General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

PAN Issue ID 172132 QoS Fails to run on a tunnel interface

Just upgraded Panorama to 10.1.8. and I want to bring by firewalls up to the same OS, but I see in the release notes that there is a known issue with QoS failing to run on tunnel interfaces. Can anyone tell me if there's a workaround or when this might be fixed? We run QoS on many tunnel interfaces and this is a deal-breaker as far as upgrading ...

Resolved! CDP Connection Issues w/HTTP application incomplete

I have a remote 820 that is connected to a 5250 via an IPsec tunnel. My CDP is directly connected to the 5250. 820<=====>5250<+++++>CDP When I restart the IKE phase on the tunnel, I see the port 80 traffic on my 820, but is says the application is incomplete. When I check my 5250, I don't see any corresponding traffic (permits or...

PA-HDF login: on a PA200

I am new to PA and bought a device and configured it but forgotten my password. i went to maint mode and did factory reset to restart my config again my device entered PA-HDF login: i tried admin/admin and getting incorrect password any advise how to overcome this i also run disk test and of which all results attached Thanks

Dalton by L0 Member
  • 4064 Views
  • 1 replies
  • 0 Likes

The FQDN issue could not be refreshed.

Hello all,We were using two FQDNs that get the same IP from 9.1.14 version.And I recently deleted one FQDN. Then there was an issue where FQDN was applied intermittently.In addition, the GUI confirmed that Refresh was applied through Commit, but it was not applied when forced to try Refresh from the CLI. 2022-10-13 10:54:18.062 +0900 Error: pan...

Resolved! Break up Active/Passive HA Cluster

Hello, we have a PA-3020 Active/Passive HA Cluster. Because of cost cutting I have to break up our cluster and just use one of the firewalls as standalone. The thing is, the license of the passive firewall will last longer than the one from the active. The goal is to use the passive firewall as standalone and to factory reset the active so i...

Veentjer by L0 Member
  • 8083 Views
  • 5 replies
  • 0 Likes

Resolved! Advanced URL Filtering Eval expired - URL filter stops (persistent)

HiI did an self requested Eval of Advanced URL Filtering on a [email protected] the trial expires, the URL filter (or its license) is broken. Even if there is a legacy URL Filter license available. XX@pan> show running url-licenseURL license expired License entry:Feature: Advanced URL FilteringDescription: Palo Alto Networks Advanced URL Lice...

fbpan_0-1627059282377.png
fb-pan by L2 Linker
  • 7778 Views
  • 6 replies
  • 0 Likes

FTP Inbound Decrypt Issues

Ok, I'm at my wit's end with TAC.. after 7 months of explaining the issues, collecting logs, and then starting over when a new agent takes the case, I'm hoping the community can help me. I've had inbound decryption set up for our FTP server for some time. We noticed an issue after updating to 10.0.8 (we're now on 10.1.5-h1 ) where people seemed...

jsalmans by L4 Transporter
  • 5442 Views
  • 3 replies
  • 0 Likes

Resolved! ECMP Preferred Route

Hi All, Does anyone have the answer as to how the Palo Alto choses the "preferred route" when ECMP is configured? As per the runtime stats, the referred route for all these routes is 172.16.8.226. (* flag) Both routes in each of the three destinations have been forwarded to the FIB as per the "e" flag.

0.png

User-ID, consistent naming

Greetings! Over time we have collected a variety of user naming formats. For example, domain\user, subdomain\user, user, user@domain and so on. Is there a way to make these names consistent, allowing us to use policies for them effectively? Thanks! Robert

cloughr by L2 Linker
  • 3531 Views
  • 2 replies
  • 0 Likes

Unable to connect the VPN ( X-Auth Support) from the Linux machine using third party client

Hi Team, ++ We have upgraded the firmware from PAN-OS 10.0.11 to PAN-OS 10.1.8 after we are facing a VPN disconnected automatically for Linux users. ++ The Linux users used to connect the firewall using the third-party VPN agent. ++ We have checked the X-Auth Support configuration and it's looking good. ++ Performed the VPN connectivity ...

Palo's behaviour as a Route reflector

We have Nexus 9k routers "R1 and R2" connected to a silverpeak device which is learning routes from the remote sites. The R1 and R2 are also connected to a Palo Alto firewall which is acting a Router reflector for R1 and R2. We are doing BGP in this setup. R1 and R2 are distributing the routes(Learnt via the Silverpeak device) to the Palo Firewa...

pahee87 by L0 Member
  • 2302 Views
  • 2 replies
  • 0 Likes

Error should be less than or equal to 2048 characters

Hi everybody We are doing a migration from version 8.1 to 10.2.2h2 and have configured syslog server profiles... We have to customize the format of the logs you have to enter a text, or what happens and that when you enter the text that comes in the reference guide crashes because it exceeds the maximum number of characters, https://docs.p...

Alpalo by L4 Transporter
  • 2966 Views
  • 1 replies
  • 0 Likes
  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels