General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 776 Views
  • 0 replies
  • 0 Likes

ASA migration to PA

Hi Team,

We want to migrate our firewalls from cisco ASA to Palo Alto. Instead of performing hot cutover, we are thinking the other option by connecting them inline to existing firewalls so that it will just monitor all policy and etc, which will hel

...

NTP Sync 10.1.6 PA-220

Hi all,

I'm getting this NTP status message.

I'm quite sure it did initially sync but then reverts to this state.

What exactly does "rejected" mean? The NTP server was reachable but has it been knocked back for some reason.

 

NTP state:

NTP not sync

...

CBrookes by L1 Bithead
  • 6172 Views
  • 8 replies
  • 0 Likes

Resolved! NAT'ing subnets - Larger to smaller? Will it work?

I'm moving some rules from an ASA we will be decommissioning at another location to our local PA-5220 for an IPSEC tunnel that we are migrating. The existing rule set on our ASA is NAT'ing our /16 subnet onto a /24 which technically could be an issue

...

Resolved! Dynamic update scheduling question

Hi Everyone,

 

 I manage a few firewalls (same model) with a template under Panorama; my firewalls do get Wildfire updated but I'm not sure how often they get updated. On Panorama, I look under Device -Dynamic Updates-'TemplateFWs', I don't see anyth

...

tinhnho by L2 Linker
  • 1788 Views
  • 2 replies
  • 0 Likes

We Want to Hear From You! LIVEcommunity UX Survey

 

Hey Everyone! Got a sec? The Live Community Team would love to get feedback on your community experience! 

 

If you are interested in giving your feedback and earning a new community badge, please take this short survey before May 15, 2023.  

 

Th

...

Screen Shot 2023-05-04 at 10.46.37 AM.png
JayGolf by Community Team Member
  • 1221 Views
  • 0 replies
  • 3 Likes

Resolved! System Log Message "WFRTSIG: Unknown error."

Hey Community,

 

we have a pair of PA-3220 in an active/passive Cluster with panos 10.0.7 and since about 4 weeks we see the following system log entry almost every night around 11pm: WFRTSIG: Unknown error.

We see this entries on both devices (active a

...

API calls to Azure failing

Hi All,

We have a setup to turn-on and turn off VPN from Palo VM to Azure (at a specific time daily) but recently the tunnels are not coming up. Seems like the API calls are not being received at the other end. This setup was working before but stopp

...

Pras by L4 Transporter
  • 3626 Views
  • 6 replies
  • 0 Likes

Resolved! ztp firewall upgrade a panorama

Hi.

 

So Upgrade ZTP Firewall for Panorama.

 

Panorama OS : 10.2.4

ZTP Firewall OS : 10.1.2

 

The ztp firewall is not licensed.

 

It was set up by referring to the link, but no update has been made.

https://docs.paloaltonetworks.com/pan-os/11-0/pan-o

...

qmso475 by L3 Networker
  • 1538 Views
  • 2 replies
  • 0 Likes

GlobalProtect on a Chromebook using HIP check.

Here's something interesting that I'm running into. I have a Chromebook managed by Google Admin Center. I have GP 6.0.6-8 installed on the Chromebook. I am doing a HIP check for Host-Id. The Chromebook connects and the HIP info is verified until the

...

rnicic by L0 Member
  • 1660 Views
  • 3 replies
  • 0 Likes

Chromebook using always on, asks to install a certificate.

We are trying to connect our Chromebooks to GlobalProtect using always on. The Chrombooks are managed by The Google Admin Console. We are pushing the certificate as described by google. On connect GP askes to install a certificate. If I cancel then i

...

rnicic by L0 Member
  • 1517 Views
  • 1 replies
  • 0 Likes
  • 23985 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Authors
Labels