General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Gateway FQDNs Equivalent in Panorama managed SASE solution

Hi All, I need to add additional gateways for Global Protect users in different locations. After adding how to check the newly added Gateway FQDNs in the Panorama managed Prisma SASE? Because i need those FQDNs to be added in Azure as Identity Provider URL for MFA. But i dont see that option in Panorama. But if it is managed directly from sase p...

PA 440 MGMT Interface and Regular Interface

Good afternoon all, I am very new to this field and I wanted to acquire some knowledge or perhaps a better explaination. Looking at all of these videos online I think some basic fundamentals are missing in terms of real world scenarios; and not so much made up topologies. SO, I am looking at my home network as a real world example. The PA...

Secondary IP and DHCP

Greetings,Say we have an interface that is configred the following way:e1/2.240Tag: 240IPv4 Address (two addresses on the interface):-10.10.100.1/24-192.168.100.1/24Now, if that interface is configured as a DHCP relay, which network is it going to send in the relay request?

mrsold by Not applicable
  • 13495 Views
  • 9 replies
  • 0 Likes

PA 850

hello we have deployed a HA 850 series cluster we have users complaining about problems with: voice quality on MS Teams screen freezes video & audio out of sync Q is there a configuration I should use to optimise the MS Teams network performance ? Q are there any logs /packet captures I should run to try and identify the issue ? thanks

Resolved! Understanding some counters from pow performance during high CPU troubleshooting

Hi all, I was troubleshooting one of our customers pa 5220 high CPU utilization based on this KB article: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmV2CAK It gives a pretty good explanation of how to interpret these outputs to determine what is utilizing CPU. So I found and calculated the most used processe...

{"status":500,"timestamp"

i am trying to register a new account to register a product... getting an error message {"status":500,"timestamp":"2024-01-14T16:30:48.473895602Z"}

Resolved! PA 220 Dataplane restart automatically.

Hi Team, We have noticed that our PA 220 device data plane has been restarted automatically. Pan OS: 10.0.6 Please find the logs below, 2021-09-24 10:36:23.126 +0530 INFO: flow_ctrl_pktlog_forwarding: exited, Core: False, Exit code: 02021-09-24 10:36:23.290 +0530 INFO: flow_mgmt: exited, Core: False, Exit code: 02021-09-24 10:36:23.487 +0530 INF...

VishnuPS by L3 Networker
  • 9776 Views
  • 8 replies
  • 0 Likes

ARP refresh in firewall if replacing the connected device

we are changing the core device hardware connected to Palo alto firewall inside interface. To minimize downtime we will be moving inside interface of secondary passive firewall to new secondary core and then we will make it active by suspending primary firewall. Is there any ARP issue or delay in arp refresh on Secondary firewall as we will live...

Deepak25 by L3 Networker
  • 1556 Views
  • 1 replies
  • 0 Likes

Resolved! Features column in Network Interface shows an IPSec Gateway

I have a HA pair of PA 5220s at the HQ location and a PA-850 at a secondary DR location. We have about 100 remote sites that have a primary Site-to-Site VPN connection to HQ and a secondary connection to the DR location. Each of which have their own IKE Gateway configuration. I've just noticed that when I look at the Network/Interfaces/Ethernet ...

Impact of license expiry

I need the impact below license expiry. This is not in terms of any OS version. This is a gen query. -SD WAN License -BrightCloud URL Filtering -GlobalProtect Portal -GlobalProtect Gateway I intend to get the below bullets:- -What one can still do, -What one can no longer do,

description contains 'Failed to connect to address: x.x.x.x port: 3978, conn id: triallr-x.x.x.x-x.x.x.x' )

ipsec vpn, global protect is not set. 34.122.191.141 > google address 200.200.200.200 > loopback address I found a Cortex logging service error, but I don't know how to solve it in detail. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POOtCAO I want to turn off the corresponding log.

qmso475_0-1705371110137.png
qmso475 by L3 Networker
  • 2095 Views
  • 1 replies
  • 0 Likes

PBF Rules being ignored

I have setup several PBFs to force traffic to use a specific egress interface for monitoring that particular path. I then setup a ping monitor on one of the servers, Source Address 192.168.200.15, to ping several different Destination Addresses (DA). The SA is the same for each 'monitor' but the DA is different. The PBF is then setup to forwa...

rmcrae by L3 Networker
  • 4458 Views
  • 3 replies
  • 0 Likes

Resolved! Confused about HA Path Monitoring recovery (Preemptive loop)

Hello,So this is a document: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClhJCASWhich states:When a link or path monitoring (or both) failure condition is detected by the HA daemon on the Active device, it moves in non-functional state.When the monitoring state is restored, the non-functional nodes moves into passiv...

  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels