How to import CA Cert via CLI
My Panorama CA Cert expired and I cannot renew it via GUI because I cannot get to the GUI interface. How can I do it via CLI.
My Panorama CA Cert expired and I cannot renew it via GUI because I cannot get to the GUI interface. How can I do it via CLI.
With the help of a software deployment tool, we are looking to install the the GP client (v2.1.0) and then follow it up with a bat file to insert the portal address into the registry. We want this to apply to all users.. (HKEY USERS).. however, the substring under HKEY USERS always changes everytime a machine is imaged. Any other way to do this?
Hello team, My account [email protected] is an eval account, how can I convert it to a production support account? Thanks, -Ivan
Globalprotect vpn prompting user principal name (upn) instead of domain-name/userid format and not connecting. Client os version: Windows 10 version 21H1 (or 21H2) No changes done on FW...
Hello, I have a case open on this item with third-party support, but they seem to have no easy answers and I'm happy to let the community take a swing at it. We have a new installation of a PA-460 running 10.2.3 and I cannot see or seemingly generate any PDF Summary Reports. I'm using the web portal to administer the firewall. On the Reports p...
set up SD-WAN in PANOS. If you look at the manual, it says to use it in conjunction with the panorama. Is there a way to set it up without linking it with the panorama?
When I tried to log in to the support portal, getting the below error, earlier I used to login into the portal. An unexpected error has occurred. Please contact support. Thanks,
Hi all, hoping someone may be able to assist with an issue . these logs are shown only in GUI with high but same logs if see from CLI didn't show up. We are seeing that every 2 hr our PA device generates messages devsrvr: exiting because missed too many heartbeats mgmtsrvr: exiting because missed too many heartbeats Thanks RR
Looking for GP authentication troublehsooting tips or if anyone else is experiencing authentication issues using SAML on globalprotect (effects every single agent version newer than 4.1.1). Our issue seems to only effect macOS users, but my shop is 99% mac users, the windows users rarely connect to the VPN and never complain. We upgraded to PAN ...
Cannot login to the Cortex XDR portal. Also cannot log any Support Cases. "Unauthorized. Error 4011 when trying to log onto a Cortex XDR tenant. Then trying to get to log support tickets the following: Salesforce Single Sign on Error, we can't log you in because of an issue with single sign-on. Contact your Salesforce admin for help Tried ca...
Hi,Planning for upgrading PA-850 to PA-3220, Just wanted to be sure that if we download the current running config from PA-850 and import it to new PA-3220 device, will that work?Precision configuration of the PA-850 and managed by a Panorama.
Hello, I am following this guide to set up ISP failover. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO The problem is that my failover ISP (Starlink), does not provide me a static IP address How would you recommend accomplishing what I want to do when the failover ISP provides a DHCP address? Thank you!
Hi Folks, I am getting the below alert in the panorama every day. I found the below article for resolving the issue.My concern is 1. Why is this necessary? I've never had the issue before v9.1.x2. Do I need to do this every 3 months from now on? Issue: Alarm “Device certificate status expired: it cannot be renewed” Article: https://live.paloalt...
Hi, We launched a sslab test for a GlobalProtect Portal website. Our note is B. We would like to improve these two things but we dont know what it can be done in PA config. These are: There is no support for secure renegotiation. MORE INFO »This server does not support Forward Secrecy with the reference browsers. Grade capped to B. MORE INFO »...
Hi All, I am trying to add new interface to the ospf and pushing the configuration from Panorama to firewall, But I am getting the below error while commiting "client routed phase 2 failure", Commit on secondary firewall is succeeding. Issue is only on Primary firewall. When I checked the logs in Palo-Alto firewall, I can see the below:route...
| Subject | Likes |
|---|---|
| 5 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes | |
| 2 Likes |
| User | Likes Count |
|---|---|
| 8 | |
| 6 | |
| 6 | |
| 4 | |
| 2 |

