General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Avaya 9611G/4610SW VPN to PA-500

Has anyone had success connecting Avaya IP phones via VPN to PA devices? I am able to complete IKE Phase 1 authentication, but fail Phase 2 due to local/remote proxy IDs not found: 'IKE phase-2 negotiation failed when processing proxy ID. cannot find matching phase-2 tunnel for received proxy ID. received local id: 192.168.50.0/24 type IPv4_sub...

itmanager by L1 Bithead
  • 29333 Views
  • 22 replies
  • 0 Likes

Resolved! IPSec VPN Setup for Avaya Phone

I am attempting to setup an IPSec VPN tunnel to connect to remote Avaya phones. I am not sure if I am doing it correctly. I've set up a new IPSec tunnel and configured it to use dynamic IP for remote peers. I am not sure if this is correct or not. It seems to me this would be for a site-to-site VPN. I believe I am looking for more of a client VP...

mario11584 by L4 Transporter
  • 28065 Views
  • 16 replies
  • 0 Likes

Palo Alto 10.2.3 VM Series FLEX - High CPU Peaks Every 10 Minutes on ESXI Hypervisor

Hello, We are new to Palo Alto and a bit confused about the firewall behavior because it peaks every 10 minutes on the MP. There is a process on "show system resources follow" that is called "monitor" that is on 99-100 % of CPU usage. Unfortunately i cannot find anything about that process on the common processes KB. There is no traffic impa...

PatrickMarkert_1-1681300911914.png
PatrickMarkert_0-1681300451377.png
PatrickMarkert_2-1681300983286.png

Resolved! Slow VPN performance in >ONE< direction

Hello Community, i have a strange problem regarding VPN. Here is my setup: HQ: - PA3020 vsys2 connects to a 100/100Mbit WAN. (local, stable provider)- Public IP is configured directly on a interface of the PA- Speedtest from local network in HQ commits the 100/100Mbit Branch:- PA220 connects to a 50/10Mbit Vodafone WAN- NAT will be applied on th...

Resolved! Where can I find an old Cortex macOS installer?

Hi community. I need to know where I can find the installer of Cortex XDR 7.8.0.2405 for Mac because I have some devices where that old Cortex version is stuck and I can't delete it successfully. Or, if you have another method that can remove that old version it would be great. Thanks in advance. Jean Franco Martínez

More disk on panorama in esxi for logs

is this the instructions to use to get more logging space on panorama VM running in panorama mode? https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/set-up-the-panorama-virtual-appliance/expand-log-storage-capacity-on-the-panorama-virtual-appliance/add-a-virtual-disk-to-panorama-on-an-esxi-server

RFC1918 addresses inbound to untrust interface

I have a pair of palos in azure, they are frontheaded by a LB. I also have a VPN gateway in the gateway subnet of the vnet where these components live. Not ideal but I am trying to connect a legacy vWAN hub to a new landing zone. I have a VPN from old to new using VNGs. I have a no-net from new landing zone vnets from trust to untrust so the rfc...

What is the difference in function between the Global Protect Content Filter and the Cortex XDR content filter

On Mac (but I assume something similar exists on PC), both Cortex XDR and Global Protect install a content filter agent. What is the differnce in function between these 2 agents? If I remove the Global Protect agent do I still benefit from the same level of protection solely with the Cortex XDR agent?

MMoerman by L0 Member
  • 2601 Views
  • 2 replies
  • 0 Likes

pan os 10.2.4 advanced routing engine static route issues, a bug?

Hi guys, I have logged the case with palo alto with 'no issues found' response I would like to ask if anyone can kindly test for me I have converted to an advanced routing engine (pan os 10.2.4) conversion when fine, no issues, green light upon conversion results all my static routes stopped working after that, they are like being ignore...

nevolex by L3 Networker
  • 2415 Views
  • 1 replies
  • 0 Likes

SCEP for firewall device cert?

We do not currently have SCEP set up in our environment nor are we familiar with it. But if we did have it set up would our PA firewalls be able to request a cert that we could then use in a SSL/TLS service profile to have a secure connection between our computers and the mgmt gui of the PA? Deploy Certificates Using SCEP (paloaltonetworks.com...

Claw4609 by L5 Sessionator
  • 2602 Views
  • 1 replies
  • 0 Likes

Resolved! URL Blank in Traffic Logs

The traffic logs for our PAs almost never actually show a URL, despite the URL category getting properly assigned. The only time I ever see a URL show up in the logs is if it is specifically denied because of the URL category, which is fairly rare. If they are allowed, or blocked based on something else like application, no URL shows. Is this ex...

  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels