General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Problem with connectivity to my lab network

So I'm running some PA's inside a Eve-NG lab environment. Everything has connection to everything, including to my local PC with one caveat. When I ping out the PaloAlto firewall to an address I need to specify a source interface or it deems host Unreachable. I believe this is causing my PC to not be able to ping the PaloAlto interfaces either ...

hfakoor2 by L2 Linker
  • 5483 Views
  • 5 replies
  • 0 Likes

Cannot install Applications and Threats : No matching contents package found in panupv2-all-apps

Hi thereI'm new here, just got our first pair or NGFW's. I'm trying to update to the latest PANOS which requires and install of Applications and Threats.How ever when i try to install it i get: Failed to update content with following message: encfilesize is 70541232 No matching contents package found in panupv2-all-apps-8743-8224.eap.tgz exitin...

Reporting URLs and Bytes together?

We are trying to produce a report which summarizes the URLs visited by a specific user along with the total bytes downloaded from each URL.It seems that the bytes are available in the Traffic log, but not the URLs; conversely, the URLs are in the URL log, but not the bytes.Is there some way or producing reports which correlate the various logs?T...

KGC by L3 Networker
  • 5458 Views
  • 5 replies
  • 0 Likes

Resolved! Traffic Loc Collection API

I am calling for traffic logs but only getting the first 20 lines by default as expected but when I add nlogs=1000 it makes no difference. has anybody else come across this?? Edited... OK it seems that the nlogs only works to generate the job and ID. does anybody know how to retrieve logs more than 20 at a time. I have a workaround by lo...

Mick_Ball by L7 Applicator
  • 1605 Views
  • 2 replies
  • 0 Likes

Global Protect Not able to access external application

Hi, I have a web application hosted by OCI, from on Prem I and my users can access the application without any problems. However when connecting to our PA setup through global protect we cant access the application. We have a very similar setup for some AWS hosted web applications and these work without any issues. Any ideas as I am stumpe...

paul-b by L0 Member
  • 4799 Views
  • 3 replies
  • 0 Likes

Web Auth FW with HA

Hello, I am configuring Webauth with certificate on my FW cluster and currently the access to the active FW is correct. I have created CA and client certificate correctly, the problem I am facing to access the passive node, is it necessary to create another CA also for the Passive FW? Is there any way to have a single CA for the cluster? Can any...

Alpalo by L4 Transporter
  • 1661 Views
  • 3 replies
  • 0 Likes

Resolved! Clarification which update to use for CVE-2023-38802 (VM-100)

Hi everyone. Just wondering on which update to apply for CVE-2023-38802 on a VM-100. The Palo CVE report CVE-2023-38802 PAN-OS: Denial-of-Service (DoS) Vulnerability in BGP Software (paloaltonetworks.com) says any version under 10.2.6 is affected. However, the Recommended OS version page Support PAN-OS Software Release Guidance | Palo Alt...

Resolved! Migrating PA-5050 to PA-5410

Hello all, Is it possible to migrate from PA-5050 to PA-5410? I've been finding threads regarding migrating to PA-5220 only, but nothing on migrating to PA-5410. We've updated the PA-5050 to the final version available 8.1.25, but when we move to the PA-5410 the lowest version possible for it is 10.2. Will the giant gap between 8.1.25 and 10....

How to configure ipsec vpn

How to configure ipsec vpn between palo atto and fortigate firewall . VPN flow is following Remote Lan (191.168.1.0/24) >>>> Fortigate (192.168.10.2 private ip)>>>>>Cisco router(203.1.1.2/29)>>>>>PaloAlto(202.1.1.10/30-public ip)----Local lan fortigate firewall is the behind the NATed device that is cis...

Chignon by L0 Member
  • 2641 Views
  • 2 replies
  • 0 Likes

Resolved! Adding management interface to OSPF via CLI

I'm doing a lab and I need to SSH to the firewalls to run some python scripts, Is there a way to set OSPF to management interacee via set commands, with a management interface of 10.1.1.75? I got the virtual-router default into OSPF, but I can't ping to my local PC. I cannot ping to other devices in the lab, unless I source it from a virtual...

hfakoor2 by L2 Linker
  • 2322 Views
  • 3 replies
  • 0 Likes

Resolved! Generate cookie vs Accept cookie

Hi Team, Can anyone explain what Generate cookie and Accept cookie actually do? I always find myself messing with the cookie settings when enabling DUO/Azure SAML MFA but confused as to what the difference is and what they do.

Schneur_Feldman_0-1680710262228.png

Resolved! adding a default route in the CLI

trying to set a default route and getting error message set network virtual-router default routing-table ip static-route default next-hop ip-address 10.1.5.9 any ideas on how to set a default route point to next hop 10.1.5.9? Thanks

cisc_forum_2.png
hfakoor2 by L2 Linker
  • 6847 Views
  • 2 replies
  • 0 Likes

Error message: "Internal error during commit process" on Panorama and PA firewall

Hi there, I am able to add a PA firewall into Panorama (both using PAN OS 10.1.4-h4). I successfully imported device config into Panorama and also pushed "the device config bundle" to firewall. so far all good as commit to Panorama is successful. However push to device failed with error message "Internal error during commit process" on both Pan...

Screen Shot 2023-09-21 at 2.31.52 pm.png
Screen Shot 2023-09-21 at 2.32.14 pm.png

Resolved! Allow wildcard DNS in a Network Address

Hello all, We have setup a Hybrid Connection Wizard between our on-prem Exchange server and Office 365, Microsoft has provided the following link for reference in regards to firewall considerations (https://bit.ly/3dpfiZs) under SMTP port 25 - the documents lists *.mail.protection.outlook.com as a required under ID#10. Can anyone advise on the e...

C4c-1942 by L1 Bithead
  • 49500 Views
  • 10 replies
  • 0 Likes
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels