General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4118 Views
  • 0 replies
  • 0 Likes

Resolved! IP Wildcard Address not supported in Address Groups?

I am trying to make an address group that consist of wildcard addresses but I get this error: vpn30-wc -> static 'vpn30-v110-wc-1' is not a valid reference vpn30-wc -> static is invalid vpn30-v110-wc-1 is an IP Wildcard vpn30-wc is a new empty address group. Is this not supported?

BBartik by L2 Linker
  • 3964 Views
  • 1 replies
  • 0 Likes

Resolved! Maximum number of routing entries on a PA 5020 running 4.1.10

Hello,Does anyone know what's the maximum routing table entries is on a PA 5020 running 4.1.10 ?I ran into a limitation with a PA 500, where it exceeded > 1K+ routes and had to change how routes are re-distributed on the routers.Thanks in advance.

wmoy by L0 Member
  • 6387 Views
  • 4 replies
  • 0 Likes

Suggestions or help needed: forwarding broadcasts with a custom ip-helper

Hello all, we have recently started using interactive boards that can display the screen of a connected client in various ways: airplay, chromecast, etc. and also by means of a manufacturer's own tool. The tool first creates a list on the client of all boards accessible on the local network. To do this, it sends broadcasts on UDP port 6618 to th...

Pieninck by L0 Member
  • 2775 Views
  • 1 replies
  • 0 Likes

Explore App - can no longer access it

Has anything changed to the Explore app lately? Just recently I was able to access it for clients that had it, but now it is not showing up in the Hub and when I visit it directly via old link I get "You do not have app: logging_service in the account". Was there a change recently for the hub/apps/Explore app?

rufat87 by L2 Linker
  • 1537 Views
  • 1 replies
  • 1 Likes

map users into groups in a multi-forest AD design

Hello Community! I´m trying to find a solution for the following problem: I have two different forests created in the same Active Directory: Forest_1:subdomain_1.domain_1.com Forest_2:subdomain_2.domain_2.com There is a trust between the two forests I have also the universal group_X in subdomain_1: subdomain_1\group_X I added the Use...

Carracido by L4 Transporter
  • 2800 Views
  • 1 replies
  • 0 Likes

Set zone to "any" in CLI

How can I set the zone for a rule to any in the CLI? If I delete the from / to lines it sets it to "none" which is not valid. If I set it to "any" then it thinks "any" is the name of the zone which is also incorrect. Any ideas? Thanks!

BBartik by L2 Linker
  • 2293 Views
  • 1 replies
  • 0 Likes

Resolved! Replace Local Firewall object (address) with Panorama pushed object?

So we are migrating ASA's to Palo Alto...like TONS of them. My question is quite simple and I've yet been able to find an answer. Lets use the following for theoreticals: Local Firewall A has an address-group of "g-RFC1918" on it. I've defined "g-RFC1918" as a Shared object for my Device Group: "Local Firewalls"Upon a push I get the following ...

PA-VM EVE || PA-HDF Mode issue

Hi Everyone, As I am running PA-VM on eve-ng, when start its stucked in PA-HDF mode & automatically rebooting after few seconds, previously it was working fine, your suggestion/solution will be appreciated Thanks.

Khalid by L0 Member
  • 2275 Views
  • 1 replies
  • 0 Likes

Resolved! license required for PAN-OS?

just purchased 2 PA-5410s and stumbled across eve-ng, do i have to have a license to be able to download the pan-os to run in eve-ng? thanks

branedge by L2 Linker
  • 2485 Views
  • 3 replies
  • 0 Likes

how to check traffic volume in IPSec tunnel

Is there any way to check the volume of traffic through an IPSec tunnel? We're being notified of spikes in volume through a tunnel but I'm not sure if there's a way to run a report or check metrics related to tunnel traffic.

Does anybody know how to install the cable management accessories that come with a PA-440 Rail kit?

I tried to get through to tech support with this, and I think I've faced easier quests trying to win money at a Casino! We have a PA-440 rail kit that we are installing 2 PA-440's on. The rail kit comes with a small baggy with cheap white zip ties, and some black plastic pieces that I think are supposed to be used to secure the power cord to th...

HA Clustering Info

Hi all,i have a question for all: i have two datacenter in two different city. The datacenters comunication in Layer 2 witn VRRP.In primary DataCenter (active) i have two FW in Active/Passive (Peer HA), i would configurate a new FW in secondary data center (in passive mode), same model FW, it's possbile? how to configuration this scenario? Than...

"Non-existent domain" error with split tunnel for "Both Network traffic and DNS"

Dear community! I have configured split tunnel for both Both Network traffic and DNS and it works fine. However while doing nslookups I get the "Non-existent domain" error According to the document down below, this can be fixed by setting "Resolve "All" FQDNs Using DNS Servers Assigned by the Tunnel (Windows Only)" option to NO. This optio...

Carracido by L4 Transporter
  • 3144 Views
  • 3 replies
  • 0 Likes

Resolved! Search security policies of network or related IPs

Hi, I need to migrate a vlan from a security zone to a new one. Which is the best way to search the related rules? Ae1.1200 10.100.15.0/24 I need to identify the rules of this network and the rules that use a specific ip like 10.100.15.20 and so one.

  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels