General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.


Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:


Rules and Best Practices


  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion

JayGolf by Community Team Member
  • 0 replies

Palo Alto consolidate interface and Panorama connection

refer picture below , client plan to consolidate their existing 1gig link to 10 gig link


1. Palo Alto is manage by Panorama

2. Palo Alto configure using default service route which is management IP

3. Client would like to con


VLim by L2 Linker
  • 2 replies

Question about System Logs

Hello there,


I know that system logs can be sent to a log collector through email, syslogs, or API calls to a REST API server. 

Is there any way to get the system alerts from panorama if we made an API call through an HTTP request?  Looking to buil


ccullhaj by L0 Member
  • 1 replies

Certificate Expiration Check- What it actually does

Certificate Expiration Check- What it actually does

The article -


I assumed 'on-box certificates' meant that it would alert on certificates that are


Regarding License activation

We already have n number of Palo Alto firewalls and those are licensed.

recently we purchased two new firewalls. 

Just wanted to activate license for those two new firewalls remotely. 

Registered these devices under Palo Alto support portal and activ


perumalj by L2 Linker
  • 2 replies

Panorama Management Memory alarm

Host: Panorama 

Trigger: Free disk space is less than 9% on Slot-0 Management Memory

Item values:
Name: Slot-0 Management Memory storage used
Key: hrStorageUsed.["Slot-0 Management Memory"]
Value: 57.3 GB




Please, we receive many times this alarm. H


BigPalo by L4 Transporter
  • 2 replies

Traffic getting hits on non-allowed URLs

Hi All,


I have been experiencing a situation where http and https traffic are getting hits on 1 of my security policies which is configured with Custom URL Category.


It looks something like this:


Source Zone: Internal

Source: Internal Network



SAML Configuration between Palo alto and WorkspaceOne

PAN-OS 10.1.8-h2:

I want to configure SAML for palo alto and Workspaceone I m getting an SSL handshake failed Failed to load URL on my linux machine when i log in and on the WS1 interface and put the token. and for my windows maching the global prote


AmineBen by L0 Member
  • 0 replies

Resolved! LACP interface ethernet1/24 moved out of AE-group ae1

Hi Guys,

We are getting "LACP interface ethernet1/24 moved out of AE-group ae1" through syslog (emailed) multiple times in a day on PA 3410 running on PAN OS 10.2.3 in HA active/passive. The switch in use is Aruba 8320

Interesting the same msg is rec


Pras by L4 Transporter
  • 9 replies

Resolved! Palo Alto Layer 2 bridging

Any idea on when or if PAN is going to produce the functionality to do layer 2 bridging (example, traffic on vlan 300 would be directed to vlan 3000...etc? Right now the function only seems to be possible when in conjunction with a physical interface


Resolved! Palo Alto BGP routes from Azure

Palo 5220 running at the edge, using VPN tunnel to Azure virtual WAN running eBGP. Palo iBGP peered to switches, switches peered eBGP to Azure Express Route. My issue is VPN route is always installed in route table rather than express route, I assume


Enable DNS Cloud Security

Dear All,


I generated  BPA Report for Panos 10.2.3  but I need to know how to enable it DNS Cloud Security ?


Best Practice Checks 
DNS Cloud Security (Fail)
Configure DNS cloud security and set the action to Sinkhole and packet capture to a si

  • 23936 Posts
  • 113 Subscriptions
Top Liked Authors