General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Verify CA root certificate

Hi, Related to the new Emergency Update Required - PAN-OS Root and Default Certificate Expiration After you do the workaround to renew the certificate. Is there any way to check the new validation date for this internal cetificates to check its now correct? thanks

BigPalo by L4 Transporter
  • 3689 Views
  • 4 replies
  • 0 Likes

Resolved! Difference between Summary database vs Detailed logs on Custom Report

Hi everyone, I have a question about what difference between Summary database vs Detailed logs on Custom Report - When we create a report, if we use the Summary database in many of the conditions that we created, We found that when we press Run Now, the data cannot be displayed. But if we use Detailed Logs, the results can be displayed normall...

HA dedicated port inop

I setup active-passive PA-5410 firewalls (brand new) and I can't get the HA ports to communicate. The secondary has activity lights when I plug into a switch, but the other one is completely death. Is it possible that I received a new PA-5410 with a bad HA port from Palo Alto, or how can I check its status (via browser or CLI)? I configured the ...

possible to know what triggered malicious website classification on my website?

I run a small website (www.milkywayidle.com) which is an online game ran directly in the browser. after a few recent updates around 2-3 weeks ago, I saw noticed that https://urlfiltering.paloaltonetworks.com/query/ classified my website as malicious. I requested reclassify and it quickly classified to "game". However around the same time many us...

DUAL ISP IPSEC TUNNEL ECMP

Hi, FirewallDUAL ISPISP1 ETH1/1 IPSEC TUNNEL 1ISP1 ETH1/2 IPSEC TUNNEL 2 ECMP Method HASH I have ECMP enabled with DUAL ISP with two IPSEC tunnels going to another firewall with one ISP. What I am seeing is sometimes is IPSEC tunnel from Eth1/1 to the other firewall going over Eth1/2. How do I prevent this?Thanks

junior_r by L3 Networker
  • 7093 Views
  • 3 replies
  • 0 Likes

Security Policy

hello we have taken over support of a PA there are a number of entries configured under the Security policy our customer has reported an issue that we are trying to troubleshoot can I use packet trace or packet capture to see what policy an IP Address is using ?

Change panorama mode from "management-only" to panorama-mode

Hi, We have a panorama (version 10.1.6) in management-only mode. This panorama is maging 6 FWs. We would like to change the mode to panorama in order to get the logs. So what implications should keep in mind? i think it should be necessary to increase add a new disk with high space in Vmware? Its that correct? what is the recommendation about...

SIZE.JPG
BigPalo by L4 Transporter
  • 11665 Views
  • 7 replies
  • 0 Likes

FW wrongfully declared as a spare

Hello, One of my FW is wrongfully declared as a spare and thus I can't update it without transferring licences from another FW. It seems that I can't chage this property on my managing asstets page. Can anyone help. ? Regards

PA440 management interface doesn't take configuration

I used to think I knew how to do this stuff, but apparently not. This is an out of the box configuration of a PA440 - I set the firewall to configure system in standard mode and use static addressing. Initial configset deviceconfig system ip-address 192.168.1.1set deviceconfig system netmask 255.255.255.0set deviceconfig system update-server up...

Resolved! PAN-OS Certificate exprie and panorama

Currently, Panorama and the firewall are connected. However, the connection will be disconnected in April 2024. Even if the connection is lost, is it possible to connect through syslog?

qmso475_2-1706166397204.png
qmso475 by L3 Networker
  • 1884 Views
  • 1 replies
  • 1 Likes

Resolved! Force user GlobalProtect client refresh

Piggy backing off of this earlier thread (LIVEcommunity - Force GlobalProtect Portal refresh of connected clients? - LIVEcommunity - 514881 (paloaltonetworks.com)). It there a way whether by registry or whatever, to force the client to grab its new config. We are switching over from on-demand to always-on and want to have users connect without t...

Claw4609 by L5 Sessionator
  • 11353 Views
  • 10 replies
  • 0 Likes

Resolved! API call fortmat

Hello, I want to know, what is the issue with this API call?<request><content><upgrade><install><sync-to-peer>yes</sync-to-peer><version><lastest></lastest></version></install></upgrade></content></request> I would like to sync the content update by API call...

RobertoParra_0-1705959598802.png
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels