General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

User ID Agent all DCs in connecting (Access is denied) status after migrating from Win 2012 to Win 2019 Server

Hi all We have installed 10.2 version of UIA in new win 2019 server as our 2012 server would be shutdown soon. The problem is after configuring all the required permissions the agent status overall is connected, but on all our ADs listed in UIA, the status is stuck at connecting and after sometimes we get Access is Denied status as well. The s...

JamshedDayar_1-1704692360221.png

Resolved! How to compare configuration btw PA firewall.

Dear Team, I recently backed up and restored the configuration of the existing Palo Alto firewall to a new model. My question is: how do I compare the configuration on a new firewall and my existing device, or does PA have any useful tools for the comparison? Thanks!

Resolved! No AV updates, 'Virus updates are available but you must first update threat content'

New 1410 appliance running v11.0 -> 11.0.2-h2. Fully licensed, latest content update installed yet no AV updates are available and the following message appears in system logs (in both .0 and h2): Retrieving Content 'Antivirus' info failed with error 'Virus updates are available but you must first update threat content'. We suspect this w...

mb_equate_0-1704874707896.png
mb_equate_1-1704874792720.png
mb_equate_2-1704874854746.png
mb_equate by L3 Networker
  • 7670 Views
  • 1 replies
  • 0 Likes

Resolved! PA-440 with partial working GUI (PAN-OS 11.1

Hey all, I've got 2 PA-440s at a customer in an Active-Passive HA Cluster. These firewalls have replaced the older PA-220s that were previously present. Traffic and everything flows as intended and all of the firewall rules are also working as intended. The issue that I'm running into is that part of the GUI works. The first 3 tabs (Dashboar...

Resolved! HIP Objects - matching multiple OS versions in one object

Hi All, Within PAN-OS (10.1.x) Using GP, I want to setup one HIP object to match for multiple OS versions for instance Windows 10 and upwards. But does not seem to be doable instead i can only select each version within a specific OS range. I want to avoid having to create an object for each version of Windows10 and 11 and wondering if there is ...

PA_nts by L4 Transporter
  • 5383 Views
  • 3 replies
  • 0 Likes

PAN-OS 11.0 Explicit proxy with no authentication

Hello, may it be possible to use explicit proxy feature in PAN-OS 11.0 with no authentication and allow access for all users? The documentation is very limited in this area and describes SAML or Kerberos authentication only. Thanks Lumir

itsnoc by L1 Bithead
  • 6139 Views
  • 7 replies
  • 0 Likes

Resolved! Some CVE Not Present In PA NGFW

Dear Team, I hope all of you are doing well. I have some CVE IDs from my Tie 1 firewall, which is Check Point. I have checked all of those CVEs in the Palo Alto firewall, and most of them weren't available. Could someone explain or advise me on the reason? Best Regards!

Unexpected change by user __cloud_services - Anyone else get this today?

We use Panorama to manage Prisma access and have alerts configured for config changes. Today got an alert of a commit from user __cloud_services, from the loop back IP 127.0.0.1 I assumed I would look up this user in google and see that it's a service account used by the prisma access plugin for when changes are deployed but didn't find anythin...

Screenshot 2024-01-09 at 19.36.01.png
jbusby by L1 Bithead
  • 2803 Views
  • 2 replies
  • 0 Likes

version recomendada de PA-445

donde puedo verificar la version recomendada de actualizaccion de software para firewall pa-445, en tratado de ver en esta direccion :https://live.paloaltonetworks.com/t5/customer-resources/support-pan-os-software-release-guidance/ta-p/258304 pero resulta que no estoy autorizado, me podria ayudar por favor la version recomendada para este fir...

PA-3420 will not detect SFPs on any port

My backup PA-3420 in an HA peer will not detect SFPs or link on any port (including copper) but the management. The primary unit detects and links on multiple SFP slots with multiple different SFP types and brands. The same SFPs in the backup unit will not detect. adrian.admin@PA_CorpEdge_A(active)> show system state | match sys.s1.p13.capa...

Resolved! Can not check Forward Trust Certificate

Hello. I'm having an issue with a setup of decryption. we have a custoemr who wants decryption. and they also have an entreprise CA. to have the least user impact they wanted to use an entreprise signed certificate for their ssl forward trust. I created a certificate as explained on palo alto resourceshttps://knowledgebase.paloaltonetworks.com/K...

PA-3420 sudden restart issue

Hi all, One of our clients has a PA-3420 HA-pair device with an active-passive setup, one day they noticed that their firewall went to reboot. Upon checking there are no signs on the system logs that encountered power interruption or hardware failures, we checked on using PANTS and the Auto assistant tool, but we did not find any event that poin...

Daryl_Cruz_0-1704781577308.png

Resolved! Palo PA-415 on High-availability but Wireless access points only have 1 network port.

So I have a very small site and PA-415 seems like a idea firewall to that, but we have a company policy which we have to have a HA on a firewall. I'm trying to not to use a switch given that PA-415 have a 8 poe ports. issues APs we use only have 1 ethernet port. Is there a way to do HA on this scenario. I'm trying to get an AP with 2 network ...

din100 by L3 Networker
  • 3671 Views
  • 2 replies
  • 0 Likes
  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels