General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1994 Views
  • 0 replies
  • 0 Likes

pan-os-python Panorama set_ha_peers() method not working

The document I'm referring to - https://pan-os-python.readthedocs.io/en/latest/howto.html > High Availability Pairs

 

I've been working with the pan-os-python SDK, specifically with a Panorama High Availability (HA) pair. I'm following the documentat

...

vsurresh by L1 Bithead
  • 1472 Views
  • 1 replies
  • 0 Likes

Resolved! IPV6 how to protect the hosts

Hi everyone, I learn the palo alto firewalls as I configure them.

 

I have a PA firewall with 3 vlans, with management allowed over main vlan.

 

My ISP provided the Ipv6/48 block and I have manage to redistribute it over the networks it works great.

...

nevolex by L3 Networker
  • 1897 Views
  • 1 replies
  • 0 Likes

PA-7000 Series PANOS-10.1

Hello,

 

We have a PA-7050 firewall that we are looking to upgrade from 9.1.15 to 10.1.10-h2. 

 

We are following the upgrade path provided by Palo Alto however when we upgrade to the recommended 10.0 release or the 10.1 release the entire firewall c

...

Owen1 by L0 Member
  • 697 Views
  • 1 replies
  • 0 Likes

Sending logs to SIEM one file per type

I am an administrator of a SIEM, for this I have usually asked the paloalto administrator to send me the logs via Syslog using port 514 to the IP of the server I administer.

 

After informing me that the process has been done, I check a specific rout

...

Error: failed to handle CUSTOM_UPDATE

HEllo,

 

I am using 5220 series firewall in 2 different DC. versions 9.0.9 and 9.1.6. When I commit on both firewalls, I get a custom_update error. After check now the dynamic updates, I commit again and the problem goes away.

Any suggestion,
Thank you K

...

Resolved! Using HA without a virtual mac possible?

Hello,

as the title says: I want to implement an HA active-passive setup on a virtualization platform that doesn't support MAC address changes on the VM side. Therefore, a newly generated virtual MAC is unfortunately not an option.

So, is there a way

...

User-ID with OpenLDAP

Hi,

I'm looking for a guide or guidelines on how to set-up User Identification with OpenLDAP. I've already set-up User-ID with Active Directory for an other customer but I fail to see how this is doable on a non-Windows machine (no PAN agent).

Any help

...

Resolved! Internet and internal network sepration via virtual router

Hello,

 

I am new to Palo Alto. I have basic question. 

 

Traditional setup I worked on my last project was as below,

 

 

VRF on cisco router for 

- Internet -0 bgp

- Production - bgp

- DMZ  - bgp

 

FW connects to all 3 VRF. Route between VRF is via

...

gondolf by L1 Bithead
  • 3184 Views
  • 4 replies
  • 0 Likes

cluster PA-5020 migrating to PA-1410

Hi Experts,

We are migrating from Cluster PA-5020 to PA-1410, I have some queries below if you guys can help me out please.

1. For platform migration(PA-5020 to PA-1410), we can just upload configuration files on the new PA-1410, just recheck physica

...

SNMP response on two interfaces? Possible?

I'm configuring NetFlow on our PA-5200. I'm collecting the data in What's Up Gold.  WUG has a limitations (it appears) that the NetFlow IP that I use for the IP address also has to be respond via SNMP on the same address.  However, the PA-5200 cannot

...

  • 24215 Posts
  • 117 Subscriptions
Top Liked Authors
Labels