General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Merging two Palos Config

Hello everyone I have two Palo PA-850s with software version 10.2.2 that are running in different locations. To merge all the services to one location, I must merge two Palos configurations from ACLs, NATs, and Interfaces to a single device (or the HA pair). As far as I know, I can export the .xml config, edit it, and then import it to Palo, but...

SCP Import returns Server error : Failed to import logdb

When exporting logdb file using SCP to different linux machines there would be no errors but when importing the same file we receive the error: Server error : Failed to import logdb, the files would list during importing but the error would appear near the end after a pause, and the original logs are all deleted from the firewall, the test is d...

Resolved! VM series firewalls not sending logs to Panorama

Hello again all, My next hurdle is figuring out why my VM-Series firewalls aren't getting their logs to the panorama server. I've checked the following soo far: Network path between the firewalls and panorama look good. it's allowing ICMP and all TCP. Managed collectors (local to this panorama an an HA panorama) show green, in sync, green...

Verac22 by L2 Linker
  • 4177 Views
  • 3 replies
  • 0 Likes

shadowed rules not showing in cli commit

I need get the shadowed rules name list and remove them, my firewall OS version is 10.1.11, the shadowed rule warning is not there any more in commit, is there a switch on command to show this warning?

RedHat IPA authentication on Palo Alto

Hi, When using RedHat or CentOS IPA authentication on Palo Alto firewall, we may ran into challenges when adding LDAP Server Profile and GP Clients functionality related issues.LDAP Server Profile - On a traditional RedHat or CentOS IPA server there will be multiple ou under the Base DN, In order to work properly along with Palo Alto Server prof...

vjbennet by L0 Member
  • 4680 Views
  • 3 replies
  • 0 Likes

Palo Alto Firewall - Exporting Log Database via FTP/SCP is not working

Hello All, We are currently doing a POC with Palo Alto firewall in a customer network. The POC got successfully completed. But while exporting the log database from the appliance we are hitting we issues. After checking the admin guides, found the logs can be exported via FTP on the "Scheduled log export". Via GUI:Provided the FTP path, credenti...

Resolved! masterd: restart exhausted, rebooting system | Palo Alto's process

Hi all, I'm trying to understand better Palo Alto's proccesses analyzing tech-support file with dedicated PANTS tool. I can clearly see that, this pa2020 with 6.0.9, reboots due to masterd process: -------------------------------------------------------------------------------------- ----------------------------------------------------------...

Masterd_exhausted.JPG

Update of Default Trusted Certificate Authorities?

I am just curious - in which way is the list of trusted certificate authorities (WebUI: Device > Certificate Management > Certificates Default Trusted Certificate Authorites) updated? By firmware update or by dynamic update? Regards,Sylvia

sylvia by L1 Bithead
  • 7214 Views
  • 4 replies
  • 1 Likes

PSE software firewall associate

Dear all, I need your help to find my exam question, I am really confussed some question about PSE software firewall associate. Please help me to find right answer. 1. What is the preferred way to analyze traffic logs generated from multiple data center firewalls? a)Use Palo Alto Networks Prisma Access console to view all firewall logs. b)Log ...

Tugsbold by L0 Member
  • 3447 Views
  • 1 replies
  • 0 Likes

advertise inter-vr route to BGP

Hi, I have RBVPN with BGP and I need to advertise routes that have a next-hop to another VR. They do not seem to be advertised to BGP (currently I advertise only connected routes, not static). Is there a simple way to add these routes from another VR to BGP?

MiikaR84 by L0 Member
  • 1573 Views
  • 1 replies
  • 0 Likes

Recover Deleted Customer Support Portal account

Anyone have any idea how to create a user account with an email that was already used prior? I created an account but messed up and deleted it. Unfortunately I did not mess up the email so now when I try to create the account again, it says the email already has an account and cannot be used and cannot log in. I cannot change the email address...

Resolved! PA-440's, and Redundancy

Can you setup/configure 2 PA-440's inter-connected with one being a failover for redundancy in case the other bricks? Or only Dual ISP redundancy using Static Routes Path Monitoring feature, for Traffic failover? Is it even possible to setup 2 PA-440's configured identically with one a hot(plugged in) failover? Forgive my terminology.

Group of Regions / Region Groups

Is there a specific reason that this feature is not yet available? It's a bit of a pain from a readability perspective to have a massive list of Regions tied to multiple policies, to say nothing of having to update multiple policies which may reference the same set of regions. It just seems as though "region" should just be another thing you can...

charlesw by L1 Bithead
  • 5141 Views
  • 3 replies
  • 3 Likes
  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels