General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

PA-220 console is blank

I received a PA-220 to set up at work. When connected to the console (USB-C cable), I'm only seeing a blank screen. I'm using 9600 speed and 8-N-1 but nothing shows up.Even if I reboot the device, nothing appears while it is booting up.

dlemez by L0 Member
  • 2353 Views
  • 1 replies
  • 0 Likes

Resolved! Google Chrome Geolocation

Hi, we have been experiencing a strange problem and not 100% sure if it is the Palo causing this. We use 2 ISP's and BGP, and have confirmed that our Geolocation is accurate, however when accessing google.com and using any map site including google maps it shows that we are located somewhere in Northern UK (we are in the US). My question is, I...

Resolved! High Availability Commit Failure on PA-5220

I am having trouble trying to get a PA-5220 to commit, when attempting to configure HA1, not on the ha1-a default interface, but rather on aux-1. The same applies when configuring HA1-Backup to use aux-2. I can commit with this config, under high-availabilty: set deviceconfig high-availability group 1 peer-ip 192.168.0.2set deviceconfig high-av...

Cortex geolocation ip error

Hi team, Cortex is erroneously geolocating IP addresses, although the FW itself locates them correctly. Can anyone help us how to proceed? Regards

Alpalo by L4 Transporter
  • 1303 Views
  • 1 replies
  • 0 Likes

Global Protect Hip check doubt

Hello, We are implementing HIP for our company, the case is that we already have several HIP objects and profiles working properly. My question is, if we have identified a machine that does not pass the hip check as we want, is it possible that the vpn is cut? or we can only limit access through security policies? Greetings.

Alpalo by L4 Transporter
  • 1418 Views
  • 1 replies
  • 0 Likes

User mapping - IdleTimout and MaxTimeout architecture with GlobalProtect only (no User ID agents)

We have a setup for up to 2.000 employees. Every employee has the GlobalProtect installed, but we are not using any User ID agent.We have only one portal configured, for both internal and external (vpn) connections.On both gateways (internal and external), we have configured the client tab with a Login Lifetime to 7 days and the Inactivity Logou...

convert configuration from set syntax to xml

dear community, please help with any idees how can convert a config file with "set" syntax into xml format. i know that i can extract the config direct in xml format 🙂 i need this solution to migrate some configuration that care only available in "set" format ..don;t ask me why 🙂 many thank for all your feedbacks

Failed to renew device certificate

Hi the device certificate is going to expire end of march.My PA trys to renew it and comes up with the following error:Failed to renew device certificate.Failed to send request to CSP server.Error: No OCSP response received(dest => 35.238.43.180) I have no telemetry enabled. Just activated the certificate with OTP on 2020/12/29 after upgradin...

kbe by L3 Networker
  • 32629 Views
  • 15 replies
  • 0 Likes

Tacacs+ Cisco ISE config

Does anyone know how to configure the cisco ISE side? We can use tacacs now to access the gui but only local usernames and passwords work when trying to access the CLI using SSH. Does anyone have a complete cisco ISE setup? I found a guide to set up palo alto on the cisco ACS platform but ACS is end of life.

PAN-OS 8.0 HA A/S Cluster MAC Flapping

Is anyone else experiencing MAC Flapping with an A/S Cluster running PAN-OS 8.0? When one of the firewalls is rebooted and goes into the HA passive state the network detects a network loop because of MAC address flapping between the Active and Passive firewall. Because of this dynamic MAC learning is disabled for 180 seconds on both interfaces. ...

mvdooren by L0 Member
  • 4137 Views
  • 1 replies
  • 0 Likes

ISP Configuration in case of TATA (Unmanaged ILL)

ISP Configuration in case of TATA (Useful for Indian Customers willing to configure an unmanaged TATA ILL) ** This is useful in case you are not provided with a MUX or a ROUTER along with the Internet Link form the ISP** If you are a customer willing to configure an unmanaged TATA ISP where you are provided with a LAN IP POOL and WAN IP POOL fro...

dc firewall Management interface

Hi, Where should I connect in terms of security and management if I need to connect to the oob management interface? I have access layer, collapsed core, and server farm switches. Thanks

simsim by L4 Transporter
  • 1459 Views
  • 1 replies
  • 0 Likes
  • 24443 Posts
  • 125 Subscriptions
Top Solution Authors
Labels