General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Global Protect - "A valid client certificate is required for authentication" but works correctly for X days after PA restart

Hi all, Just putting this out there to see if anybody else has had similar issues. If you have, I would really appreciate you letting me know please! Palo Alto PA-820 - HA (active/passive) - PanOS 9.1.5 For several months we have had intermittent problems with Global Protect rejecting client certificates when our users try to connect to o...

DavePalo by L4 Transporter
  • 16713 Views
  • 2 replies
  • 0 Likes

Palo Alto PA5220 is not login after password complexity changes

We changed the password complexity and history settings on our firewall a couple of days ago.After committing the changes the local users are not able to login on the firewall.So we tried to boot into maintenance mode by connecting through a console cable in order to roll back to a older running config.This did not do anything though, because th...

MacBook Air M1 connection problem

After my computer upgraded to VENTURA 13, I cannot connect remotely. It constantly says "STİLL WORKING". There is no lock status in the privacy and security settings, as in previous versions. This is hindering my work. You are welcome please help.

Arda14 by L0 Member
  • 1535 Views
  • 1 replies
  • 0 Likes

IKE protocol notification message received: INVALID-SPI (11).

Dears, I have a site to site VPN between PAN 7.1.6 and Cisco ASA 8.2.5, I'm receiving a lot of Invalid SPI error. I tried to reset the VPN many times and still having the same issue. This issue by the way is casusing a lot of packet dropes in the VPN 'IKE protocol notification message received: INVALID-SPI (11).' Did any one faced a similer iss...

Ammar by L2 Linker
  • 40087 Views
  • 17 replies
  • 2 Likes

RMA

Hi I can see that mi shipping information in my case 02366569 for the RMA, the web didn´t save well the shipping information, I wrote a post on the case, with the address correct, Do you know if it is enough or I must do something more?, please. Thanks in advance.

GlobalProtect client behind a proxy, configuration help

I am trying to establish an ssl vpn connection using the globalprotect client, but the client is behind a proxy using a configuration script. I have tried calling paloalto support but they said their client is not proxy aware. Does anyone know of some things I could try to get the globalprotect ssl vpn client to work from behind a proxy?

bigtone by L1 Bithead
  • 23064 Views
  • 6 replies
  • 0 Likes

SYSTEM ALERT : high : Machine Learning engine for PE stopped, please update your content

Dear all, since a couple of hours I'm getting the following alerts every 5 minutes: SYSTEM ALERT : high : Machine Learning engine for PE stopped, please update your content I checked via CLI and I have the latest content installed. Just in case tried to go back one version but that didn't help Downloaded latest version again and installed it. ...

Resolved! Prioritizing an BGP route over other BGP routes for IPSec tunnel traffic redirection

Hi All, We have an physical Firewall on our premise. We have Three ISP and single virtual router with ECMP enabled(Balanced Round Robin)in it. Recently we had configured Two pairs of IPsec tunnels(Pair one -Tunnel 1 and Tunnel2// Pair 2 - tunnel 3 and tunnel 4) to communicate to AWS Peer(Only one Subnet on AWS 10.x.x.x/24) using the BGP Method f...

SNAT to a FQDN

Hi All, I am trying to create a NAT policy that would NAT traffic from my internal Zone to and update server. the problem is i have FQDN of destination server which resolves to multiple different IPs. I need to find a way to complete this NAT policy, is there any way i can make this work?

mike.07 by L1 Bithead
  • 6196 Views
  • 6 replies
  • 0 Likes

HA Pair manual syncronization

Good morning, I'm trying to understand the behavior with this command request high-availability sync-to-remote running-config . I have a HA active/passive pair that I had some config sync issues after an OS upgrade. If I want to push the active running configuration from my active device to my passive device, do I run this command from the ac...

danoman2 by L3 Networker
  • 7676 Views
  • 9 replies
  • 1 Likes
  • 24428 Posts
  • 125 Subscriptions
Top Solution Authors
Labels