Resolved! Need to re-open closed case
Hello everyone I had an old case that was closed already. I need to re-open it. Can you please guide me?
Hello everyone I had an old case that was closed already. I need to re-open it. Can you please guide me?
donde puedo verificar la version recomendada de actualizaccion de software para firewall pa-445, en tratado de ver en esta direccion :https://live.paloaltonetworks.com/t5/customer-resources/support-pan-os-software-release-guidance/ta-p/258304 pero resulta que no estoy autorizado, me podria ayudar por favor la version recomendada para este fir...
My backup PA-3420 in an HA peer will not detect SFPs or link on any port (including copper) but the management. The primary unit detects and links on multiple SFP slots with multiple different SFP types and brands. The same SFPs in the backup unit will not detect. adrian.admin@PA_CorpEdge_A(active)> show system state | match sys.s1.p13.capa...
Hello. I'm having an issue with a setup of decryption. we have a custoemr who wants decryption. and they also have an entreprise CA. to have the least user impact they wanted to use an entreprise signed certificate for their ssl forward trust. I created a certificate as explained on palo alto resourceshttps://knowledgebase.paloaltonetworks.com/K...
Hi all, One of our clients has a PA-3420 HA-pair device with an active-passive setup, one day they noticed that their firewall went to reboot. Upon checking there are no signs on the system logs that encountered power interruption or hardware failures, we checked on using PANTS and the Auto assistant tool, but we did not find any event that poin...
So I have a very small site and PA-415 seems like a idea firewall to that, but we have a company policy which we have to have a HA on a firewall. I'm trying to not to use a switch given that PA-415 have a 8 poe ports. issues APs we use only have 1 ethernet port. Is there a way to do HA on this scenario. I'm trying to get an AP with 2 network ...
In PA-3220, are HA logs enabled by default? Does these logs contain the reason for transition between HA primary and secondary?
Hi All, Did a replacement of a PA FW 5260 (pan-os 10.1.x) with a 5420 (pan-os 10.2.7) everything is working as expected.. however not able to view any botnet reports. botnet config in place under monitor\botnet\configuration. licenses are in place and updates up to date. in URL logs i can see logs for malware categories and blocked as expected. ...
Hi, We have recently come across an interesting issue between a Cisco ASA ikev2 tunnel with a PA. If I was to failover the PA to an HA peer, traffic initiated from the Cisco ASA continues to flow whilst traffic initiating from the PA stops. I noticed when the PA fails over the ASA drops both phases and recreates them with a new SPI value whilst ...
Hi All, I think most of you had experienced this failure issue once in your worklife 🙂 🙂This error reason is mostly because config memory usage is too high.>debug dataplane show cfg-memstat statisticsAs we all know the number of custom url is limited and we will likely face this commit issue after this limit exceed. But we can not be aware...
Customer have configured OSPF peering with firewall and switches. Have multiple OSPF peering with different ZONEs via each sub interfaces. Currently we are receiving around 4k routes at DCE-ES for each peering. Since ES switch hardware not supporting that much routing entries, we need to do summarization for those routes. Need to know how to do ...
Hello, I have a problem with a DNS resolution, in some users with the GP agent 5.2.10-6 we can reach a resource for example vmare.x.x, but with other users.There are several important points here:All users have the same version of the global protect agent.To reach the vware resource, the user connects to the VPN that is located on vsys 1 and goe...
Hi There, I'm trying to upgrade a firewall from PanOS 8 to 10, and I want to skip the intermediate versions. The firewall is not in production. Is there any way I can boot the firewall directly to version 10? I appreciate any help you can provide.
Hi Folks, i like to try the new opportunity from Palo Alto to test the PAN VM for 30days. But for me it seems that this is the standard VM without any license.So here we go:https://www.paloaltonetworks.com/vm-series-trialSounds for me like a full featured PAN VM to try all the nice things.I tried to ESX and QEMU Images. At both versions i stuck ...
We currently run a pair of Palo Alto 5220's and are in the planning process for moving the VPN services from our Pulse Secure (Ivanti) appliances over to the PA and using Global Protect. On the Pulse appliance, there is an option to allow users to login to a web interface for controlled access to some internal resources if there is no VPN option...
| User | Count |
|---|---|
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
| User | Likes Count |
|---|---|
| 8 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |

