General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Question about Change Behaviour Log Collector PANOS 10

Hi Team, We have some question regarding Log Collector. We want to upgrade all devices from 9.1 to 10.1 because the 9.1 is EoL on end of year. But, after we read the document about changes behaviour on PANOS 1, the log collector need minimum 3 log collector on the collector group (https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-release-no...

Log entry - packet count

Hello LiveCommunity,I have a, hopefully, quick question regarding traffic log entries and packet counts. What if: there is a security policy which has the action set to "Deny" and the application to traceroute (or anything else but the "send ICMP unreachable" box is ticked); when a packet is received that matches this "Deny" policy and the firew...

Resolved! Help with NAT Configuration on PA-440 In Conjunction With IPSec Tunnel

Hi everyone, I need to do some source/destination NATs on my PA440 for anew ipsec tunnel. I have never had to configure a NAT until now. I have been watching some videos and I understand the basic concept of NAT and why it is needed. My question is, all of the videos I have watched are referencing the outside zone. For my ipsec tunnels, I am usi...

wrong report period while scheduling the report.

Hi Community, I have a weekly scheduled report for saas usage (pre defined in PA) to an email running on my PA-3060, it was working fine. i upgraded the box to 8.1.7 recently, now i am noticing that the report period my report is for one week in 2015, and there is no data in report. But when i run the report using run now, i have detals and the ...

Resolved! Queries regarding upgrade path to version 10.2.3-h4

Hi Guys, I want to upgrade my PA-5220 Firewall from PAN-OS 9.1.14-h1 up to 10.2.3-h4. But I had some confusion regarding the upgrade path. As per referred on this KB https://live.paloaltonetworks.com/t5/customer-resources/support-pan-os-software-release-guidance/ta-p/258304 I draft the path as below: 9.1.14-h1 (Current) upgrade to --->>9...

Incorrect traffic on ACC --> Source and Destination IP Activity

Hello for all, We were having problems importing certificates in an automated way in version 10.2.3-H4, so we did an Update to version 10.2.4-H3 and since this version we have verified that the certificate problem has been resolved, however, the network traffic shown on tab ACC --> Source and Destination IP Active is unreal! Then we migrated ...

Palo Alto Cli login

I can log with the same password as web GUI but i cant log in to the CLI using the same password .what could be the issue?

Resolved! How can I see secure ports?

In the Palo Alto GUI, when I go to Objects -> Applications I would like to be able to view the additional secure ports that an application uses. I know you can select the application to view this, but I'd like to be able to see that information at a quick glance. Is there any way to adjust the columns to show secure ports?

dgagnon by L1 Bithead
  • 2023 Views
  • 1 replies
  • 0 Likes

Resolved! Upgrade path from 9.1.x to 10.1

Hello, I need some help verifying that the below upgrade process from 9.1.x to 10.1.x is correct way. 1. Upgrade to the latest 9.1.x release 2. Download/install 10.0.0 base 3. Upgrade to the latest 10.0.0 relase 4. Download/install 10.1.0 base 5. Upgrade to the preferred 10.1.x release Thank you!

Static route path monitor for dual IPSec tunnels not recovering

We have two ISP's and created redundant IPSec tunnels to our datacenter (one per ISP). We followed this doc on how to setup tunnel failover even though it did not mention that the tunnel IP's needed to be added to allowed tunnel traffic via tunnel Proxy ID setting: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POO0CA...

Issue with QRadar API 19.0 - Unable to Retrieve Event Data

I'm using QRadar API version 19.0 to fetch event data from our QRadar instance. I'm making GET requests to the appropriate endpoint, providing the necessary parameters like time range and filters. However, the responses I'm getting seem to be empty, even though I'm certain that there are matching events in the specified time frame. Has anyone el...

Panorama 10.1.5-h2 - Adding a PA-220 and serial number already in use?

Adding new firewall PA-220 to Panorama >Managed Devices> Summary. Every time I try to add serieal number it fails to import <serial> already in use.I close the error and search for the serial number in managed devices and it can't be found. I also tried to search using the IP address and it doesn't see it either.Global search on <...

Whatsapp traffic not recognize by palo alto firewall

Hi, In one of the Palo alto firewall Whatsapp traffic is detected as “unknown-tcp” for destination port 5222. Only mobile phone users Whatsapp traffic is detected as “unknown-tcp” & Whatsapp web traffic is allowed for destination port 443 & 80. On the other PA firewall Whatsapp traffic is detected as “whatsapp-base” for destination port ...

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels