General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! PA-HA Server - Drive Error

we are getting a commit error and HA peer end status "Non-functional drive error detected". Then we suspended the Secondary firewall after making the local device function it's showing a passive state and now it's working as expected

SANKETM by L1 Bithead
  • 5341 Views
  • 1 replies
  • 0 Likes

Issues with phase 1 of ipsec

Hi, i've been having an issue with getting the phase 1 of our ipsec tunnel to a customer up who is using a watchguard firewall.As far as i can see our phase 1 settings match up, but i keep getting the no proposal chosen error in the logs.I've attached screenshots of the settings and also a packet capture receive result. I've been a bit stumped a...

User names with two different domain prefixes - inconsistent rule application

I'm semi-reposting this because it didn't get any bites in another topic/discussion area and this seems to be a lot busier. I'm having an issue where are users are showing up in the logs as both domainname\username and domainname.com\username. Whenever I show the user names and group listings on our firewall from the CLI they show as domainn...

Domain config on Split Tunnel

Hi All, I have excluded few of the domains in Split Tunnel config. I am not able to verify if the split tunnel is working curretly. If we check the route print we are not seeing any difference in the route table. Is there any way i can test this or confirm the split tunnel is working? Also is it necessary to * before the domain? For example *pro...

Bandthwidth Issue

We are getting hardly up to 6 Mbps download & 60-70 Mbps upload. The problem is with download. When we connect the laptop directly with Tata, it is showing full bandwidth during speed test. But while connecting through Firewall, the download speed is showing between 1-6 Mpbs.

SANKETM by L1 Bithead
  • 1270 Views
  • 1 replies
  • 0 Likes

USER-ID Rules

Hi Team, We have implemented SAML authentication for GP users. Since then the Source User logs are being seen as email IDs and not with the SAMACCOUNTNAME. So the rules implemented with the LDAP user groups are not working. Is there any way we can get this sorted? Regards, Sanjay S

Resolved! Sub-Interface Configuration

Hi All, Please help. I never configured Sub-Interface in PA. There is a new requirement to configure a sub-interface under already configured interface. So my doubt is how this Sub-interface if we already configured the physical interface with the IP address? What is the use of Sub-interface is it similar to the VLAN interfaces in Checkpoint and...

Resolved! Editing server profile removes the credentials from server settings. Is this a defect?

Hi, In the LDAP server profile section, if you open an existing profile and edit any field (example even an ip address) , it automatically removes the account credentials from the server settings for all servers defined in the server profile. Simply editing an entry like an IP address for one server should not remove credential information for...

Param_Upadhyay_1-1684260564359.png
Param_Upadhyay_2-1684260697074.png

How to check Content version in 7.9 Agent version

Hello All, Greetings for the Day! Kindly find below snap, how to check Content Version In New Agent version (7.9). We have observed that we are not getting "Open Log file" Option in the latest 7.9 agent version which earlier present in 7.8 version. Please let us know how we can check the content version from user's end. Thanks & Regards

MGMNT Slow and Serching logs slow and Syslog server issue.

Device Model: PA-5220 HA Mode Active-standbyPAN-OS 10.0.0The questions below as I couldn't find anything on Palo Alto website. Recently we have upgraded Palo Alto to v10.0.0. 1. Web management interface became very slow and searching logs takes very long time to load.Kindly advise if there’s any solution for that. Can we disable services of some...

SDWAN Shus Down an interface every few minutes

SDWAN.1 is Xfinity comcast no issue ( cable modem 500 down 30 up) SDWAN PROFILE. set to ethernet even though it is a cable modem circuit with an ethernet handoff SDWAN.1 TIER 1 ISP. Bouncing every few minutes based on SDWAN probing. SDWAN PROFILE Tried AGGRESSIVE vs RELAXED Tried ETHERNET vs Fiber link. The Tier1 carrier and I have verifi...

SSL inspection issues with PAN-OS 10.2.3

Good day, Hoping to get some insights on a particular issue we're having. I've managed to get SSL inspection running using a test server: - uploaded the private key and certificate, and the CA's public certificate - created a decryption profile and decryption policy While it tested OK, i can't seem to get it running on our production serv...

  • 24428 Posts
  • 125 Subscriptions
Top Solution Authors
Labels