General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4444 Views
  • 0 replies
  • 0 Likes

Palo Alto BGP: Conditional Advertising

Dear All,Recently we have been migrating to a non-trivial BGP setup, and I have had to experiment with the conditional advertising BGP feature in Palo Alto. I was familiar with this concept from cisco, but alas I still found the documentation available on this feature to be a bit unclear and lacking. So, I've written a how to with a step - by - ...

HA Active/Standby HA-1 and HA-2 Ip addressing

The training videos say HA1 1.1.1.1 <-> 1.1.1.2 HA2 2.2.2.1 <-> 2.2.2.2 do there addresses ever get place in the Routing table , RIB, VRF or Vwire? I wish to avoid any issue where people cannot route to cloudflare 1.1.1.1 or other conflicting presence on the internet. I want for best practice every firewall I build. have si...

Policy Based Forwarding is not working for Secondary ISP

  We recently added a new Internet link to our PA-3020. We want only one server (10.1.12.130) to use it, so we configured the new internet link interface as layer-3 , assigned it a static IP, created a PBF policy that basically specifies the zone (internal) and the source IP (10.1.12.130) and the destination is any (negate 10.0.0.0/8) and the ac...

Drawing1.png
Anees10_0-1666768952880.png
Anees10_3-1666769066909.png
Anees10_5-1666769175304.png
Anees10 by L1 Bithead
  • 2274 Views
  • 2 replies
  • 0 Likes

Data Filtiring logs not Show on GUI

I got a problem with showing logs. In past I got problems with threat and data filtering logs, they are simply not showing on the monitor tab. I clean some space from the disc and upgrade pan-os to next version, threat logs start working, but still no data filtering. This problem is on 2 VM firewalls. I cheack root partition (30 percent availab...

Panorama Log Retention Command

Hi, I am running the command to show the Panorama log retention details on a Panorama M-500 'show system logdb-quota' This doesn't show me the retention of traffic, threat logs etc: user@PAN-PRI(primary-active)> show system logdb-quota Quotas:system: 25.00%, 17.755 GB Expiration-period: 0 daysconfig: 30.50%, 21.661 GB Expiration-period:...

ElliotM by L2 Linker
  • 2792 Views
  • 2 replies
  • 0 Likes

Resolved! PAN-OS 10.2 version log4j impact

If I access the log4j related link below, it is confirmed that it has been updated to PAN-OS 10.1 version. URL : https://security.paloaltonetworks.com/CVE-2021-44228 I would like to know if PAN-OS 10.2 is also affected by log4j. If anyone knows about this information, I would appreciate it if you could share it with me. Thanks in advance...

Dipp nat pool duration time

Dear Team, Any documentation or information regarding dipp nat pool duration time? I would like to know how much the previously allocated IP:Port is maintained. If anyone knows about this information, I would appreciate it if you could share it with me. Thanks in advance,Kyungjun,

Resolved! PA-820 Configurable HA Interfaces?

I'm looking at buying a pair of PA-820's. The intention is to have them in an Active/Passive setup. One thing I haven't been able to get a clear answer on though is if the predefined copper HA1/2 ports are the only option on the 820 or if any interface can be configured for HA. I've seen videos of the port configuration for other models.

Resolved! DynDNS client on PANOS 9.0

Hi, I'm trying to setup DynDNS based on the instructions found at https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/networking/configure-dynamic-dns-for-firewall-interfaces.html I'm using DuckDNS, but I'm stuck at the 'certificate profile' portion. As I understand it correctly I have to import the (public) SSL certificate of DuckDNS, bu...

Resolved! AWS VM series 100

Hi I need to deploy Palo in active passive in AWS cloud I was planning to use vm 100 with C5 large instance type 1. Does this instance type only give 3 network interfaces max? Thanks

  • 24375 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels