General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Fetch Device Certificate failure

Hello,

 

I am getting this error (Failed to fetch device certificate.TPM public key match failed.) on a PA460 (11.0.2-h2).

 

I tried multiple solutions without success :

  • This KB https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000
...

Meed by L0 Member
  • 4405 Views
  • 9 replies
  • 0 Likes

Resolved! tcp/dynamic port range

I'm looking for a definitive answer on what port range "tcp/dynamic" and "udp/dynamic" uses. I would figure that it is 49152-65535, but I have not been able to locate anything in documentation or the community to confirm this. 

Exclude www.google.* from decryption

Hello,

are you able to exculde https://www.google.com ; https://www.google.de and other domains from SSL decryption?

Or clients complain about the slow loading of the website when they open Google or try to search something.

Currently i add in a white c

...

Hithead by L4 Transporter
  • 6986 Views
  • 17 replies
  • 0 Likes

High availability Links on different locations

Hi,

we have 2 PA1410 on two different buildings. They act in an active-passive cluster.

On each location is a switch, and the Firewall ist connected with all of its port (ha1a, ha1b, ha2, MGM, Data) to the switch.

The switches are connected though a

...

IT-Esp by L0 Member
  • 782 Views
  • 3 replies
  • 0 Likes

Beaon PCNSE study guide - practise questions

Hi Guys

did one of the  prep exams and had a couple of questions marked wrong.. but not sure they were.. any ideas?

 

Q1

GlobalProtect clientless VPN provides secure remote access to web applications that use which three technologies? (Choose three.)

...

PA_nts by L3 Networker
  • 518 Views
  • 2 replies
  • 0 Likes

Resolved! Install the Cortex XDR Agent Using Msiexec

Hi Team,

 

we need to install the agent using Msiexec, kindly provide the steps, and also, we have followed the below-mentioned command, but we didn't get the expected result. 

 

msiexec /i c:\Windows_agent_8_4_x64.msi /l*v C:\temp\cortexxdrinstall.l

...

Resolved! How could i drop"unknown RADIUS authentication protocol"?

Hi!

Recently we were receiving in our environment alerts of failed authentications from different random IP's and random usernames, i was able to reduce them following the next article: Detecting Brute Force Attack on GlobalProtect Portal Page - Know

...

RTudon_0-1717363128954.png
R.Tudon by L1 Bithead
  • 1091 Views
  • 3 replies
  • 0 Likes

Resolved! Zoom phone custom signature thru: ssl-req-chello-sni

Hi everyone!

 

We are currently moving our phone system to zoom, and we had an issue with the zoom application, some of their traffic its categorized as an incomplete causing that some calls hang out, or don't ring, I made an custom application, usin

...

R.Tudon by L1 Bithead
  • 842 Views
  • 1 replies
  • 0 Likes
  • 24034 Posts
  • 102 Subscriptions
Top Liked Authors
Labels