 replies
  • 0 Likes

Resolved! pa-450 issues and going down 2 days in a row

all our path monitoring profiles on our ISP links were down even though the ISP was up and we confirmed internet access. There was no ping connectivity from the ISP Firewall Interface to the ISP gateway and we have 3 ISP connection. When we removed the path monitoring profiles on the default route, there was still no connection. Downgrading the ...

F.Pinar by L3 Networker
  • 1981 Views
  • 4 replies
  • 0 Likes

Policy Cache Usage Warning After Upgrade to PAN-OS 11.1.13-h1

After upgrading to PAN-OS 11.1.13-h1, we started seeing the following warning log:Warning: Policy cache usage is greater than 80 percent of the capacity We have multiple firewalls in our environment, but this issue is only occurring on devices that were upgraded to version 11.1.13-h1. When checking with the following command:> debug datap...

khkim by L0 Member
  • 919 Views
  • 1 replies
  • 0 Likes

Captive Portal with custom images

Hello everyone,I'm trying to implement the custom Captive Portal Response Page with custom images in it. Is there a way to upload my own images to the Palo Alto to use them in the Captive Portal? I did found the info about using the custom images from outside web or FTP resources via URL tag, but it doesn't fit the requirements of my customer. S...

higawajj by L0 Member
  • 5192 Views
  • 2 replies
  • 0 Likes

API - Number of object /item return valu

Hi Team/ @BPry Just checking , what is the default number of object/item return value per page while running get operation.For example, i am trying to pull all address present at shared location and we have around 30K+ address present. So what would be default return value of object per page. If there is any document , it will be helpful .Thanks

Resolved! PA-445 VERSION 11.2.7-h8

My pa-445 version 11.2.7-h8 sufferred a suddenly reboot affecting the whole operation. Troubleshooting : 1. ID:69b1fcea60b6f010bfa3a5e8, Serial:028101007082, OS:11.2.7-h8, Platform:400, IP:10.166.240.10+++++ 2026/03/11 11:52:35 System reboot /opt/panrepo/logs/reboot.log 2026-03-11 11:52:35 SYSTEM REBOOT [Watchdog tim...

F.Pinar by L3 Networker
  • 3316 Views
  • 3 replies
  • 0 Likes

Issue ports to switch turned (errdisabled) for both HA pair after upgrade from 11.1.6-h14 to 11.1.6-h25

Hi All, We have a pair PA 5220 in HA x2 and in PAN-OS 11.1.6-h14we perform upgrade to PAN-OS 11.1.6-h25, the upgrade is successful but we counter issue issue ports to switch turned (errdisabled) and it running normally after that First Pair HA we able to recover with shut/unshut the errdisabled interface however the second pair we try th...

Resolved! Prisma Browser ECCN

Hello, I downloaded Prisma Browser https://get.pabrowser.com/welcome and I am looking for the ECCN (Export Control Classification Number). Can someone in your Trade Compliance or Legal department provide me the ECCN ? Thank you.

  • 24442 Posts
  • 125 Subscriptions
Labels