General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4224 Views
  • 0 replies
  • 0 Likes

unable to access Palo Alto Web GUI.

Hello, After a recent update from 8.1.20 to 9.0.0, we are not able to access the Palo Alto web GUI (hmmm.. can't reach this page) But we are able to ssh to the device though. We are updating the firmware to the latest version but now need to figure out how to bring up the web gui. our device model is pa 3020 any thoughts? Thank you.

Power supply unit for Paloalto PA-850

Hello everyone, I have Palo alto PA-850 at my warehouse which needs the power supply unit replacement. My colleagues says it should be DPS-500WB-2 B model but a lot of suppliers says they have DPS-500WB-1 A and it's the legal replacement. But I could not find any info about that. Can somebody tell me who is right here? Thanks!

Oleg_a by L0 Member
  • 1608 Views
  • 1 replies
  • 0 Likes

PA VM Firewall

Hi All, I have issues configuring eth1/2 in the VM firewall. I have configured eth1/1 as internet facing interface. eth1/2 should be the MPLS facing interface. When checked on Vcenter the NIC is showing teh Mgmt interface IP and not the eth1/2. Tried manually setting up the eth1/2 MAC in the Network adapter on Vcenter and tried but still teh sam...

Log System setting

I want to set up messages to be sent to email Log Settings - Config I want every user who connects to the admin to receive an email no matter where the WAB or CLI or IP source comes from. @filter builder (severity eq informational) and (description contains 'logged in via WEB') or (description contains 'logged in via CLI') This is what I confi...

Shalev_0-1689570642938.png
Shalev by L1 Bithead
  • 3566 Views
  • 9 replies
  • 0 Likes

DHCP Interface Stuck

Hi All, I have a situation where the Meraki sends error saying it cannot reach the internet which is connected to the PA and then to the Service provider's NTU. The NTU is providing DHCP connection to the PA's ethernet port. No error message is seen on the PA, but then each time this happens, we need to renew the DHCP Lease in the PA's interface...

Pras by L4 Transporter
  • 2505 Views
  • 1 replies
  • 0 Likes

IP Wildcard mask for IPv6 adresses

Greetings! I am running a VM with PA-VM-KVM-11.0.0 and wanted to test the usage of "IP Wildcard Mask" addresses in Security Policy Rules. The addresses I want to select look like fd00:10:244:*:2000::/80 and "IP Wildcard mask" type for addresses seemed to be the way to go. However the doc reads: Enter an IP wildcard address in the format of a...

frigault by L1 Bithead
  • 3197 Views
  • 1 replies
  • 0 Likes

Route to IPSec Tunnel

Hi All, I need to add a route pointing to a Tunnel interface. As the peer has dynamic IP have created the IPsec tunnel with Dynamic IP Peer Identification as its Hostname. To Add route in the VR as we do not have IP address if i just point it to the tunnel interface and select IP address as none would be enough? Or is there any other way to ...

Email Scheduler Not Working

Hi Team I am on panos 10.2.4 and having issues sending a test email via email scheduler via smtp.zoho.com.au Email profile has been configured and I can receive test emails but from the actual email schedulers I get a failed to send an email message can somebody please help? thank you

nevolex by L3 Networker
  • 5049 Views
  • 3 replies
  • 0 Likes

Global Protect MFA with Google Authenticator

Dear Team, Please help me understand can we configure TOTP Google Authenticator(Free) for Global Project VPN users we have configured Global Protect VPN with AD authentication and want to configure the above solution. Thanks in Advance Regards Sandip Kumbhar

issue when import APP & Threat file

Hi, i have an issue when i tried to import the App & threat file into my palo alto but it shows the following error, Getting error "Failed to update content with following message: encfilesize is xxxx. No threat content update is applied. No valid Threat prevention license. exiting with 255" From device -> license, I can see my threat lic...

How to disable RSA/SHA1 on Palo alto device for SSH access

We are using OpenSSH v8.2 cannot connect to SSH hosts with SSH Proxy enabled (SSH Decryption). Testing showing that this is due to the Palo Alto attempting to use RSA with SHA1 which has been removed by OpenSSH in v8.2. Is there a way we can configure the Palo Alto to disable RSA/SHA1 for SSH?

High temperature DP0 CORE PALO ALTO PA5220

Hello team Since 2 weeks ago we have detected that the temperature for Sensor DP0 Core is high than other members the Paloalto FW It is normal? show system environmentals ----Thermal----Slot Description Alarm Degrees C Min C Max CS0 Temperature: Broadwell MP Core False 38.40 -5.00 85.00S1 NP False 36.50 -5.00 70.00S1 CP False 33.50 -5.00 8...

Alpalo by L4 Transporter
  • 7506 Views
  • 7 replies
  • 0 Likes

Invalid Role - RADIUS

Greetings! Am troubleshooting PA authentication using RADIUS. The user is part of the appropriate AD group for the RADIUS configuration and the PA and RADIUS server are both setup for RADIUS auth. On the PA side, added an administrator and set their auth profile as the radius profile. When the user tries to login, the PA log shows: User 'userX' ...

SDorsey by L4 Transporter
  • 11627 Views
  • 8 replies
  • 0 Likes

Resolved! CSRF Protection

GlobalProtect portal page isn't protected by anti-CSRF tokens. Is it possible to add this protection?

  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels