General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

IKE protocol notification message received: INVALID-SPI (11).

Dears, I have a site to site VPN between PAN 7.1.6 and Cisco ASA 8.2.5, I'm receiving a lot of Invalid SPI error. I tried to reset the VPN many times and still having the same issue. This issue by the way is casusing a lot of packet dropes in the VPN 'IKE protocol notification message received: INVALID-SPI (11).' Did any one faced a similer iss...

Ammar by L2 Linker
  • 39920 Views
  • 17 replies
  • 2 Likes

RMA

Hi I can see that mi shipping information in my case 02366569 for the RMA, the web didn´t save well the shipping information, I wrote a post on the case, with the address correct, Do you know if it is enough or I must do something more?, please. Thanks in advance.

GlobalProtect client behind a proxy, configuration help

I am trying to establish an ssl vpn connection using the globalprotect client, but the client is behind a proxy using a configuration script. I have tried calling paloalto support but they said their client is not proxy aware. Does anyone know of some things I could try to get the globalprotect ssl vpn client to work from behind a proxy?

bigtone by L1 Bithead
  • 22963 Views
  • 6 replies
  • 0 Likes

SYSTEM ALERT : high : Machine Learning engine for PE stopped, please update your content

Dear all, since a couple of hours I'm getting the following alerts every 5 minutes: SYSTEM ALERT : high : Machine Learning engine for PE stopped, please update your content I checked via CLI and I have the latest content installed. Just in case tried to go back one version but that didn't help Downloaded latest version again and installed it. ...

Resolved! Prioritizing an BGP route over other BGP routes for IPSec tunnel traffic redirection

Hi All, We have an physical Firewall on our premise. We have Three ISP and single virtual router with ECMP enabled(Balanced Round Robin)in it. Recently we had configured Two pairs of IPsec tunnels(Pair one -Tunnel 1 and Tunnel2// Pair 2 - tunnel 3 and tunnel 4) to communicate to AWS Peer(Only one Subnet on AWS 10.x.x.x/24) using the BGP Method f...

SNAT to a FQDN

Hi All, I am trying to create a NAT policy that would NAT traffic from my internal Zone to and update server. the problem is i have FQDN of destination server which resolves to multiple different IPs. I need to find a way to complete this NAT policy, is there any way i can make this work?

mike.07 by L1 Bithead
  • 6118 Views
  • 6 replies
  • 0 Likes

HA Pair manual syncronization

Good morning, I'm trying to understand the behavior with this command request high-availability sync-to-remote running-config . I have a HA active/passive pair that I had some config sync issues after an OS upgrade. If I want to push the active running configuration from my active device to my passive device, do I run this command from the ac...

danoman2 by L3 Networker
  • 7507 Views
  • 9 replies
  • 1 Likes

Resolved! Firewall replacement procedures

We are planning to replace PA-3260 with PA-3430, can anyone suggest the procedures and prerequisites to be followed before replacing the firewalls. Currently the firewalls are managed from Panorama.

Cannot block theoxymoron.xyz

Hello, I have been trying to block the site theoxymoron.xyz but can not get it to block. I have tried URL filtering with many different versions of the URL as well as blocking the IP addresses for the site, neither of which worked for me. We do not use decryption. Any help would be appreciated. Thank you.

Stuck in a customer support loop

I'm trying to setup my PA-220 to use the AIOps and need to login into the Palo Alto customer support portal. I have not logged in for a long time, but when I use the account associated with my device, it tells me "Unable to sign in". Trying forgot password, sends no email to the email account. When I try to create an account and enter Serial ...

3dmaxer by L0 Member
  • 2320 Views
  • 2 replies
  • 0 Likes
  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels