General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Thank You for Filling Out the LIVEcommunity Experience Survey!

If you've visited LIVEcommunity anytime recently, you've probably seen a pop-up asking for your feedback. We've deployed this survey since April 2020 for new and returning visitors alike as a way to gather feedback from our users. 

 

In the past six

...

survey-livecommunity.png
jforsythe by Community Team Member
  • 14501 Views
  • 1 replies
  • 4 Likes

Resolved! How to get PCNSC Statue

Hello,

 

Does anyone knows, how can you get PCNSC Statue? I passed the PCNSC exam in January and since that time I did not received it yet. I seen pictures on Instagram and on Linkedin that people received it after one month. What do I have to do to ge

...

Pawel_G by L1 Bithead
  • 1022 Views
  • 1 replies
  • 0 Likes

Block YouTube/Instagram Mobile app

Hello There,

 

What is the best practice to block YouTube, Instagram for mobile apps? So far I tried to create an application base and custom URL policy  to deny YouTube, Instagram. It works (deny access)  if you access the site via HTTPS (Chrome, Fire

...

KurdTech by L1 Bithead
  • 1954 Views
  • 5 replies
  • 0 Likes

Resolved! NAT, Routing and license requirements

Hello Bros,

                I have an unlicensed and out of support single paloalto 3220 appliance, and this device is not licensed now as we have upgraded to paloalto ha.

my question is I wanted to re-use this appliance for some network services such

...

Resolved! Authentication issue with Global Protect

We are having difficulty with our Active/Passive pair of PA_820’s where they are setup to allow auth to GlobalProtect based on AD group membership.

If we create a new OU in AD and move a user to the newly created AD OU whilst still having the same gro

...

Group Mapping.jpg
Auth Profile.png

Resolved! Welcome Page - Iframe

Hello,

we want to include a (external or internal) website via iframe in the welcome page. My test HTML site:

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Frameset//EN"
      "http://www.w3.org/TR/xhtml1/DTD/xhtml1-frameset.dtd"> 
<HTML>
<HEAD>
<TITLE>Pal

...

Hithead by L4 Transporter
  • 3126 Views
  • 13 replies
  • 0 Likes

Resolved! opcmdhistory log missing in PanOS9.1

I noticed that the “opcmdhistory” log disappeared in Panorama after upgrading to PanOS9.1. It was there in 9.0 and previous  versions.

 

Do you know why it changed and if the information is in another log file?

I was using it for troubleshooting and det

...

batd2 by L4 Transporter
  • 1510 Views
  • 4 replies
  • 0 Likes

Resolved! Change speed/duplex on 10G SFP port for PA-5220

Hello,

 

Is it possible to hardcode speed/duplex for 10G SFP port on PA-5220 device? i am getting below error:

 

>set network interface ethernet ethernet1/5 link-speed 10000 link-duplex full 
Error: 
Server error : ethernet1/5 -> link-duplex 'full' is not

...

skanani by L2 Linker
  • 8009 Views
  • 4 replies
  • 0 Likes

Policy not matching actual traffic

Hi All,

 

I have a security rule to allow ip "A" to ssh to ip "B". I can see the traffic actually hitting the fw but it gets dropped with interzone-default. The test policy match also verifies that it matches the traffic.

 

IP "B" is actually the firewal

...

olloczky by L1 Bithead
  • 1674 Views
  • 3 replies
  • 0 Likes

Why tcp aged-out?

Hi all,

Our developers are connecting from Zone1 to Zone2 with tcp (on ports between 2000 and 3000)

The tcp session timeout on firewall is 3 hours.

The security policy allows any application, any port from Zone1 to Zone2. But there are all default secur

...

Global protect Notification

Hi,

 

When I connect global protect Gateway. Once is connected I received this notification.

I have check the internet connectivity it's working fine.

 

Can you please let me know how to avoid this notification 

 

 

Joshan_Lakhani_0-1614493398995.jpeg

Need help with logging in case of App-Id

Hi,

 

I have below rule in my Palo Alto and another default rules which are Intra-zone and Inter-zone.

Source: 10.0.0.0/8

Source Zone: Trust

Destination: Any

Destination Zone: Untrust

Application: ssl, web-browsing, dns, Facebook-base, YouTube-base, etc

Serv

...

Top Liked Authors