General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4471 Views
  • 0 replies
  • 0 Likes

Cannot install Applications and Threats : No matching contents package found in panupv2-all-apps

Hi thereI'm new here, just got our first pair or NGFW's. I'm trying to update to the latest PANOS which requires and install of Applications and Threats.How ever when i try to install it i get: Failed to update content with following message: encfilesize is 70541232 No matching contents package found in panupv2-all-apps-8743-8224.eap.tgz exitin...

Reporting URLs and Bytes together?

We are trying to produce a report which summarizes the URLs visited by a specific user along with the total bytes downloaded from each URL.It seems that the bytes are available in the Traffic log, but not the URLs; conversely, the URLs are in the URL log, but not the bytes.Is there some way or producing reports which correlate the various logs?T...

KGC by L3 Networker
  • 5373 Views
  • 5 replies
  • 0 Likes

Resolved! Traffic Loc Collection API

I am calling for traffic logs but only getting the first 20 lines by default as expected but when I add nlogs=1000 it makes no difference. has anybody else come across this?? Edited... OK it seems that the nlogs only works to generate the job and ID. does anybody know how to retrieve logs more than 20 at a time. I have a workaround by lo...

Mick_Ball by L7 Applicator
  • 1551 Views
  • 2 replies
  • 0 Likes

Global Protect Not able to access external application

Hi, I have a web application hosted by OCI, from on Prem I and my users can access the application without any problems. However when connecting to our PA setup through global protect we cant access the application. We have a very similar setup for some AWS hosted web applications and these work without any issues. Any ideas as I am stumpe...

paul-b by L0 Member
  • 4679 Views
  • 3 replies
  • 0 Likes

Web Auth FW with HA

Hello, I am configuring Webauth with certificate on my FW cluster and currently the access to the active FW is correct. I have created CA and client certificate correctly, the problem I am facing to access the passive node, is it necessary to create another CA also for the Passive FW? Is there any way to have a single CA for the cluster? Can any...

Alpalo by L4 Transporter
  • 1601 Views
  • 3 replies
  • 0 Likes

Resolved! Clarification which update to use for CVE-2023-38802 (VM-100)

Hi everyone. Just wondering on which update to apply for CVE-2023-38802 on a VM-100. The Palo CVE report CVE-2023-38802 PAN-OS: Denial-of-Service (DoS) Vulnerability in BGP Software (paloaltonetworks.com) says any version under 10.2.6 is affected. However, the Recommended OS version page Support PAN-OS Software Release Guidance | Palo Alt...

Resolved! Migrating PA-5050 to PA-5410

Hello all, Is it possible to migrate from PA-5050 to PA-5410? I've been finding threads regarding migrating to PA-5220 only, but nothing on migrating to PA-5410. We've updated the PA-5050 to the final version available 8.1.25, but when we move to the PA-5410 the lowest version possible for it is 10.2. Will the giant gap between 8.1.25 and 10....

How to configure ipsec vpn

How to configure ipsec vpn between palo atto and fortigate firewall . VPN flow is following Remote Lan (191.168.1.0/24) >>>> Fortigate (192.168.10.2 private ip)>>>>>Cisco router(203.1.1.2/29)>>>>>PaloAlto(202.1.1.10/30-public ip)----Local lan fortigate firewall is the behind the NATed device that is cis...

Chignon by L0 Member
  • 2539 Views
  • 2 replies
  • 0 Likes

Resolved! Adding management interface to OSPF via CLI

I'm doing a lab and I need to SSH to the firewalls to run some python scripts, Is there a way to set OSPF to management interacee via set commands, with a management interface of 10.1.1.75? I got the virtual-router default into OSPF, but I can't ping to my local PC. I cannot ping to other devices in the lab, unless I source it from a virtual...

hfakoor2 by L2 Linker
  • 2259 Views
  • 3 replies
  • 0 Likes

Resolved! Generate cookie vs Accept cookie

Hi Team, Can anyone explain what Generate cookie and Accept cookie actually do? I always find myself messing with the cookie settings when enabling DUO/Azure SAML MFA but confused as to what the difference is and what they do.

Schneur_Feldman_0-1680710262228.png

Problem when SSH into a firewall

I can SSH from firewall to firewall, but when i try to SSH from a C brand router to the paloalto firewall I receive this error message: *Sep 27 21:16:32.190: %SSH-3-NO_MATCH: No matching cipher found: client aes128-cbc server chacha20-poly1305@openss h.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com Whe...

hfakoor2 by L2 Linker
  • 1971 Views
  • 1 replies
  • 0 Likes

Resolved! adding a default route in the CLI

trying to set a default route and getting error message set network virtual-router default routing-table ip static-route default next-hop ip-address 10.1.5.9 any ideas on how to set a default route point to next hop 10.1.5.9? Thanks

cisc_forum_2.png
hfakoor2 by L2 Linker
  • 6679 Views
  • 2 replies
  • 0 Likes

Error message: "Internal error during commit process" on Panorama and PA firewall

Hi there, I am able to add a PA firewall into Panorama (both using PAN OS 10.1.4-h4). I successfully imported device config into Panorama and also pushed "the device config bundle" to firewall. so far all good as commit to Panorama is successful. However push to device failed with error message "Internal error during commit process" on both Pan...

Screen Shot 2023-09-21 at 2.31.52 pm.png
Screen Shot 2023-09-21 at 2.32.14 pm.png

Resolved! Allow wildcard DNS in a Network Address

Hello all, We have setup a Hybrid Connection Wizard between our on-prem Exchange server and Office 365, Microsoft has provided the following link for reference in regards to firewall considerations (https://bit.ly/3dpfiZs) under SMTP port 25 - the documents lists *.mail.protection.outlook.com as a required under ID#10. Can anyone advise on the e...

C4c-1942 by L1 Bithead
  • 48701 Views
  • 10 replies
  • 0 Likes

Incorrect PANORAMA health MonitorStatus

Hi there, Could you help me understanding of my device status correctly : I was looking at my device status in PANORAMA's beautiful featrure called "Deviating devices" list. I couldn't quite understand why it is reporting some of my PA devices as deviating from Baseline though it's not even close to the threshold values. for example it's reporti...

  • 24379 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels