General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

files are occupying under traps.

files are occupying under traps. [root@xyz opt]# du -sh * |grep G5.9G traps[root@xyz opt]# pwd/opt[root@xyz opt]# cd traps[root@xyz traps]# du -sh * |grep G4.7G ecl[root@xyz traps]# du -sh * |grep M80M bin479M download25M glibc67M lib11M lib3216M local_analysis256M ltee23M persist74M python230M shared_packages[root@xyz traps]# pwd/opt/traps[root...

Resolved! Migration from HA pair PA-3220 running PanOS 9.1.16 to HA pair of PA-1420 running 11.0.2

Hello, as the Subject' saying, i'm facing this issue - what is the recommended procedure? While I'm considering upgrading my 3220 pair to 10.1.10 prior to migration (I'm not that keen to go all the way to 10.2.4) and i'd prefer to avoid the upgrade process entirely if possible - so the Subject still stands. As it is now, my setup is running 5...

Manu_P by L2 Linker
  • 3393 Views
  • 2 replies
  • 0 Likes

HTTP/1.1 404 object not found

Hi Team, HTTP/1.1 404 object not found We are seeing this error when the traffic is passing through the Palo. When we bypass palo it works absolutely fine. May i know what could be causing this? Regards, Sanjay S

How to export the certificate

Hello, I am trying to export a self-sign certificate via CLI as I am getting an error related to the certificate. to give you the background, I am trying to access a remote firewall (PA) via GP whihc terminates on the local PA. when I do that I come across "Certificate Error There is an issue with the SSL certificate of the server you are trying...

Shadow by L2 Linker
  • 3774 Views
  • 2 replies
  • 0 Likes

"Failed to upload image. Device not connected." updating dedicated logger content.

I have dedicated loggers running 10.1.5 and need to upgrade them to 10.1.10. Before I do that, I need to update the content versions. However, when I try to install via dynamic updates from the Panorama to the Log Collectors, I get the subject error. ms.log 2023-07-22 11:20:18.745 +0000 Error: pan_evtmgr_client_check_action(evtmgr_client_actio...

PA-220 OID CPU Data Plane Usage

I´m working with PRTG to monitor our network devices specially Firewalls, for PA-220 I want to monitor and set notifications for the Data Plane CPU usage I can get the OID for the CPU usage, but it´s not the same as the one I want. Does someone know about this? Thanks.

Resolved! Microsoft updates getting blocked by Firewall

I have follow below link to allow these URL in my security policy but today I perform Windows update still very slow and from the log I still able to see some aged-out in my log for update. Any configuration change can help me to solve this issue ? https://docs.microsoft.com/en-us/windows-server/administration/windows-server-update-services/depl...

JiaXiang by L4 Transporter
  • 22821 Views
  • 8 replies
  • 1 Likes

Resolved! Device on L2 interface trying to reach L3 interface on same subnet

Are you able to have a device connected on a layer 2 interface be able to reach a layer 3 gateway on the same subnet? We are able to get this working with a vlan interface when its on a different subnet. Scenario: Sub interface ethernet1/1.100 with IP address 10.10.100.1/24 and tag 100 Ethernet 1/2: Layer 2 interface Device with IP address 10....

Claw4609_0-1689782300039.png
Claw4609 by L5 Sessionator
  • 2340 Views
  • 4 replies
  • 0 Likes

Migration from Checkpoint R81.10 to PaloAlto

Hi Team, We need to migrate a cluster Checkpoint firewall to PaloAlto. We do not have any Zones configured in Checkpoint, but Palo should have Zones as it is zone based firewalls. May i know what is the best way to migrate? Any KB or guide that can give detailed info on migration from Checkpoint to Palo? Regards, Sanjay S

Ignite On Tour Stockholm, Sept 19th 2023

Wish to participate as an interested cyber security network technician but in private. How to do? Reason is that I am still on aprroval my new work and do not want to affect my approval. Best regards, Erik

Using Loopback interfaces for a site-to-site IPSEC VPN

Does anybody have experience configuring site-to-site IPSEC VPNs using loopback interfaces instead of phsical ones? If you are going to respond with a sassy comment (e.g. Why are you doing that? or That's dumb!) then please don't respond. I have a specific need. I have the VPN setup. I can send traffic to the remote end, but it appears that...

merrick by L1 Bithead
  • 31880 Views
  • 13 replies
  • 1 Likes

list for PAN IPSEc Error Codes?

Hi Community, for a problem with IPSEC Tunnels I recently reviewed some ikemgr logs.Those included some Error Codes(for example error Code 19). I was just wondering if there exists a list with error codes and the explanation for those codes?I searched a bit and found lists with those codes but I think in this Case PAN has its own codes. (I am as...

unable to access Palo Alto Web GUI.

Hello, After a recent update from 8.1.20 to 9.0.0, we are not able to access the Palo Alto web GUI (hmmm.. can't reach this page) But we are able to ssh to the device though. We are updating the firmware to the latest version but now need to figure out how to bring up the web gui. our device model is pa 3020 any thoughts? Thank you.

Power supply unit for Paloalto PA-850

Hello everyone, I have Palo alto PA-850 at my warehouse which needs the power supply unit replacement. My colleagues says it should be DPS-500WB-2 B model but a lot of suppliers says they have DPS-500WB-1 A and it's the legal replacement. But I could not find any info about that. Can somebody tell me who is right here? Thanks!

Oleg_a by L0 Member
  • 1669 Views
  • 1 replies
  • 0 Likes

PA VM Firewall

Hi All, I have issues configuring eth1/2 in the VM firewall. I have configured eth1/1 as internet facing interface. eth1/2 should be the MPLS facing interface. When checked on Vcenter the NIC is showing teh Mgmt interface IP and not the eth1/2. Tried manually setting up the eth1/2 MAC in the Network adapter on Vcenter and tried but still teh sam...

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels