General Topics
Showing results for 
Search instead for 
Did you mean: 
General Topics

Forum Posts

Resolved! GlobalProtect, Working from Home, Prisma Access and Covid-19

To all, Just wanted to post a message about the Hot Topic right now, which is Covid-19. With all of this going around, everybody's health and safely is the utmost concern. Keeping your hands clean, washing your hands (A LOT), using hand sanitizers, a...

jdelio by Community Team Member
  • 41 replies

Add LDAP *GROUP* as Administrator

All - So, I know how to add individual LDAP users as local appliance / Panorama administrators. What I'm wondering is, is it possible to add an LDAP group as an administrator, instead of enumerating each user individually? So, instead of manually enu...

Resolved! How to configure multiple routes at once

Need to configure a firewall with the same 100+ routes that exist on another. Is there a way to copy the routing table from one FW to another via CLI? Can I copy the "show routing route" output and configure multiple routes on another using this outp...

Panorama VM - Decrease Size

Hi Community, I got a customer who has a VM Panorama with 1 TiB of local storage.Now we have a SIEM solution installed, where the long-duration logs are stored, so the Panorama disk storage is oversized now. I know there's a guide to add disk space t...

Chacko42 by L4 Transporter
  • 2 replies

Resolved! How to...(VPN globalprotect)

Hello guys, I'm trying to do something and i'm not really sure if it's possible. Let's get into... I have an url that is for example: "". Our partner is hosting that web and with his firewall is just allowing us the access through our IP...

certificate management with PA

Hi Seems like the certificate renew strips all the SAN/Sub Alt stuff. This is basic cert management .... So why this is a pain - bad .. I have my GP portal cert generated by my PA. it was created with a SAN. if I renew it, the SAN gets striped and gu...

giving the outside interface multiple ip?

im facing issue where a firewall with a outside interface is not receiving public ip adresses from the isp router , the isp router is showing it is own interface which is connected to the firewall as the arp destination for the public ip subnet inste...

chuckles by L2 Linker
  • 7 replies

Resolved! Wildfire

I was wondering ifsomeone could help with clarifying how the WildFire– Proof Point integration works.A client of ours has Palo Alto NGFW in more geographically distant locations, and they also have Proof Point integrated with Wild Fire.[1] How and wi...

Hammer88 by L1 Bithead
  • 6 replies

Captive portal to redirect to intranet site

Trying to set it so when users open their web browser and no matter what they go they are redirected to an intranet site for the first web request of the day. Same thing as a captive portal at a hotel, coffee shop, etc. Want it to redirect to http://...

IP to local address object/hostname resolution.

Prior to an upgrade Panorama was able to resolve an IP address to the host/object name of a local address object.For some reason, the resolution has stopped working and support seems to not know what I am referring to but yet it is discussed here htt...

rkoenig by L3 Networker
  • 2 replies

Resolved! Tunnel went down while PA was responder

Seems PA was responder and tunnel went down today at 9.29.22 MSTbelow are logs We were responder so we should know the reason for tunnel going down 72%2019-05-10 09:28:16.772 -0600 [PNTF]: { 14: }: notification message 36136:R-U-THERE, doi=1 proto_id...

MP18 by Cyber Elite
  • 7 replies

Resolved! Why PA is Responder for Phase 1 and Initiator for Phase 2

Seems Phase 2 is down and system log shows below logs again and again and ( description contains 'IKE phase-2 negotiation is failed as initiator, quick mode. Failed SA: 198.160.x.x[500]-173.182.x.x[500] message id:0xF55F380F. Due to negotiation timeo...

MP18 by Cyber Elite
  • 4 replies

Screenconnect App

Hi to all, this is Marco. I just update my 850 from PanOs 8.0.15 to 8.1.7.Now i can find in the APP list screenconnect.When i try to create a rule using screenconnect, the firewall tell me unknow-app.Keeping in mind that the destination addresses of ...