General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

GlobalProtect MFA Radius 30sec Timeout

Hello, I want to setup MFA (radius) on palo alto for both the vpn and the admin page. For the admin page i have no problem. However for globalprotect i have a timeout problem. My configuration is : - radius timeout : 120 sec - globalprotect timeout: 120 sec - portal auth profile = ldap - gateway auth profile = radius The problem is that wh...

zakergfx by • L1 Bithead
  • 1656 Views
  • 1 replies
  • 0 Likes

Resolved! FIPS-CC mode default user/password issue

We recently tried switching to FIPS-CC mode but the factory default user/password didn't work. The Admin guide showed the default user/password to be admin/admin even in FIPS-CC mode. We also found a Palo Alto documentation that for FIPS-CC it should be admin/paloalto but that didn't work as well. There was a mention of using the serial number a...

B.Vance by • L1 Bithead
  • 12496 Views
  • 4 replies
  • 0 Likes

VM-300 GP capacity

Hi Team, Total how many users can login at a time through global protect vpn on the VM-300 Palo Alto firewall, i want to check the capacity of user handle by VM-300

PA-5220 Version: 10.2.5 - Unable to commit after adding a VIP

After creating the sub interface ae1.1416 and using the address 10.149.124.98/27, we are receiving the error below after adding the first usable address as the VIP with 10.149.124.97Both palos are in an active/active pair- We are able make the commit without using the VIP - We can use another IP address in the subnet range as the VIP and commits...

R.Smith by • L0 Member
  • 1208 Views
  • 1 replies
  • 0 Likes

Developer Edition

Please forgive my ignorance. I am new to Palo Alto and I am wondering is there a virtual device option for me to use (training, testing, developing)?

DNS Dynamic Updates not working when on Global Protect after update to 10.1

We began a step migration from 9.1.13 to eventually 10.2.2. We usually pause at each major update and make sure everything is working before taking the next jump. I got to 10.1 and hit a roadblock. We have our laptops check in with DNS and do a dynamic update so that DNS has the correct IP when people are bouncing between working in the office...

Walt by • L1 Bithead
  • 3412 Views
  • 2 replies
  • 0 Likes

Ignite 2022 CPE Credits

I saw before I attended Ignite 2022 that we would be eligible for CPE credits for the classes we attended at the conference. Does anyone know how we go about claiming these CPE Credits and getting them applied to our ISC2 account?

CoAAdmin by • L0 Member
  • 5485 Views
  • 7 replies
  • 0 Likes

Resolved! Upgrade to 11.1 from 10.1.11-h5

Hello PaloAlto users! I have to upgrade my PA-820 from 10.1.11-h5 to 11.1 due new features needed. I have purchased my Palo Alto from ebay and is not licensed. I have downloaded the image 11.1 but it´s necesary to update the content version to achieve this update. And when I try to update from a file, this happens... Someone know another ...

Jlsierra_0-1709672963590.png
Jlsierra_1-1709673065218.png
Jlsierra_2-1709673116881.png
Jlsierra by • L1 Bithead
  • 2706 Views
  • 2 replies
  • 0 Likes

Authentication error

users in one the gateway facing the error `please click the button below to relaunch authentication` while try to connect VPN .

How to filter routes being exported to BGP neighbor?

We are currently redistributing all OSPF routes to our BGP neighbor without any filtering. We wish to exclude certain prefixes from BGP advertisement. I need an assistance in configuring the filter for this purpose. Q1. Is it going to be working if I create redistribution profile and apply noRedist_To_BGP profile to BGP-->Redist Rules? Q2...

JasonKu_0-1709226190520.png
JasonKu_2-1709226301733.png
JasonKu_3-1709226491336.png
Jason.Ku by • L1 Bithead
  • 2556 Views
  • 1 replies
  • 0 Likes

Palo alto GP with azure SAML

Hi, I was reading about the integration of Palo Alto GP with Azure SAML authentication. My globalprotect is using port 4433 to access instead of the default 443. Hence, I'm wondering what to configure for the identifier, a reply URL, and a sign-on URL in Azure SSO. Below is how I should set it up in my Azure? So instead of the default 443, i w...

Kevin-Ng by • L2 Linker
  • 1661 Views
  • 1 replies
  • 0 Likes
  • 24463 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels