General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4117 Views
  • 0 replies
  • 0 Likes

Resolved! SSL VPN- Config ERROR PAN OS 3.1

Hi,I m trying to configure SSL VPN on PAN OS 3.1 and its giving error msg even after submitting all the necessary information.My SETUP Details:-1: SSL VPN using Tunnel Interface ( Newly Created in Trust Zone)2: External Interface IP3: Created Self Signed SSL Inbound Certificate4: Uploaded CA Certificate ( This is new in 3.1) its not mentionde in...

How to find objects and rules using CLI?

Hello,I need to know if there is any method to make research based on ip adresses or groups to find out witch rules are using it on the cli. In other words, how can i use the cli to search policies in witch an ip adresse or a group of ip adresses is used.Regards.

asia by L3 Networker
  • 8743 Views
  • 6 replies
  • 0 Likes

Virtual Wire DMZ - Help Please

Hoping for some clarification on using Virtual Wire to inspect traffic to our DMZ please.Right now the external interface of our PAN has a public IP of 1.2.3.1/24.Its default gateway is another firewall in front of it, it's internal interface has a public IP of 1.2.3.2/24.Both of these interfaces are connected to a switch, and on that switch we ...

Unable to authenticate users on Captive Portal

Hi,We have following issue with our setup:-1: Captive Portal is set for entire network ( 192.168.1.0) and in Active Directory the group ( IT) is choosen which will be filtered or monitored. There are two users ( user1/user2) who are member of this group.Firewall Rule :==============1: Trust to Untrust Source Action...

User Information in Firewall Database Cache

1: Captive Portal is set for entire network ( 192.168.1.0) and in Active Directory the group ( IT) is choosen which will be filtered or monitored. There are two users ( user1/user2) who are member of this group.Firewall Rule :==============1: Trust to Untrust Source Action 1: ( Any known user) Allow...

PA-4000 series and agg/dual links

Hi,I'm looking to upgrade my company firewall (PA-2050) to one of the PA-4000 series to be the internet gateway for all our US sites. Anyone here is using PA-4000 with aggregate links with Cisco switches? I'm thinking to have aggregate links for both Trust and Untrust and also dual path to our two Coreswitchs for redudancy as well. I know the...

akatev by L0 Member
  • 2926 Views
  • 1 replies
  • 0 Likes

UIA / PAN Agent to Firewall Communication

Hello,Looking at the User Identification with PAN-OS 2.1 Tech Note rev00E 03/09, I can read :"The User Identification Agent must have IP connectivity to the firewall management interface.This is true even if the firewall is managed by an inline, Layer 3 interface on the firewall. AllAgent communication to the firewall is sent and received throug...

Why is UIA agent not aging-out entries?

Hello,I'am using the UIA agent 3.1 with AD, and i noticed that the number of mappings is always growing. The netbios probings are disabled. I want to know how the 45 min age-out work, and under what condition it is re-initialised. Seeing the growth of mappings in my case, the age-out seems to be not working.Regards.

asia by L3 Networker
  • 2865 Views
  • 1 replies
  • 0 Likes

Safe search document

Hi, I am trying to download the attachment from here https://live.paloaltonetworks.com/docs/DOC-1399 and it is corrupt. I have tried this on a few different computers and it is always the same corruption. Is it possible to upload this file to the support portal again for download.Regards.

Billy_G by L1 Bithead
  • 2821 Views
  • 2 replies
  • 0 Likes

Extract SSL-VPN Installer 1.1.0

Hello everybody,is it possible to extract the PANInstaller.msi for the 1.1.0 Version,like in the 1.0.2 Version.We want to deploy the clients manually!Kind regardsChristian

indevis by L2 Linker
  • 3149 Views
  • 1 replies
  • 0 Likes

Alarm Led on 3.1

Hello,I've got an upgraded 3.1 PA2020 following a factory-reset and everytime i boot the system, the alarm LED lights red and stays onthere are no errors in the system log and the unit isn't in HA.can you advise whether it;s a critical error and how can we fix that or at least know, what is causing this alarm?thanksVinesh

vinesh by L2 Linker
  • 2353 Views
  • 1 replies
  • 0 Likes

Forcing Safe Image Searches

st1\:*{behavior:url(#ieooui) } /* Style Definitions */ table.MsoNormalTable {mso-style-name:"Table Normal"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-parent:""; mso-padding-alt:0in 5.4pt 0in 5.4pt; mso-para-margin:0in; mso-para-margin-bottom:.0001pt; mso-pagination:widow-orphan; font-siz...

rodrigum by Not applicable
  • 2817 Views
  • 1 replies
  • 0 Likes

Looking for information regarding

Threat ID 12544, I would like to know what are the characteristics for that threat ID located within the Spyware Category. The Item is listed as Win32.Conficker.C p2pAny assistance would be greatly appreciated, since I belive that this is a false positive.Message was edited by: mike (removed link)

jpadro by L0 Member
  • 2759 Views
  • 1 replies
  • 0 Likes

Automated configuration exports

Is there a way to perform a scheduled (weekly) configuration export. I can manually ssh to the device and run: scp export configuration to user@hostnamr:E:/Backup/pabackup from running-config.xml (the problem here is that it asks for a password and it is manual) - what I would like to be able to is have this run automatically every week.

  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels