General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4235 Views
  • 0 replies
  • 0 Likes

HA2 interface not up using HSCI cable

Hi Good day, Our client received two Palo Alto units, including an HSCI cable. However, they noticed that the HSCI cable is not functioning. When they connect it to the HSCI port, the LED port does not light up. However, when using a normal SFP with fiber, there is no problem. Is there any solution that can help us, or should they proceed with t...

No DNS, cannot ping anything above gateway

I'm trying to set up a PA-820 from scratch, but would like to update and set up rules before placing it on top of our network. Currently it is set up as a DHCP client, parallel to our office router, connected upstream to a Charter AP and modem (for some reason, this is the only way they'll give us a static IP and a high speed connection to the i...

Altais by L1 Bithead
  • 8387 Views
  • 7 replies
  • 0 Likes

SMB Mid-Market Competitors

Hello All, About 2 weeks ago and in the forth coming weeks, the key target area for me will be the PA-400 series and the PA-14xx series as we shall be focusing on the SMB / SME / Mid-Market sector. However as I have worked in this area for 15+, I am aware you have you SonicWall, Watchguard, DrayTek, ZyXEL are heavy lifters in the UK market. Ou...

J.Patel by L1 Bithead
  • 3511 Views
  • 2 replies
  • 1 Likes

How does Expanse know about my website?

I have the following message in the User Agent field of my Apache log: Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com"...

Reminder to Register / Log In to Make the Most of LIVEcommunity!

LIVEcommunity is thrilled to share a new feature: a reminder to log in or register to get the best community experience possible! If you’re not logged in, you will notice a new prompt in the upper right corner of our site, guiding you to sign in or register to join our community.   By registering, you'll unlock a world of benefits, incl...

jforsythe_0-1707497381862.png
jforsythe by Community Team Member
  • 1008 Views
  • 0 replies
  • 0 Likes

Resolved! FIPS-CC Mode Initial Setup

We are now required to switch to FIPS-CC mode for compliance. I have read the Admin Guide section about switching the operation mode to FIPS-CC but have a question about a FIPS security function. The guide states that I can save my current running-config since this change will revert the FW back to factory defaults and all configs will be lost b...

B.Vance by L1 Bithead
  • 6246 Views
  • 7 replies
  • 0 Likes

Set a new GlobalProtect VPN portal to prisma for 1000+ devices

Hi, I've been asked to roll out a new VPN portal and automatically switch users over to it in a phased approach. I don't think this is possible via Palo Alto (as it will set it for all users immediately) and Group Policy has some limitations around phased approaches so we are using SCCM. I have a script which i am testing but getting mixed resul...

AJP_UK by L1 Bithead
  • 3148 Views
  • 3 replies
  • 0 Likes

Ubuntu_OpenLDAP with PAN-OS User id

Hi All, Is there any document which will show how to configure Ubuntu based OpenLADP as a user id agent with Palo Alto firewalls. How to add the LDAP server into Server monitoring profile.

Resolved! Vip(DNAT not working)

This is my topology. From 30.0.0.10 i would like to access the server 192.168.0.2 with the help of PA wan interface IP(30.0.0.1)I have created DNAT and Ssecurity policy . Object Prenat IP is 30.0.0.1/8 and Webserver Ip is 192.168.0.2/24, when I try to open 30.0.0.1 from my web browser I am not able to see server's web page. I took a captur...

ArunKumar7_0-1707441279489.png
ArunKumar7_1-1707441365240.png
ArunKumar7_2-1707441401377.png

Resolved! Refund for Palo alto NGFW purchased on AWS

We have been trying to reach Palo Alto branch of refund. We have tried all the contact information for refund. They are not answering to both email and phone calls. We have removed the palo alto stack If anyone knows how we can contact Palo Alto for refund please let us know. Warm regards,

E1T1Tech by L1 Bithead
  • 3069 Views
  • 3 replies
  • 0 Likes

SIP Invites timing out for certain calls

Hi all, I've have a sip voice issue for a few weeks that I am a bit lost on. For a bit of background, we have a cloud phone system we just moved over to around a month ago. A cloud phone system links up to Webex softphone for our call center to receive calls. If someone dials our main phone line it will start in the cloud PBX but then send the...

ECMP, interface, zone and security policy question

Hi guys I am quite new to Palo Alto NGFW. We have on-prem PA-32xx on 11.0.3. I am having trouble with static route ECMP for redundant IPSEC tunnels to AWS. Previous guy configure both tunnel in different zone (lets say AWS1 zone and AWS2 zone) and then configure bunch of PBFs. Then when the return path is changed, traffic will get dropped and I ...

  • 24358 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels