General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4441 Views
  • 0 replies
  • 0 Likes

Downgrade Firewall from 10.0.0 to 9.1.1

Greeting Team! I noticed some problems with a downgrade in my internal lab. So, some information: I want to downgrade from 10.1.7 to 9.1.1 (i need it for the experiment). 1st step i downgrade from 10.1.7 to 10.0.0, everything fine. But, when I want to downgrade from 10.0.0 to 9.1.1 I faced an error with: Upstream NAT not supported on 9.1.1, plea...

wharsapp block

I have blocked WhatsApp on my laptop but not blocking on my mobile. My laptop going to authenticate throw the Active directory. Also, my mobile wifi going to authenticate throw the Active directory but on mobile WhatsApp not going to block please suggest.

Resolved! GLobal Protect Spit Tunnel not restricting domain/applications.

Due to the Void-19 situation and users having to work from home. My company want to reduce bandwidth Utilization by excluding Zoom traffic through global protect. the I.T team has decided to exclude zoom by configuring the "Exclude Client application process name" and adding the path in windows program file for both Win10 and 7. C:\Program Files...

How to find ALL the links related to a website.

Looking for the better idea. User reported xyz.com site is not working, When I look at the firewall logs xyz.com was allowed in firewall. And I filtered the logs with source IP for 5mins time frame and found deny logs for particular IP address 1.1.1.1 I am not sure what is the url for 1.1.1.1, In such case what you will do to find the URL for 1....

Resolved! QoS - Guaranteed bandwith

Hi Team! I'd like to ask about QoS Guaranteed Egress, because I'm not sure I understand the topic well. (used devices PA-220 and VM-100) Here's what I need to do: My branch office bandwith is limited by the ISP to 30Mbit/sec (ethernet1/1 WAN interface). I need to shape traffic to guarantee some bandwith to different kind of traffic classes...

Resolved! How to configure per-client certs on GlobalProtect?

NOTE: the freeware pfsense firewall can configure a working VPN with user passwords and user certs (2FA) inside of 20 MINUTES. With Palo Alto Networks, I'm on WEEK 6. Where I am at:1) I have GlobalProtect working with password auth. (Had to call tech support, who knew what steps were missing from the documentation.)2) I want to have 2FA: so, I s...

dannyman by L2 Linker
  • 14416 Views
  • 14 replies
  • 0 Likes

PAN-DB URL Filtering Categories list for PAN-OS 10.1.x

Does this document below apply to PAN-OS 10.x.x or just for <9.1 Where Can I Find a Complete List of PAN-DB URL Filtering Catego... - Knowledge Base - Palo Alto Networks We are trying to block URLs on both 9.1.x & 10.1.x, but it seems there are URL categories on the document that are not available for all versions of PAN-OS. We implem...

Resolved! ctd-agent-connection error

Dear Team, The following error is occurring in the firewall type : ctd-agent severity : high event : ctd-agent-connection description : Failed to establish GRPC connection to service : failed to start grpc connection with address ----- I would like to know what causes this error and how to fix it If anyone has had a similar experience, p...

Paloalto cannot resolve specific FQDN through Nslookup & "fqdn refresh" is not working on CLI console

Hello all, Our client company uses FQDN A and B that Nslookup the same IP, and the firewall has a DNS access policy applied with these FQDN.Recently, the customer deleted the DNS of B, and if it is normal operation, it should be normal service with FQDN of A, but DNS blocking issue occurred. In addition, entering FQDN refresh from the CLI does n...

Hip profile cannot check process

Hello all,Hope you are doing well!Currently, we are checking the process through Hip profile setting.
However, some PCs are facing an issue where the Process Check information list is not displayed. I checked the HIP Object settings and found that they are using the same settings and that the same program is running on the PC.In addition, I trie...

XML API response for predefined EDL only returns 1 value instead of the entire list

Hi there,Has any one been able to successfully use the XML API to query the predefined EDL lists and have the ENTIRE list returned back in the response? When I attempt to query say the panw-torexit-ip-list, the XML response only returns using this command: https://<firewall>/api/?REST_API_TOKEN=**********&type=op&cmd=%3Crequest...

mslavens by L1 Bithead
  • 1618 Views
  • 1 replies
  • 0 Likes
  • 24375 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels