General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4105 Views
  • 0 replies
  • 0 Likes

The Cortex UX Research Lab Is Seeking Participants!

Hello LIVEcommunity! The Cortex team is currently developing a significant UX research effort, the Cortex UX Research Lab, for all aspects of Cortex. As a part of that, we need you — the user — to help us best understand how people use our products and other security products in the real world, as well as test and give feedback on all manner...

Screen Shot 2023-01-17 at 9.59.01 AM.png
JayGolf by Community Team Member
  • 2845 Views
  • 2 replies
  • 1 Likes

Pre Logon then On Demand

Hi All, I have a question regarding Pre-Logon and then on demand. A client has reported they have setup pre-logon tunnel rename timeout to 90 secs. After the client logs in, the GP client goes into a disconnecting state and never times out. Client has to select refresh connection to resolve the issue, and then login manually. I have tested in o...

Ben-Price by L4 Transporter
  • 5962 Views
  • 5 replies
  • 0 Likes

Resolved! Secuity Profile Question

I would like to test the virus file through the PA firewall. But PA firewall is no configure any security profile. May I know is it defected by Palo Alto? Such as found by threat log?

WingMak by L1 Bithead
  • 3278 Views
  • 5 replies
  • 0 Likes

Syslog within a Multiple Vsys environment

Hi All, I have a pair of 5220's, running version 10.0.7 and we are running multiple vsys's on it. We need to set up syslog on one particular vsys to send log data to a service within that environment. I have configured this but the syslog data seems to be heading out of the management interface and not the designated interface. For configuration...

a.jones by L3 Networker
  • 3717 Views
  • 2 replies
  • 1 Likes

PAN-OS dark mode

Hi guys, I work a lot at night and all portals and tools, from Azure Portal, Office 365 Admin Portal, Slack and even Gmail have a Dark Mode, and it really makes the experience a lot better for your eyes. I use dark mode for everything, but spending long hours in PAN-OS with the bright white GUI isn't the best experience at night for your eyes. S...

Tool to generate 'phash' style hashed passwords?

We have a need to create password hashes offline, is there a tool or script available to take a cleartext password and generate a phash?For example, the audit team wants to be able to select a password and generate the hash, so we can later paste into a firewall when provisioning the 'audit' user, even though I would never know what their passwo...

snocc by L0 Member
  • 21107 Views
  • 6 replies
  • 0 Likes

Resolved! Can I have a static bi-directional NAT rule and a PAT rule working together?

Hi, I currently have a static NAT bi-directional policy, number 6 in the screenshot, that publishes an internal server (LAB-Skype) on Internet using a public IP (LAB-Skype-pub). This works fine. Now I need to add an exception for port 443 for that public IP, which needs to be redirected to port 4443 towards the same internal server. I tried ...

Commit Warning for Antispyware

Hi guys,Trust all is well. After the firewall upgrade to version 10.2.1/ 10.2.2, we are getting the following errors after each firewall. Changes/commits are executed successfully. And everything seems to be working without problems. Warning: spyware-profile AntiSpy-Alarm-Only(id: 251) is considered duplicate of AntiSpy-D(id: 258)Warning: spyw...

The existing DNS servers and LDAP server is reachable by the management interface. The additional set of DNS servers and LDAP server setup will have t

Hi Team, The existing DNS servers and LDAP server is reachable by the management interface. The additional set of DNS servers and LDAP server setup will have to access via an interface other than the management interface. Could someone please assist me on this (PA-5220s in a HA configuration). Thanks you

Custom App-ID for Tinder

Good morning all,We have had a situation occur where students and teachers are 'liking' each other on the Tinder dating application (www.gotinder.com), bit of a strange one but surprisingly looking on our PAN the firewall doesn't recognise it as an application?Has anyone created it as a custom application and can share the app-ID for it or give ...

Merging two Palos Config

Hello everyone I have two Palo PA-850s with software version 10.2.2 that are running in different locations. To merge all the services to one location, I must merge two Palos configurations from ACLs, NATs, and Interfaces to a single device (or the HA pair). As far as I know, I can export the .xml config, edit it, and then import it to Palo, but...

SCP Import returns Server error : Failed to import logdb

When exporting logdb file using SCP to different linux machines there would be no errors but when importing the same file we receive the error: Server error : Failed to import logdb, the files would list during importing but the error would appear near the end after a pause, and the original logs are all deleted from the firewall, the test is d...

Resolved! VM series firewalls not sending logs to Panorama

Hello again all, My next hurdle is figuring out why my VM-Series firewalls aren't getting their logs to the panorama server. I've checked the following soo far: Network path between the firewalls and panorama look good. it's allowing ICMP and all TCP. Managed collectors (local to this panorama an an HA panorama) show green, in sync, green...

Verac22 by L2 Linker
  • 3893 Views
  • 3 replies
  • 0 Likes

shadowed rules not showing in cli commit

I need get the shadowed rules name list and remove them, my firewall OS version is 10.1.11, the shadowed rule warning is not there any more in commit, is there a switch on command to show this warning?

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels