General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4243 Views
  • 0 replies
  • 0 Likes

Resolved! MIBS FILES

Hello all. We are trying to load the mib files into SolarWinds/Orion and it doesn't like the .my extension on the files provided at https://support.paloaltonetworks.com/index.php?option=com_pan&task=dl_tech_doc&filename=PAN-MIB-MODULES.zipHas anyone experienced this? Is this a SolarWinds/Orion issue or can the file extension be changed...

vnt90 by L2 Linker
  • 8666 Views
  • 5 replies
  • 0 Likes

How can I let AD login script auto-run after SSL VPN connected?

Hi, All,We want our Windows AD login script to auto-run after remote users get connected SSL VPN (NetConnect), so that users' home drive can be auto-mapped.Pls advise us whether it is possible. If yes, pls provide us the procedure to achieve it.We're using PA-2050 firewall, software ver 3.1.6, SSL-VPN client ver 1.2.0. Kindly find other details ...

certisis by L0 Member
  • 4016 Views
  • 3 replies
  • 0 Likes

Can't sort columns in the ACC page

Hi there,In the ACC page, I can't sort columns in any order. Sorting options are not available for any columns (take a look at the picture below)Is it bug or something else?PS. SW version is 4.0.5

goldandy by L2 Linker
  • 2784 Views
  • 3 replies
  • 0 Likes

Resolved! Panorama Management Port

Is port TCP 3978 the only one required to manage the FW's from Panorama? Is this initiated in both directions? Does this include logging?Thanks - Chris

chrisp by L3 Networker
  • 5131 Views
  • 5 replies
  • 0 Likes

Change Severity of Entries in Systen Log

Hi,Is there a way to change Severity of particular log entries in System Log.In particular I'm interested to know how to change Severity of log entries which identify when a port is up or down. Currently these log entries are identified as 'informational'Rgds,Burim

bbivolaku by Not applicable
  • 3518 Views
  • 1 replies
  • 0 Likes

CLI error when "show system statistics"

We have a problem when we are trying this CLI command show system statistics in active node, not in the passive node.Any hint?XXX@YYY(active)> show system statisticsSep 13 11:42:27 Error: pan_shm_alloc(pan_shm_alloc.c:55): failed to open shared memory:(errno: 2) No such file or directorySep 13 11:42:27 Error: pan_shmgr_init(pan_shmgr.c:244): ...

aj.reus by L0 Member
  • 2659 Views
  • 1 replies
  • 0 Likes

Modify QoS Profile on interface based on schedule?

Hi all,I'm wondering if there's a way to have a different QoS profile applied to an interface based on a schedule? We want to be able to set different guaranteed egress and maximum egress values to the QoS classes based on time of day. From what I can see, there can only be one QoS profile set per interface and there appears to be no way to ha...

Mack by L2 Linker
  • 2494 Views
  • 2 replies
  • 0 Likes

Data center PAN configuration

Hello!We need to implement Palo 5050 in data center with Cisco Nexus 7k infrastructure and 10 Gbps interfaces. Is following design ok?One 10 Gbps interface on N7k connected to Palo will be trunk (allowing vlan tags: 2, 3, 4). Second 10 Gbps interface on N7k also will be trunk allowing vlans: 12, 13, 14.Is it possible to configure Palo for bridgi...

mkopcic by L2 Linker
  • 4805 Views
  • 4 replies
  • 0 Likes

Resolved! Reporting Question

Is there a way to report on all users that have gone to a specific site? I have a PA 2050 that I am evaluating and is in TAP mode.

jvigil by Not applicable
  • 3341 Views
  • 3 replies
  • 0 Likes

Unable to commit in 4.0.4

Hi,I seem to have an issue whereby I can't commit changes on our Palo anymore. I get the following error:OperationCommitStatusFailedDetailspan-agent -> Deafult -> link-speed unexpected hereAnyone seen this before or any tips on how to resolve this would be greatly appreciated.Many ThanksHarsh

harsh01 by Not applicable
  • 2537 Views
  • 2 replies
  • 0 Likes

Facebook

Hey,Is there a way to allow post and block chat . It seems you have to allow both . Also, how can you restrict posting to a corporate Facebook page only while denying access to Facebook personal account .

usvi by L3 Networker
  • 2161 Views
  • 1 replies
  • 0 Likes

PBF config works wonderful, except

We have two ISP links and have PBF configured. Our main Internet connection went down on the DS3 side of the next hop router at 3AM. The ethernet interface that we connect to never went down. I had to manually disconnect the ethernet interface on the PAN for PBF to work. I imagine this is a common scenario. Any ideas? TIA.

URL block page: import file error

Hello,Im using a pa 4020 and i want to custom the blocking pages. Im trying with the URL block page but when i import the file is an error saying:Error in parsing xml response.Is something missing in my txt file? i will appreciate any suggestions?thanksSimon

Default zone protection behaviour

Hi all,Here is a small question regarding zone protection profile :smileycool:What happens if we do not define any zone protection profile to a specific zone ? Is the default behaviour to allow all types of potential threaths ( ICMP flood, fragmentation and so on ... ) or to deny them ?Thanks for your help.

bdaussin by L0 Member
  • 4518 Views
  • 5 replies
  • 0 Likes

Resolved! i'd like to change current device owner.

Hello allI’d like to change the registered device under my account to Customer Company’s account. Korea branch of Company A has introduced PA4020 some time ago. Company A’s APAC HQ (same company with korea branch) located in Singapore already has introduced a PaloAlto F/W and using them. I've registered devices under my account for devices of K...

willstech by L3 Networker
  • 3955 Views
  • 2 replies
  • 0 Likes
  • 24359 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels