General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4439 Views
  • 0 replies
  • 0 Likes

Resolved! SNAT for multi WAN IP

Hi All, I have ISP provide 4 public IPs can be use. But I can use 1 public ip to outbound traffic only., if i create another SNAT to 2nd public IP, it can't go out to internet. e.g. Interface IP: 20.1.20.20/29 Not work NAT configuration NAT: DMZ NAT : DMZ Source IP 10.1.10.0/24 to DIPP 20.1.20.21-20.1.20.22 APP SNAT: DMZ2 Source IP : 10....

jthk215 by L0 Member
  • 1850 Views
  • 1 replies
  • 0 Likes

Panorama Policy Push Failed

Hi Team, I am unable to push policy from Panorama to one of the firewalls. Getting the Commit Failed due to below reason. . ssl vpn cert file (CERT_GW) processing failed. (Module: rasmgr). global-protect-gateway tunnel interface (tunnel.1) in vsys (vsys1) parsing failed. (Module: rasmgr). client rasmgr phase 1 failure. Commit failed Please h...

Resolved! Windows update URLs with IP addresses show up as unknown

Hi, we have set our PA-440 (PAN-OS 10.1) to block all unknown URLs, which works amazingly well. However, I am seeing more and more URLs getting blocked which are probably for Windows updates that contain an IP address like 151.139.87.98/phf/c/doc/ph/prod5/msdownload/update/software/defu/2023/12/1024/am_delta_patch_1.403.99.0_ccea2ad383853e202858...

CPE for the Conferences or Summits

Hello, Can anyone help me how to check how many ISC2 CPEs are provided from Palo for the Summit and Conferences (like one we have recently in London Threat Management MicroSummit on 5th Dec-2023? Thank you Regards Hina

Failed to Fetch the Device Certificate

Hi Team, I facing the issue to install the device certificate. I have generated the OTP in CSP. and installed it in the panorama-managed firewall. but we are getting the below error ' Failed to fetch the device certificate.TPM public key match failed. Kindly help to resolve the issue. Please note you are posting a public message where comm...

Packet buffer protection - PA5220 vs PA5410

I've recently upgraded my firewall from a PA-5220 pair to a PA-5410 pair. The firewalls were on the same PanOS version (10.2.4-h2) and with the same configuration. This was the original configuration for PBP at the upgrade time:The 5220 wasn't logging any PBP intervention, as you can see here (there's some sporadic intervention by zone protectio...

Screenshot 2023-06-21 alle 13.32.49.png
Screenshot 2023-06-21 alle 13.14.05.jpg
Screenshot 2023-06-21 alle 13.14.44.jpg
Screenshot 2023-06-21 alle 13.47.53.png

Dual ISP failover - stuck UDP sessions

Hi, I've configured Dual ISP failover using a PBF and everything seems to failover from ISP1 to ISP2 just fine. My issue is after we have failed over to ISP2 and ISP1 comes back online, not all traffic flips back to ISP1. UDP sessions for devices that have a keep alive or heart beat seem to be the most problematic. Currently the SIP/RTP traffi...

PA-3220 after upgrade into 10.2.6

Experience applications flow issue, most of the sessions incomplete (i deleted all active sessions with no resolution), reboot, fail-over several times, no luck. I opened a ticket with Tech support for advance packet flow process analysis no resolution until this moment. The odd is, it is one of HA pair experience this issue Active/Passive setup...

elmgbar by L1 Bithead
  • 2467 Views
  • 5 replies
  • 0 Likes

DH group 15 not supported in phase 1 with IKE v1?

I need to migrate an old firewall to a PA-440 and came across an ancient IPsec where they have used DH group 15 for both phase 1 and 2. According to the docs for PanOS 10.2 DH 15 is now supported but the 440 whines about DH15 in phase 1 as I use IKE v1. DH15 in phase 2 seems OK. (Note: The cryptos are from the original setup, will change to more...

Resolved! License renewal

Please confirm if the expired PaloAlto licenses can be renewed? If “YES”, Please confirm which of the expired PaloAlto licenses can be renewed?

PanOS 11.1.0 Upgrade - Panorama Refuses to Commit or Push on a Multi-VSYS System

Hey Team,Has anyone encountered any problems performing the PanOS 11.1.0 Upgrade? I've encountered the following issue after an upgrade, where PanOS (Panorama) would not commit changes, much less push them to our devices. The configd.log file shows the following: 2023-12-09 16:36:16.778 +1100 DG-push(selective): Waiting for DG file to be writt...

not able to open support case

Hi, When I try to open support case error message coming up saying "Problem Category is missing". Although I select the product as PAN-OS while creating the case. BR, Alaa

aasaggaf by L0 Member
  • 911 Views
  • 1 replies
  • 0 Likes
  • 24374 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels