General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1914 Views
  • 0 replies
  • 0 Likes

Pre go-live Health checks for auto deployed VMs in AWS

Not sure how to post in the automation section anymore as it now has been moved to read only.

 

Anyways.. need some insight please.

so we recently did a POC to use Terrarorm to autoscale / deploy VMs in AWS cloud. all good and working.

However we nee

...

PA_nts by L4 Transporter
  • 1132 Views
  • 2 replies
  • 0 Likes

Resolved! Why cant a URL be used directly in a policy?

Hi, 

I understand that to block an individual URL it has to be in a custom category before it can be used in a policy as a destination. For my own education and curiosity, my question is why must it be in a category? What is the processing logic in th

...

ABurger by L0 Member
  • 1482 Views
  • 2 replies
  • 0 Likes

HA mode with vwire

Not sure it this is the right location for this question but here we go ...
I'm trying to replace 2 transparent ASA's in ACT/STDBY with 2 Palo's in the same setup vwire ACT/PAS. Current setup is the asa's are connected to 2 vpn servers in ACT/PAS conf

...

Chromebook usernames in Palo Alto logs.

Hi,

I was wanting to know if it is now possible to have the Palo Alto firewall log url traffic with the username from chromebooks.  It shows the username for all windows users as it syncs with AD, but can't get the chromebook users to show up.  I set

...

dholmes by L0 Member
  • 2365 Views
  • 3 replies
  • 0 Likes

VPN event messages keep receiving

Hi,

I have two IPSec tunnel configured between Azure PA firewall and cisco router.

worried about continuously getting the informational event logs ikev2-nego-child-sart,  ikev2-nego-child-fail & ikev2-recv-p2-delete

Did the setting DH group to No PFS

...

VirupakshaRajapur_0-1691068863263.png

PA-5400, 3400 series DP memory check

Dear Team,

 

For existing firewall models, I can check the DP's memory through the 'tail follow yes dp-log dp-monitor.log' command.

 

However, new devices(PA-3400, PA-5400) do not have a dp-log path itself.

 

Is there a way to check dp memory on new

...

Resolved! Ha config not in sync

Hi Guys.

I have a Palo 220 in HA A/P managed by the panorama.

The customer made mgmt IP change and Added a Zone but then ever since the config is out of Sync Between the HA pairs.

So all the articles are referenced, request high-availability sync-to-

...

Pras by L4 Transporter
  • 3527 Views
  • 4 replies
  • 0 Likes

HSCI Link flapping

Hey all, I had to RMA one of my PA-3220s and rebuilt my HA just recently. After getting everything up to 9.1.11-h3 my HSCI link just doesn't stay up between the two 3220s. One side has green HSCI links, but the other side is dark.

 

-Replaced fiber j

...

DNS Sink Hole Data Base

Hello Gentlemen,

 

Could you please tell me where I can locate the DNS SinkHole database? I need to use it to determine whether a specific website is operating properly. Any suggestions on where I could look for that? Under DNS Sinkhole activities, a

...

Code On Firewall Not Mine

Hello,

 

I ran a config audit today and found some uncommitted code that was not mine. Is it possible that a dynamic update had some uncommitted code in the config?

Thanks

MJF

  • 24193 Posts
  • 117 Subscriptions
Top Liked Authors
Labels