General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4469 Views
  • 0 replies
  • 0 Likes

Resolved! Nested Device Group in Panorama

How to create nested device group in panorama, is the same device group can be part of multiple nested device group. If yes, how the policy priorities would be. Please suggest here.

Sujanya by L3 Networker
  • 4819 Views
  • 4 replies
  • 0 Likes

NAT without braking current IPSec

Hi All, Need some help regarding my dilemma. IPsec tunnel between Site A and Site B. Static route for this tunnel is setup to forward traffic to only on subnet (10.100.x.x). I am working on updating patches on server that is under Site A. I need a solution to allow traffic from internet site to the server IP that is on Site A. is there a NA...

mike.07 by L1 Bithead
  • 2574 Views
  • 3 replies
  • 0 Likes

PCI DSS 3.2.1 Responsibility Matrix for SaaS Services

I've been looking for any details from Palo Alto regarding the responsibility of controls for PCI 3.2.1 when it comes to SaaS and PaaS offerings such as Prisma Access, Wildfire, XSOAR, XDR, etc. Most service providers will publish a 'responsibility matrix' that will define what the service provider is responsible for and what the consumer is. ...

mslavens by L1 Bithead
  • 4096 Views
  • 2 replies
  • 0 Likes

PA-220 maximum PAN-OS version

Hi All, May i know what is the maximum version of PAN-OS supported by PA-220. I am migrating PA-500 to PA-220 can i just import the config snapshot directly from PA-550(PAN-OS: 8.1.18) to PA-220(PAN-OS: 9.1.0)? Please suggest. If there is any link which will give all models Maximum and Minimum versions of PAN-OS support that will be helpful. R...

Panorama - Administrators user - Required Password Change Period (days) - Pan-OS 9.1.14

Panorama - Administrators user - Required Password Change Period (days) - Pan-OS 9.1.14 Good afternoon, Thank you for your collaboration and your time I am doing some tests in relation to Minimum Password Complexity -Enabled, mainly to force the password change in X days. When I set Required Password Change Period (days) with value of 3 days...

Metgatz by L4 Transporter
  • 2692 Views
  • 2 replies
  • 0 Likes

Resolved! Global Device/Setup Authentication Settings vs Device/Setup/Authentication Profile

Global Device/Setup Authentication Settings vs Device/Setup/Authentication Profile Hello good afternoon, thank you very much for the usual collaboration. I have the following doubt, at Global level in Device/Setup Authentication Settings there are parameters such as: Failed Attempts and Lockout Time and also if I create an Authentication pro...

Metgatz by L4 Transporter
  • 2738 Views
  • 2 replies
  • 0 Likes

[ASK] Newbie Guide Installation - Failed Booting paloalto-9.0.4 on Eve-NG

Hello guys, I'm a newbie and want to learn about Palo Alto Firewall. I have some problem with booting up Palo Alto in Eve-NG. It appears like this when booting up Palo AltoSpoiler (Highlight to read)Booting 'PANOS (sysroot0)'root (hd0,1)Filesystem type is ext2fs, partition type 0x83kernel /boot/vmlinuz ro root=/dev/sda2 init=/sbin/init_single_co...

PA-440 Pair and license type

Hey guys, First of all please accept my apologies if this question is boring for some of you. I'm new to Network Security world and I need some guidance and additional details around licensing. What I want the fws to do is quite simple but the licensing always makes things difficult if you're new to Palo world. I was looking to recommend to ...

Resolved! IPSEC aggressive exhange mode and enable passive mode

I woulld like to understand the advanced IPSEC gateway configuration.between to ike gateway on with a static ip address and the other with a dynamic ip allocated.to established the phase 1, i need to set the aggressive mode on both firewall or only on the one with dynamic ip allocated?and when I need to activate the enable passive mode?thank's

Gregoux by L4 Transporter
  • 20042 Views
  • 5 replies
  • 0 Likes

Subinterfaces with same VLAN tag

HelloWe are designing a setup with PA 3060. On that we plan to have 2 vsys, lets call them V1 and V2.I have an aggregated interface, lets call it ae22. I want to create 2 subinterfaces:ae22.1 ----- will be assigned to V1ae22.2 ----- will be assigned to V2 Question: Can ae22.1 and ae22.2 have the same vlan number lets say vlan 100 ? Thanks and Re...

PA 10.0.1 not booting on eve-ng

while booting PA10.0.1 on eve-ng getting the below message and getting stuck after that. "Booting 'PANOS (sysroot()' root (hd0,1) Filesystem type is ext2fs, partition type 0x83 kernel /boot/vmlinuz ro root=/dev/sda2 init=/sbin/init_single_core console=ttys 0,9600n8 console=tty0 alternate_root=/dev/vda2 alternate_root=/dev/xvda2 hugepa ges=0 al...

vj.smit by L1 Bithead
  • 2784 Views
  • 1 replies
  • 0 Likes

Resolved! SNMP monitoring on PA3250 PSU

Hi, Is there any way to monitor PA3250 power supply status via SNMP? We need to know in case there is power failure or outage in our environment. In the gui, we never see any alarms regarding on the power loss event. However it is only appear in system log. Thanks

iFAST-SG by L0 Member
  • 6511 Views
  • 2 replies
  • 0 Likes

SNMP traps for power supply monitoring on PA-5260 MIB

Hi Team, We have an PA-5260 deployed in our environment. Need to monitor the firewall using SNMP manager for power failure or when the power supply removed. Firewall is running on PAN-OS 10.0 and we had downloaded the MIB file from the below link and loaded the MIB file for PANTrapshttps://docs.paloaltonetworks.com/resources/snmp-mib-files But ...

  • 24379 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels