General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4455 Views
  • 0 replies
  • 0 Likes

URL Category rule works on some firewalls but not others

We are using a rule to permit traffic for Cisco licensing using URL Categories. The rule is applied via template, so all of the firewalls get the same rule. The only variable is the source IP/host. This rule works on most of the firewalls (all are PA850) but fails on some. The traffic does not match the rule and is blocked by the default rule.

jwill2 by L2 Linker
  • 1636 Views
  • 3 replies
  • 0 Likes

PA-220s randomly crashing

We are having a large number of our PA-220s randomly crashing. No critical system logs are see shortly before the crash, the device just goes down and they are logs of dataplane starting up like 30 minutes later. Our other models are fine, its only the 220s we are having issues with. We have had a critical TAC ticket for the last few days and it...

Claw4609 by L5 Sessionator
  • 5518 Views
  • 9 replies
  • 0 Likes

Need help! Specific subnet cannot access my internal resource

Hi Team, I just need an advise. I have this setup as attached but I have this mystery that's been bugging me for days now. There is only one subnet which cannot access my internal resource. I ran the filter and global counter and there are specific counters I noticed. Can someone enlighten me on this? Regards, Renz

renzanjo11_0-1701938769587.png

Resolved! PAN_OS 10.0.0 upgrade issue

i am going to upgrade pan-os from 9.1.14-h4—>10.0.0–>10.0.11-h1–>10.1.0–>10.1.6-h6 for my pa 3260 device.But when the Pan-os upgraded to 10.0.0, i waited for two hours and the global protect client can connect the portal and gateway, but it can't access any network include Paloalto host ip, internal network and external network. i...

Resolved! Layer 3 between 2 buildings

Hi everyone, I have 2 buildings; they are about 40 miles apart. I'd like to set up a layer 3 connection (OSPF) between 2 buildings. The fiber connection is provided by the ISP and is ready. I have a couple of questions: Is it a good practice to use virtual wire ports between 2 routers A and B for layer 3? We own all the equipment but not th...

tinhnho_0-1701963726227.png
tinhnho by L3 Networker
  • 2499 Views
  • 3 replies
  • 0 Likes

Resolved! DNS setup best practice

Hi All , I am planning to use FQDN based address for security policy . Any best practice to follow . As we have concern related to FQDN dns cache on firewall . And if we are connecting to cloud ( using hybrid setup) any specific recommendation for that as well . Thanks

deepak12 by L3 Networker
  • 7338 Views
  • 6 replies
  • 0 Likes

Concurrent Policy Installation

Could someone help me from which PAN-OS version can we do Concurrent Policy installation ? For example : Admin A and Admin B can push 2 different Access Policy to 2 different Clusters ?

Imposter by L0 Member
  • 1401 Views
  • 2 replies
  • 0 Likes

PAN HA with different SFPs

Hi Guys quick question.. planning a pair of PA 5420's in HA - the plan was for each to have a 40gb QSFP+ module. however on our secondary core switch we are unable to source a 40gb sfp in time. So.. as a temp solution, will HA work if we have a 40GB QSFP+ module on FW1 connecting to 40GB sfp on Core1 and a 10GB SFP on the FW2 connecting to 10g...

PA_nts by L4 Transporter
  • 2120 Views
  • 3 replies
  • 0 Likes

Remove Domain Name from LDAP user mapping IMPOSIBLE =(

Hi Someone know if there is a way to remove the domain name from the group mapping The reason why is because i get from external source on palo alto the user id test1 or "test2" or "test3" Goal is create a policy rule base on the source user that is being part of a domain group In my case LDAP group mapping get this information: show u...

Threat Logs not showing specific source IP Address

Hello everyone! Just have an issue that I can't seem to figure out. In our threat logs, we are noticing that the source address shows the default gateway address rather than a specified address. We will get a specific address, however more often then not, we see the default gateway address. Any idea how we would be able to consistently see...

Resolved! Software NGFW Credits renewal

Would anyone have any idea why the portal would show Renewal Confirmed but the dashboard does not seem to be updating? Do I need to wait? Still not showing updated:

Schneur_Feldman_0-1694558046673.png
Schneur_Feldman_1-1694558135175.png
Schneur_Feldman_2-1694558159143.png

Modified XML API for Top Users last 30days

Hi Support, We want to get top all users for last 30 days using XML API, how we get it? This is XML API to get top 10 users (Worked😞 <type><panorama-trsum><sortby>sessions</sortby><group-by>srcuser</group-by><aggregate-by><member>src</member><member>app</member></aggregat...

Security policy with sources on a CDN or domains with wildcard

Hello to all, I would like to know how smart PAN admins would solve this problem: suppose you have to allow inbound traffic from a source address that is: - defined as a FQDN but you know from DNS that it is delivered via a CDN like cloudflare, akamai, etc or - defined as a domain with a wildcard, for example *.letsencrypt.org I know that: - I...

TonyP by L0 Member
  • 2675 Views
  • 1 replies
  • 0 Likes
  • 24377 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels