General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4221 Views
  • 0 replies
  • 0 Likes

mdns forwarding between vlans no option

hi guys how can I enable mdns forwarding between l3 vlans (my ports are essentially l2 bridges into groups with l3 vlan interfaces having ips and running dchp servers) it seem like bonjur forwarding can only be enabled on physical l3 and not l3 vlans not quite sure what to do thank youalex

nevolex by L3 Networker
  • 2599 Views
  • 1 replies
  • 0 Likes

Resolved! UserID Agent 11.0 on Windows Server 2022

Hi all, i wanted to know if there are any issue identified on installing the user-id agent 11.0 on windows server 2022. I have tried it on a server 2022 and there aren't any problem . Wanted to be sure about it and to not have problems in case of a support request. Thanks in advance

Leobute by L0 Member
  • 3147 Views
  • 1 replies
  • 0 Likes

Collecting customer deployment information

Given I am a newbie to Palo, I am running through the PSE Strata Associate training and have seen this statement (or something like it) many times : using intelligence generated across many thousands of customer deployments. This prompts a few questions: 1. What is being sent from these customer deployments for this analysis to be done ? 2....

shodgdon by L0 Member
  • 1804 Views
  • 1 replies
  • 0 Likes

IKE phase 1 not working

I'm trying to setup a site-to-site VPN between Palo 820 and a Cisco ASA. I've checked the configs and both are matching OK with correct PSK. I've configured the proxy IDs accordingly. I don't have access to the Cisco ASA as this is on the customer side however they sent me the config so I can confirm that crypto settings, psk are matching. T...

G.Grant by L2 Linker
  • 8800 Views
  • 2 replies
  • 0 Likes

Symmetric Return Details - DNAT - PBF Out or PBF In return Symmetric

Symmetric Return Details - DNAT - PBF Out or PBF In return Symmetric Hello Live Community, good evening, as always, thanks for the good vibes, the collaboration and your time. One doubt, I have managed to validate this behavior associated to environment, with two or three ISP Internet links, when I point 2 DNAT to the same IP. And of course ...

Metgatz by L4 Transporter
  • 2701 Views
  • 1 replies
  • 0 Likes

Resolved! GlobalProtect Multiple Profile

Hello, I Have question regarding GlobalProtect: I have 1 virtual PaloAlto with configured GlobalProtect. I would like to configure 2 profile, 1 for my Staff, 2 for external peoples (Like connection profile on cisco anyconnect). difference between these 2 profiles are next: For my staff I would like to provide auto connection to our corporate VP...

3CX PBX behind a PAN-500

After about a week of trial and error, the Palo Alto Network engineers have told me that my PAN-500 does not support the 3CX phone system. I am told that a future feature request will resolve flow based NAT issue I am having with STUN traffic. Unfortunately, I have already bought the server and all new IP phones and the changeover is 2 weeks awa...

JCapron by L1 Bithead
  • 16299 Views
  • 13 replies
  • 0 Likes

Resolved! communication between 2 segments in 2 zones diferents

I have a problem to be able to communicate internally my different segments which are declared in two different interfaces and in different zones. I dont use vlan's Eth 1/6= WAN 141.201.78.43/27 Eth 1/8= LAN10.144.3.19/2610.144.3.64/26 Eth 1/4= LAN2192.168.200.254/24 Interfaces Routes static policies I dont use vlan's

Fipaterm_1-1679082061379.png
Fipaterm_0-1679081978740.png
Fipaterm_2-1679082177979.png
Fipaterm by L1 Bithead
  • 3118 Views
  • 2 replies
  • 0 Likes

Resolved! Allowing ms-update on app-default, File blocking PE and therefore no windows updates

Me again and file blocking per PA best practice (PE, multi-level, etc..) and allowing ms-update on application default. However the WSUS server is not able to download any updates and its classifying a PE file as a threat. The file in question is am_delta_patch_1.249.1313.0_52b04aae0eb450654fc89884b43d10b7ed5 and threat-id is 52060 but nothing...

pa-threat-pe.JPG
drewdown by L4 Transporter
  • 54479 Views
  • 14 replies
  • 0 Likes

PA--820 Power Supply Voltage In (Vin) Voltage and Frequency Range

Hello, I am looking for the exact specification of the PA-820 PSU Voltage and Frequency range, as I need to install the device in mobile asset where the ranges may fluctuate within certain parameters. Due the environment that the units will be deployed in we need to better understand the tolerances of this PSU and I am hoping that there is ...

Steve-P by L0 Member
  • 2623 Views
  • 3 replies
  • 0 Likes

Query regarding the default state of FPGA on PA-3060: What's the output of the command "debug dataplane fpga state" running on PAN-OS 9.1.7 or above?

Dear Community Members, I hope someone will be able to help me out to confirm the default FPGA states on the PA-3060 appliance and supply some additional info on this matter? As per the knowledgebase article (CAN THE CONTENT INSPECTION PERFORM ONLY IN SOFTWARE OR HARDWARE ON PA-3000 SERIES FIREWALLS?) I see that the used algorithms are: AHO - Ha...

Resolved! Cannot create a support account

So I have bought the Palo Alto Firewall Bundle in the AWS Marketplace and was registering a support account, but when I log in the I get the following message:UnAuthorized AccessYour email address, **********, was not found in the support portal. Please make sure to sign in with an email address that is associated with a support portal account. ...

s.nguyen by L0 Member
  • 3146 Views
  • 3 replies
  • 0 Likes
  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels