General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4253 Views
  • 0 replies
  • 0 Likes

Firewall Access issue

Hi Team, The user is having issues logging in to the firewall. Please find below a screenshot and suggest how we should troubleshoot. Under the system log, I see authentication success, but the user is not able to login.

shirishkulkarni_0-1708412549709.png

Why doesn't Firewall PAN automatically change the MAC address of the Rever Proxy device?

Hello guys, can you help me with this problem? We are looking for the following logical scenario, we have 2 Reverse Proxy (Imperva) devices connecting through a PAN Firewall as shown below. When checking for backup on Imperva. We tried the following: - Turn off eth2 port on Master and traffic is transferred to Backup successfully. All operations...

Namppmtechpro_2410_1-1708400988356.png

URL list allowed on firewall

Hi Team, I need a list of URLs that are allowed through the Palo Alto firewall. Is there any way to get the URL's name through cli or gui that is allowed through our firewall? Only allowed url names are require

Export option in Software section

Hi, I have a PAN-OS VM on version 11.0. I've noticed the option "Export" on the page of software update but couldn't figure it out. The list of SCP profiles is empty even though I have an SCP server on my host.   I have also created SCP profile under devices:   Would be thankful for any help

Screenshot 2024-02-18 135507.png
Screenshot 2024-02-18 161654.png
YonatanG by L1 Bithead
  • 3852 Views
  • 3 replies
  • 0 Likes

ECCN

Hi Team, I need to know the ECCN for the below part numbers. PAN-ENT-SUB-ELA PA-PRORATED-CREDIT-SUBS PAN-ENT-PREM-ESA

Device certificate advisory when firewall doesn't use the mgmt interface for these connections

Hello. so in regards to the palo advisory of upgrading and rolling out device certificates we are running into an issue which I'm not sure what the impact is. we have a number of panorama managed firewall clusters. however these firewalls don't use their mgmt/oob interface for connections to palo alto services or dns. as a result after following...

input logs firawall

Hi, is it possible to add information imported from another event log to the logs of a Palo Alto firewall?

axelfa by L2 Linker
  • 1690 Views
  • 2 replies
  • 0 Likes

HA upgrade oddness (no preempt)

Hello, just seeing if anyone has an explanation or has experienced this before. I followed the HA firewall upgrade guide and experienced this unexpected behavior. i suspended the primary, ( secondary went active), installed the new os, and rebooted. Upon reboot, it was no longer suspended, came up and went active and caused a split brain. After ...

VK9H13 by L2 Linker
  • 1697 Views
  • 2 replies
  • 1 Likes

Possible NAT issue on a PA-3260

Folks, I am trying to configure a NAT policy which should be bi-directional. Here the traffic can be initiated from outside or the inside. The policy is configured and I can see NAT hits. However, this policy does not work. The NAT IP is from a subnet which does not reside on the Untrust interface. This is where I see the possible challenge is...

Resolved! Panorama Software Upgrade

Hi All, Just wanted to confirm I have the process right. We're running Panorama, M-100 appliance (32GB RAM), managing 3 pairs (6 no) of PA-3220 firewalls. All currently running PAN-OS 8.1.5. Looking to upgrade to the next major stable release, currently listed as 9.0.6. From what I have read, upgrade path is, Panorama first, 8.1.5 > 9.0.0 &gt...

Captive portal authentication over TLS

Hi, I've enabled captive portal on our systems, following the PA docs (Configure Authentication Portal (paloaltonetworks.com)). I have an SSL/TLS profile created with a valid, trusted certificate signed by our own internal CA. When our machines try to authenticate to the captive portal, they do so over HTTP not HTTPS. Is there some way to force ...

Prisma Cloud: Azure Active Directory resources not being ingested

I have provided Prisma Cloud with all the necessary API Permissions and more, along with granting the necessary roles needed to view Azure Active Directory Security Settings. The issue lies in resources showing up in Prisma Cloud itself when queried, e.g Identity Protection related resources or Active Directory Roles and Administrators or even P...

AJohri by L1 Bithead
  • 2679 Views
  • 2 replies
  • 0 Likes
  • 24362 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels