General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4136 Views
  • 0 replies
  • 0 Likes

Palo alto panorama - Any advice on how we can deal with old logs?

We would like to migrate logs from M100 to M200 – Could you please advise how to proceed? M100 has 4x2 disks M200 has 2x2 disks M-100 appliance to an M-200 or M-600 appliance- I understood this from the below URL. Kindly correct if any change Log migration is not supported. The M-100 appliance logging disk form factor is not supported on the M...

Blocked traffic log has no url logged

I want to look at the url address of a data packet that was blocked by a deny rule. I had url filtering applied on the rule but the denied traffic log shows the url category but not the url address. Please advise me in logging url address for denied traffic. TIA

LACP Aggregate Group with Subinterface

Hi everyone, I'm trying to set-up a Subinterface on a Aggregate group with LACP on a PA-3020 and a DELL 6248 switch in a test envoirment. If I assign an IP on the default VLAN to the Aggregate Group everything works but I can't seem to get the Subinterface to work, I've tested a Subinterface on a standard interface which also worked. Below is th...

Resolved! TS-Agent CANNOT redistribute user-ip-port mappings

I wanted to put this out in the forum to to save someone time and answer the question on the use case of TS-Agents participating in user-id redistribution. In a long trouble-shooting period and TAC engagement, it was confirmed that you cannot redistribute user-id mappings obtained from a Terminal Services (TS) agent.We have submitted a FR for th...

Resolved! Configuring DNAT on PA-820

Hi All. I'm running into a bit of difficulty for setting up a DNAT configuration on my PA-820. Essentially what I want to do is remotely access an iMac workstation from outside the LAN. However, I don't want to advertise port 5900 I want to setup port translation from 2485 to 5900 to a particular host on the LAN. I've created a DNAT rule as fo...

KGH0511 by L1 Bithead
  • 5194 Views
  • 8 replies
  • 0 Likes

Using wildcards in a query on the traffic log and in custom reports

I was wondering if wildcards are supported on the reporting interface of the Panorama?Actually I would like to run a very specific query on the traffic log. In the normal traffic log we see all the traffic of all our users.I would like to report on the traffic patterns based on a certain kind of domain users. Therefor I need to be able to single...

Choosing the Right Cloud Delivered Security Service for E-commerce Platform

I've been researching various cloud delivered security services for our e-commerce platform, and I'm a bit overwhelmed by the options available in the market. Our main concern is ensuring the safety of customer data, Nexus-iceland portal app especially during transactions, as well as protecting against DDoS attacks. I'm leaning towards a managed...

Unable to get support

We cant go online to submit a support case because no products come up when entering any of our devices. Called support and entered our serial number but it will not take because we must submit a case online first. Called back and this time tried to submit a administrative case thinking I could get someone to help, nope Called back and chose d...

Network Configuration in Cortex XDR

Hello All, I would like to know about the network configuration in cortex XDR. What is the benefit of adding the IP range & domain suffix for the customer deliveries? Regards, Sakshi Seth

Seth_Sakshi_0-1692776049634.png

Resolved! Panorama cannot enter normal status

Hi Panorama version 10.2.3 start to run. but it always show like the below picture. default password and username are admin. and it never work. Anyone has experience to share? Thank you!

kevinospf_0-1692906721815.png
kevinospf by L3 Networker
  • 4442 Views
  • 4 replies
  • 0 Likes

Resolved! Vwire traffic in session table?

Hopefully a simple question - are TCP sessions traversing a vwire in the sesson state table? In other words, is the vwire more like a wire or more like a stateful firewall? Thanks.

pnelson by L2 Linker
  • 1575 Views
  • 1 replies
  • 1 Likes

Question about Change Behaviour Log Collector PANOS 10

Hi Team, We have some question regarding Log Collector. We want to upgrade all devices from 9.1 to 10.1 because the 9.1 is EoL on end of year. But, after we read the document about changes behaviour on PANOS 1, the log collector need minimum 3 log collector on the collector group (https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-release-no...

Log entry - packet count

Hello LiveCommunity,I have a, hopefully, quick question regarding traffic log entries and packet counts. What if: there is a security policy which has the action set to "Deny" and the application to traceroute (or anything else but the "send ICMP unreachable" box is ticked); when a packet is received that matches this "Deny" policy and the firew...

Resolved! Help with NAT Configuration on PA-440 In Conjunction With IPSec Tunnel

Hi everyone, I need to do some source/destination NATs on my PA440 for anew ipsec tunnel. I have never had to configure a NAT until now. I have been watching some videos and I understand the basic concept of NAT and why it is needed. My question is, all of the videos I have watched are referencing the outside zone. For my ipsec tunnels, I am usi...

  • 24340 Posts
  • 124 Subscriptions
Top Liked Authors
Labels