General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.


Resolved! SNMP to track NAT/PAT translation usage statistic



There's public IP configured with NAT port address translation for outbound Internet access. Can we monitor the statistics/utilization of NAT/PAT to prevent port exhaustion, is yes is there a reference guide what's the OID value or which modules


GP/ LDAP authentication



I have a test AD/PA setup.

AD and LDAP connectivity is okay so far.


My problem is that I am unable to authenticate any user against Global Protect.

The un/pw are correct.

The group are correct too, as far as I can see.


This is the output i get when


Vimz888 by L1 Bithead
  • 3 replies

Resolved! Commit fails in 10.0.7

Error-Failed to add '' to external-URL-list" and Commit fails after that in 10.0.7.


we got to know that there is bug ID  PAN-172580 declared in 10.0.7 and error will be fixed in Target version 10.0.8(ETA by Mid Nov)


I tr


LDAPS Falling back to LDAP

Our firewalls are configured for LDAPS on port 636 to our Windows DC. We have the require SSL/TLS option checked in the LDAP settings window. The useridd log shows:


2022-03-22 14:42:09.136 -0700 connecting to ldap://[dcserver]:636 with StartTLS...


Device Certificate Issue

Hi Team,


We are facing an issue with the device certificate. I have generated that OTP in the CSP portal and imported it into the firewall after I am facing the below issue


"Failed to fetch device certificate. Failed to send a request to the CSP serv



Resolved! URL Category Any

Is there any body has got URL Category Any?

I check the URL List document and there is no Any category.

Also, I had find a category called "uncategory".

Will Allow/Block List IP addresses will be categoried in "uncategory"?

What's the difference between


MineMeld behind proxy server - Using docker

I am trying to use a proxy for MineMeld Internet connectivity, and I have assigned proxy settings to the container instance. For some reason, it is not working and I probably need to especifically set proxy settings in the MineMeld application, but I


version 10.2.0 upgrade issue

Dear Support crew,

we have two PAN-3220. Our devices are HA. We received advanced evaluation package licenses for the devices, but my device operating system was 10.0.3 so the advanced licenses are only installed on PANOS 10.2.0.
According to the relea


Clientless VPN getting worse with each PANOS ver

Timeline of my struggles:


Somewhere between 10.1.0 and 10.1.4 the clientless VPN stopped showing icons for each app not super big deal because the apps still worked but after trying a couple upgrades...


10.1.5: brings the icons back! but now the apps


hshawn by L4 Transporter
  • 4 replies

Resolved! View debug status


I come from Cisco background and getting familiar with Palo Alto firewalls. 

My query is about checking any debug running on the box and how to turn it off. In case of Cisco, show debug will show any active debug(s) and undebug all would turn it of


  • 24130 Posts
  • 102 Subscriptions
This widget could not be displayed.
Top Solution Authors
Top Liked Authors