General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Failed to renew device certificate

Hi

 

the device certificate is going to expire end of march.

My PA trys to renew it and comes up with the following error:

Failed to renew device certificate.Failed to send request to CSP server.Error: No OCSP response received(dest => 35.238.43.180)

 

I h

...

kbe by L3 Networker
  • 20279 Views
  • 15 replies
  • 0 Likes

Tacacs+ Cisco ISE config

Does anyone know how to configure the cisco ISE side? We can use tacacs now to access the gui but only local usernames and passwords work when trying to access the CLI using SSH. Does anyone have a complete cisco ISE setup? I found a guide to set up ...

PAN-OS 8.0 HA A/S Cluster MAC Flapping

Is anyone else experiencing MAC Flapping with an A/S Cluster running PAN-OS 8.0?

 

When one of the firewalls is rebooted and goes into the HA passive state the network detects a network loop because of MAC address flapping between the Active and Passiv

...

mvdooren by L0 Member
  • 2782 Views
  • 1 replies
  • 0 Likes

ISP Configuration in case of TATA (Unmanaged ILL)

ISP Configuration in case of TATA (Useful for Indian Customers willing to configure an unmanaged TATA ILL)

 

** This is useful in case you are not provided with a MUX or a ROUTER along with the Internet Link form the ISP**

 

If you are a customer willing

...

dc firewall Management interface

 

Hi,

Where should I connect in terms of security and management if I need to connect to the oob management interface? I have access layer, collapsed core, and server farm switches.

Thanks

simsim by L4 Transporter
  • 769 Views
  • 1 replies
  • 0 Likes

Resolved! Change Font on Palo

Hi All,

I was wondering if there is a way to change the font or font size on a Palo device.

Couldn't find any relevant doc for it.

Thanks,

P

@BPry 

@SCantwell_IM 

Pras by L4 Transporter
  • 1687 Views
  • 2 replies
  • 0 Likes

Resolved! Error in commit after upgrade to 10.1.5-h1

After upgrade from a PA850 from 10.1.5 to 10.1.5-h1 in the end of last week we no longer can commit new configs 

It gives the following error when we try to commit.

  • Validation Error:
  • rulebase -> security -> rules -> Block xxx -> hip-profiles unexpected
...

Upgrading PAN-OS active/passive question

I have 2 firewalls in active/passive mode. Am I able to upgrade one of the PAN's and leave the other in standby or passive mode for a few days while I ensure there are no issues before upgrading the second PAN? It is a jump bigger than 2 versions so

...

AnthonyT by L1 Bithead
  • 2341 Views
  • 8 replies
  • 0 Likes

Global Protect

Entered the credentials, got the push. Gp is showing connecting and after 2 sec showing not connected and minimizes the agent. Exactly after 5 sec agent pops up.. Started spinning and gets connected.(Without asking for credential and push mfa)

Versio

...

OOM-Killer on 8.1 Trail (PA-5050 device)

Hi,

 

i know this is about old software on old hardware, but both are still supported by Palo Alto. In the last months we get a heavy amount of OOM Message / Stack Traces / you name it.

Actually we arent able to push new config changes from Panorama

...

  • 24034 Posts
  • 102 Subscriptions
Top Liked Authors
Labels