General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 309 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3651 Views
  • 2 replies
  • 14 Likes

5450 - Included cards in base bundle

It seems odd that the base bundle (PAN-PA-5450-AC-SYS) includes a NC and not a DPC.     

 

Can someone from Palo, or someone that has received a 5450, confirm that a DPC is *not* included and the base bundle (it will not function on its own)?

PA not responding to any incoming requests

I have a PA-220 (PANOS 9.1.8) running with a dynamic PPoE link to the ISP. I've tried everything! It does not respond to PING, SSH, HTTPS. I removed the firewall security profiles, zone protection, added the management profile. Looking at the pcap, t

...

DJ_Palo by L1 Bithead
  • 1550 Views
  • 2 replies
  • 0 Likes

Resolved! Cdb process not running on PA firewall

Hi Folks,

 

Auto-commit on our passive firewall is failing. When checking the logs we could the see the commit failure reason as below:

 

PA-3220 not started, auto commit failed:

 

Details:
Management server failed to send phase 1 to client cord
Commit faile

...

PAN-OS 10.1.4-h4

Hello all,

We are looking to update PAN-OS to 10.1.4-h4 but wanted to ask if anyone had any issues after upgrading? 

I had 10.1.4 installed but it had bugs and had to roll back so I am a little bit leery to upgrade again.

Thank you,

Tom 

thoffman by L2 Linker
  • 1445 Views
  • 1 replies
  • 0 Likes

Global Protect 6.0 Client Windows Authentication

Since upgrading to the 6.0 client every hour, when the client does its config refresh interval, Windows defaults to the Global Protect password sign in option when unlocking the computers rather than what the users are normally using (PIN, Face, Fing

...

Interface Status in Suspended state

I have my production firewalls in HA active/passive mode. My question is if I have suspended the passive firewall, what would be the interface status, would it be down or showing up ? I do understand it will not be forwarding traffic but what would y

...

bambox by L1 Bithead
  • 2309 Views
  • 1 replies
  • 0 Likes

Migration Cisco to PAN

Hello,

I have run a config through the migration tool and I have noticed the following application generate warnings-

 

icmp-  I understand I change this to- ping

ipsec-esp-  I have no idea what this should be changed to?

gre(generic routing encapsulation

...

mamuhopo by L0 Member
  • 1277 Views
  • 1 replies
  • 0 Likes

Resolved! Site-To-Site VPN with payed VPN Providers

I would like to test this hypothetical scenario it is possible :

* I have an account with 3 vpn providers (i.e. NordVpn, PIA, Boleh)

* I would like to create 3 (or more) vpn tunnels (at least one tunnel with each vpn provider)

* I will route different t

...

useridd process is consuming 100% CPU on the PA-5250

PAN-OS is 9.1.10 running on PA-5250.

 

The useridd process is consuming 100% CPU:

 

Tasks: 313 total, 1 running, 309 sleeping, 0 stopped, 3 zombie
%Cpu(s): 2.8 us, 1.5 sy, 0.0 ni, 95.7 id, 0.0 wa, 0.0 hi, 0.0 si, 0.0 st
KiB Mem : 32640128 total, 197252 fre

...

dtran by L4 Transporter
  • 4698 Views
  • 8 replies
  • 0 Likes

Leak a specific route from BGP summarization

Hello All,

 

I have a question related to BGP summarization in a PAN firewall. We currently have summary aggregate advertised to the upstream device. But now we need a leak /32 route to the upstream along with the original summary route. What is the be

...

a-techie by L1 Bithead
  • 1926 Views
  • 4 replies
  • 0 Likes
  • 24185 Posts
  • 100 Subscriptions
Top Liked Authors
Labels