General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4105 Views
  • 0 replies
  • 0 Likes

Cluster FW Active-Pasive syncronize certificate profile 10.1.9-h1

Hello team I am deploying web auth with certificate https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/manage-firewall-administrators/configure-administrative-accounts-and-authentication/configure-certificate-based-administrator-authentication-to-the-web-interface in an active - passive cluster, the problem is th...

Alpalo by L4 Transporter
  • 891 Views
  • 1 replies
  • 0 Likes

Resolved! Firmware hotfix releases

I currently run 9.1.16 on our 3000 series firewalls. I need to upgrade to 9.1.16-H3 to resolve the cert expiry issue. Are the H releases cumulative? Or do I need to install H1, H2, H3? Will this require a reboot? Or as the term 'hotfix' implies, will it install on a live firewall? We run the firewalls as an Active/Passive pair.

Resolved! Upgrade path from 9.1.x to 10.2

HI everyone, I want to upgrade all my PA220, so I would follow the upgrade PATH from 9.1 to 10.2 but, I don't find what is the actual 10.0 preferred version ? After upgrading to the last 10.2, the certificate issue will be solved ? Regards

vlgm75 by L0 Member
  • 2412 Views
  • 2 replies
  • 0 Likes

Resolved! Net-flow configuration for PA firewall

Hi , We like to know net-flow configure for Palo Alto firewall. We notice the NetFlow traffic to our NetFlow server are inconsistence. What we need to find out are as below : Will the Firewall cache the Netflow data? How frequent is the Netflow data transferred and the interval timing the packet are send out? Thank you

PanOS sdwan and PanOS versions

We are looking to upgrade our 9 firewalls PanOS version before December 31st. We have Panorama and are using PanOS SDWAN. Do the PanOS versions on the firewalls all need to match or can we update a couple a night and have SD-WAN still work. Or do we have to upgrade all 9 of the firewalls in a single night?

Resolved! Disk status 5220

Hello, I just noticed that it seems like one of the disks is failed, am I correct? Even though RAID Status is Good and both disks are detected and visible, those records in bold make me worry admin@SWA-5220-OCC-B(active)> show system raid detail Overall System Drives RAID status Good----------------------------------------------------------...

Portal Password

I was just setup with user ID to and temp password to access the portal. How do I change the temp password?

Resolved! NTP Server for internal network

Hi, Is it possible to configure a PA-3220 firewall to work as NTP server for my internal network devices? In this scenario the firewall would synchronize with an external source and would be used by the internal devices as a NTP server. Thanks!

Borala by L0 Member
  • 12066 Views
  • 3 replies
  • 1 Likes

GRPC status UNAVAILABLE in intelligent offload

Hi All, Has anyone else come across an issue where a process called 'pan_grpcd' is using upwards of 85% of the CPU on a PA-VM. The VM is running version 11.0.2 and i can see an error in the system logs - 'GRPC status UNAVAILABLE in intelligent offload' I have logged this with TAC however they seem to be at a dead end currently.

ElliotM by L2 Linker
  • 2662 Views
  • 4 replies
  • 0 Likes

Need to create firewall policy that allows only Microsoft teams and rest all need to block

Hi Friends, I would like to create Palo Alto configuration for specific range of IP address, not based on users.My requirement is as follow.1. Only Microsoft teams traffic (incoming and outgoing includes calls) should be allowed.2. Want to block all other traffic includes web browsing, file sharing, social media, media streaming. Anyone can sugg...

Asynchronous Security Zones?

Is there an issue with asynchronous routing if the traffic passes through different security zones? We have our PAs setup with subinterfaces for our respective VLANs. So we have:Eth1/3.10 Eth1/3.20 Eth1/3.30 Eth1/3.40 These subinterfaces connect to a trunk port on an Aruba 6300. The 6300 just has a default route configured which points to to t...

Resolved! How do we config a basic setup for guest wifi app blocking

We are relatively new to Palo Alto detailed configs, although we have used url filtering, av filtering, etc for some time. We want to start doing a better job blocking at the application level on our guest wifi, especially in the areas of peer-to-peer, etc. Are there some basic guidelines or configuration guides on how to get started. Baselin...

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels