General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 409 Views
  • 0 replies
  • 2 Likes

Resolved! Error in commit after upgrade to 10.1.5-h1

After upgrade from a PA850 from 10.1.5 to 10.1.5-h1 in the end of last week we no longer can commit new configs 

It gives the following error when we try to commit.

  • Validation Error:
  • rulebase -> security -> rules -> Block xxx -> hip-profiles unexpected
...

Upgrading PAN-OS active/passive question

I have 2 firewalls in active/passive mode. Am I able to upgrade one of the PAN's and leave the other in standby or passive mode for a few days while I ensure there are no issues before upgrading the second PAN? It is a jump bigger than 2 versions so

...

AnthonyT by L1 Bithead
  • 3033 Views
  • 8 replies
  • 0 Likes

Global Protect

Entered the credentials, got the push. Gp is showing connecting and after 2 sec showing not connected and minimizes the agent. Exactly after 5 sec agent pops up.. Started spinning and gets connected.(Without asking for credential and push mfa)

Versio

...

OOM-Killer on 8.1 Trail (PA-5050 device)

Hi,

 

i know this is about old software on old hardware, but both are still supported by Palo Alto. In the last months we get a heavy amount of OOM Message / Stack Traces / you name it.

Actually we arent able to push new config changes from Panorama

...

Inquiry about API key

In order to receive the Palo Alto Firewall api key
I checked " curl -k -X GET 'https://<fw-ip>/api/?type=keygen&user=<id>&password=<password>' " in the docs
but where is this command have to enter it?

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os

...

qmso475 by L3 Networker
  • 1390 Views
  • 2 replies
  • 0 Likes

Count Palo Alto Memory Usage

Hello All,

I want to ask about memory on PA-850 and PA-3410.

i use the calculation "Free Memory/Total Memory = xxx %" and the rest i assume is the used memory

 

 

but when i see the memory utilization on PA-3410 its only have 210MB for free memory. 

...

DennyChanditya_0-1679285413162.png
DennyChanditya_1-1679285850004.png

mdns forwarding between vlans no option

hi guys

 

how can I enable mdns forwarding between l3 vlans (my ports are essentially  l2 bridges into groups with l3 vlan interfaces having ips and running dchp servers)

 

it seem like bonjur forwarding can only be enabled on physical l3 and not l3

...

nevolex by L3 Networker
  • 1590 Views
  • 1 replies
  • 0 Likes

Resolved! UserID Agent 11.0 on Windows Server 2022

Hi all, i wanted to know if there are any issue identified on installing the user-id agent 11.0 on windows server 2022.

I have tried it on a server 2022 and there aren't any problem . Wanted to be sure about it and to not have problems in case of a s

...

Leobute by L0 Member
  • 2126 Views
  • 1 replies
  • 0 Likes

Collecting customer deployment information

Given I am a newbie to Palo, I am running through the PSE Strata Associate training and have seen this statement (or something like it) many times : using intelligence generated across many thousands of customer deployments. 

 

This prompts a few que

...

shodgdon by L0 Member
  • 1155 Views
  • 1 replies
  • 0 Likes

IKE phase 1 not working

I'm trying to setup a site-to-site VPN between Palo 820 and a Cisco ASA.

 

I've checked the configs and both are matching OK with correct PSK. I've configured the proxy IDs accordingly. I don't have access to the Cisco ASA as this is on the customer

...

  • 23695 Posts
  • 110 Subscriptions
Top Solution Authors
Labels