General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Global Protect need to ask for password all time we connect

Hi, We have configured GP with CISCO DUO. If i connect in a fisrt moment to GP is successfull. But if i disconnect and connect again the credentials are not being asked. Its like there is a cache that GP is saving my credentials and DFA for a momento. How can i configure that always i connect to GP the password is asked and DFA. If its possibl...

BigPalo by L4 Transporter
  • 4875 Views
  • 5 replies
  • 0 Likes

Resolved! PAN-OS 10.1.9 -- CAUTION

I would highly recommend waiting on deploying 10.1.9 in your enviornment, whether it be large enterprise or SOHO. Recently my company had upgraded a 5250 pair from 10.1.8 to 10.1.9 as we had experienced 2 service impacting bugs. After upgrading 10.1.9 we found that the FW was exhibiting odd behavior where traffic which had specific allow rul...

cli "show" match case insensitive and pipe

when we using cli in PAN to search something like "show | match 'string'", can it search string case-insensitively and also is that possible to pipe to another match? I suspect both answers are no, happy to know if there are some workaround.

nowayout by L1 Bithead
  • 1766 Views
  • 1 replies
  • 1 Likes

DNS Security cloud query timeout.

Hi Support, Good day, i have concern about this system alert DNS Security cloud query timeout. Not sure what to check as if this is normal alert? The dns security cloud connection seems good. attach the screenshot alert message and dns security connection Kindly please advise Thank you

Resolved! WildFire and File blocking

Hi Experts, I'm new to Palo Alto and I've seen documents where File blocking is used in addition with the WildFire analysis. So, any files which is blocked won't be forwarded to WildFire and the action which is set to 'continue/alert' will be continue forwarding. But in my organization I've seen file blocking isn't applied to any security policy...

NAT Sanity Check

Hi Can I sanity check a NAT rule please. We have a small satellite office with a PA as the firewall. We only have /30 subnet so one IP for the router and one for the IP of the external NIC on the PA. We need to have a connection for a service to a telephone system that comes from external to the telephone. So because of the IP limitation n...

Global Protect internal host detection is not working, when user is in branch office connected via to site to site vpn.

Case:Global Protect VPN is enabled in HO PA220.BO also have PA220, HO and BO connected over site-to-site vpn, If user is connected to HO LAN, internal host detection works and identify it as Internal corporate network. And if user is connected to BO LAN, it just connects to GP VPN even though site to site vpn is active and internal host detectio...

Transferring PA (already registered) license to other PA (already registered) device

How do I transfer one of my PA-220 license which is already registered to other PA-220 registered as well ? I might be able to do that if I can make one available in spare and then move my already registered PA-220 license to the spare device. Appreciate if you can write down steps and paste some screenshots. Thanks

Resolved! 303184

I need help I ordered my voucher on Palo Alto Market since 10/11/2023 and I received it I have not yet had the exam in my Palo Pearson view account I have written to Pearson several times view which sends me to palo alotstore which never replies to my emails can anyone help me

Resolved! Unable to authenticate against ISE when using External ID Source

So I have an interesting issue. I have a Cisco ISE server in our environment doing TACACS+ authentication for all our network devices. ISE is tied to our Active Directory environment, and users in certain OU's are authenticated and authorized based on the AD group they're in. I tried configuring one of our PA-440's to authenticate against the IS...

cullums by L1 Bithead
  • 11131 Views
  • 3 replies
  • 0 Likes

How to allow all the traffic from TLS V1.2 and above on firewall

Hi friends, we have a customer who wants to block TLS version 1.0 and 1.1 and to allow all the traffic from TLS V1.2 and above on firewall. Is there any option on palo alto firewall. Customer requirement is that they need to block it from the interface / port level. customer is doing a scan using a third party app. Can we have any way to mitigat...

PAN-OS 10.1 no Wildfire Submissions logs in WebGUI

Hi, I made upgrade on PA-220 to PAN-OS 10.1.0. After that the Wildfire Submission logs are not loaded in WebGUI. I only see the rotating progress circle in the upper right corner.In CLI the Wildfire logs are visible >show log wildfireOf course I have opened a support case. Just asking if anybody has the same issue and came up with a solution ...

500 Server Error for Miner nodes

Hello all, I am currently receiving error messages on two miners within minemeld regarding the "Last Run" while trying to pull and carve out new IoCs. The message I get when hovering over the error is "500 Server Error: Internal Server Error " Can anyone advise as to how to proceed. I am also running the plugin web-based version of minem...

  • 24411 Posts
  • 125 Subscriptions
Top Solution Authors
Labels