General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Traffic Deny due to DNS?

Hello,

 

I was given a chunk of IP addresses and domains/urls to update into an existing blacklist on the firewall.  I go to objects and create ip-netmask for ip addresses and FQDN objects for domains/urls. Some of the domains i received come in the fo

...

dnserror.png
Kenchh by L0 Member
  • 2124 Views
  • 1 replies
  • 0 Likes

Rendezvous Point query

Hi Team,

 

We have already used one interface for RP can we use one more interface to configure RP ??

please find below snapshor for reference

 

 

GideonKonga_0-1638293621158.png

Commit-All to Specific Device Using API in Powershell

I am using Powershell to make API requests to Panorama which cause various commands to be executed on specific NGFWs. I would like to do a commit-all to a specific firewall, not the entire DG/template stack. The documentation Commit-All (paloaltonetw

...

Have: old PA-200. Need: firmware 5.x

Hi,

I bought a PA-200 new many years ago but support long expired on it.  I've been using it simply as a home office firewall since then and have never upgraded PANOS so it's at 4.1.6.  Honestly it's running fine, but the old SSL version is forcing me

...

user id group mapping

 

Hello I have several questions to ask you about the user ID.

1)We say that the LDAP does not map between the ip and the user, so who does the mapping between the ip and the user name?

 

 

2)  then, when we configure the mapping of group. I do not unders

...

Sarou22 by L1 Bithead
  • 3044 Views
  • 6 replies
  • 0 Likes

Resolved! HIP Notification question

Hi,

 

A question regarding HIP notifications.

 

I have enabled HIP notifications for GP clients connecting in and they trigger when a violation of the HIP profile is detected e.g. firewall turned off, but just wanted to clarify something in the Palo docu

...

BenPrice_0-1637729906099.png
BenPrice_1-1637729949128.png
Ben-Price by L4 Transporter
  • 5983 Views
  • 7 replies
  • 0 Likes

XML output command of ARP managment in 9.1.11

Hello ,

 

I have multiple firewall with running PAN-OS 9.1.11 and above version.

i am facing an issue to generate XML output command of ARP managment.

 

When i run the ARP managment command to set XML output on i am getting the below error:-

 

admin@PA-VM-P

...

License issue

Hello ,

 

we have a customer who renewed the premium partner support

 

When we go to License tab , we can see Premium Partner support renewed 

 

But when i go to Support Tab, it still shows date of 2020

 

Is it cosmetic ?  We already tried to fetch the licen

...

how to configure gre over ipsec?

Anybody know how to configure gre over ipsec ?

from the 9.0,pa support gre tunnel and only one word describe about this feature.

  • (Optional) Select Add GRE Encapsulation to enable GRE over IPSec.
    Add GRE encapsulation in cases where the remote endpoint r
...

Felixcao by L3 Networker
  • 3004 Views
  • 3 replies
  • 0 Likes

Resolved! Static route path monitor shows UP with invalid next hop

I'm running PAN-OS 10.1 on a VM-100. I have DHCP on an interface and use a script to update an address object with the default gateway from the DHCP interface. I have a static route with next hop set to this address object and path monitoring enabled

...

palo-next-hop-0.png
palo-next-hop-254.png

Resolved! IPSec tunnel rekeying

Hi all,

 

We are using tunnel monitor on the IPSec tunnels and i am wondering if rekeying childs SA, causes the tunnel monitor to bring the tunnel down. In additon i would like to know if PA stores a log of all the rekeys for each tunnel.

 

TIA

Issues with Global Protect and Post-vpn-connect

I've opened a ticket with Palo and haven't had much success.  I am trying get the drive mapping script to run and it gives me an error 1008.   Below are the logs for gpservice. Few things I have noticed and tried:

1)it is using my adminacct yet i am l

...

  • 24195 Posts
  • 100 Subscriptions
Top Liked Authors
Labels