General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Suggestion on Initial Configuration of Palo-Alto

Hi All, We would be needing suggestion on the below scenario: We are having an new Palo-Alto firewall connected via management console in our data center which is integrated with Panorama and we have pre-configured the box by pushing the templates available in panorama. Now we are moving the box to the location and mounting it and planning to...

Sujanya by L3 Networker
  • 3387 Views
  • 3 replies
  • 0 Likes

Resolved! Clientless VPN and Java/Javascript

Hi We have a clientless VPN and app set up to use https on tcp 8443 but the page is not displaying at all. Connectivity has been proven end to end so all the rules are in place.The app points to a webserver that hosts a portal and uses Javascript. Some debugging was carried out on the client browser side and a comparison of going through the cli...

Resolved! Security Profiles - URL Filtering - Update Multiple Categories within all Profiles

Hello all, I'm looking for some suggestions, or information on how I can quickly update all security profiles, with 3 select objects at once. In total, our Panorama has 129 profiles, so I would need to login to all 129 profiles, and update 3 categories in them to block. By way of the gui, I think the only way would be able to edit 1 profile at...

PAN Issue ID 172132 QoS Fails to run on a tunnel interface

Just upgraded Panorama to 10.1.8. and I want to bring by firewalls up to the same OS, but I see in the release notes that there is a known issue with QoS failing to run on tunnel interfaces. Can anyone tell me if there's a workaround or when this might be fixed? We run QoS on many tunnel interfaces and this is a deal-breaker as far as upgrading ...

Resolved! CDP Connection Issues w/HTTP application incomplete

I have a remote 820 that is connected to a 5250 via an IPsec tunnel. My CDP is directly connected to the 5250. 820<=====>5250<+++++>CDP When I restart the IKE phase on the tunnel, I see the port 80 traffic on my 820, but is says the application is incomplete. When I check my 5250, I don't see any corresponding traffic (permits or...

PA-HDF login: on a PA200

I am new to PA and bought a device and configured it but forgotten my password. i went to maint mode and did factory reset to restart my config again my device entered PA-HDF login: i tried admin/admin and getting incorrect password any advise how to overcome this i also run disk test and of which all results attached Thanks

Dalton by L0 Member
  • 4111 Views
  • 1 replies
  • 0 Likes

The FQDN issue could not be refreshed.

Hello all,We were using two FQDNs that get the same IP from 9.1.14 version.And I recently deleted one FQDN. Then there was an issue where FQDN was applied intermittently.In addition, the GUI confirmed that Refresh was applied through Commit, but it was not applied when forced to try Refresh from the CLI. 2022-10-13 10:54:18.062 +0900 Error: pan...

Resolved! Break up Active/Passive HA Cluster

Hello, we have a PA-3020 Active/Passive HA Cluster. Because of cost cutting I have to break up our cluster and just use one of the firewalls as standalone. The thing is, the license of the passive firewall will last longer than the one from the active. The goal is to use the passive firewall as standalone and to factory reset the active so i...

Veentjer by L0 Member
  • 8152 Views
  • 5 replies
  • 0 Likes

Resolved! Advanced URL Filtering Eval expired - URL filter stops (persistent)

HiI did an self requested Eval of Advanced URL Filtering on a [email protected] the trial expires, the URL filter (or its license) is broken. Even if there is a legacy URL Filter license available. XX@pan> show running url-licenseURL license expired License entry:Feature: Advanced URL FilteringDescription: Palo Alto Networks Advanced URL Lice...

fbpan_0-1627059282377.png
fb-pan by L2 Linker
  • 7834 Views
  • 6 replies
  • 0 Likes

FTP Inbound Decrypt Issues

Ok, I'm at my wit's end with TAC.. after 7 months of explaining the issues, collecting logs, and then starting over when a new agent takes the case, I'm hoping the community can help me. I've had inbound decryption set up for our FTP server for some time. We noticed an issue after updating to 10.0.8 (we're now on 10.1.5-h1 ) where people seemed...

jsalmans by L4 Transporter
  • 5485 Views
  • 3 replies
  • 0 Likes

Resolved! ECMP Preferred Route

Hi All, Does anyone have the answer as to how the Palo Alto choses the "preferred route" when ECMP is configured? As per the runtime stats, the referred route for all these routes is 172.16.8.226. (* flag) Both routes in each of the three destinations have been forwarded to the FIB as per the "e" flag.

0.png

User-ID, consistent naming

Greetings! Over time we have collected a variety of user naming formats. For example, domain\user, subdomain\user, user, user@domain and so on. Is there a way to make these names consistent, allowing us to use policies for them effectively? Thanks! Robert

cloughr by L2 Linker
  • 3561 Views
  • 2 replies
  • 0 Likes

Unable to connect the VPN ( X-Auth Support) from the Linux machine using third party client

Hi Team, ++ We have upgraded the firmware from PAN-OS 10.0.11 to PAN-OS 10.1.8 after we are facing a VPN disconnected automatically for Linux users. ++ The Linux users used to connect the firewall using the third-party VPN agent. ++ We have checked the X-Auth Support configuration and it's looking good. ++ Performed the VPN connectivity ...

  • 24426 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels