General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4111 Views
  • 0 replies
  • 0 Likes

Resolved! Pan-OS database

Hi guys, greetings. On of my customers asked me a simple question about palo alto database. How does it work internally? Is there any SQL database internal on PAN-OS? Should it be accessed by any external factor like APIs os something like that?

IPSEC tunnel not working post HA failover

Hello Friends, We have Palo Alto firewalls (various models like 3050, 5220 and 3220) which are in HA (active-passive mode). IPSEC tunnels are working fine when traffic is on active gateway. The issue is, when we failover traffic on passive gateway, internet works fine but my tunnel resources becomes unreachable. When i checked tunnel status on ...

HA Interfaces failover triggers

Hi All, We currently have a pair of PA-5250 firewalls configured in active/passive. We have 4 port channel groups configured with the condition set to 'all'. The question i have is we are using eth1/1 & eth1/2 as HA interfaces if one of these goes down will the firewalls failover? Also is it possible to stop a interface from causing a ...

ElliotM by L2 Linker
  • 6029 Views
  • 4 replies
  • 0 Likes

Resolved! GlobalProtect Local LAN Printing

I have GlobalProtect running for machines when they are off the network. Is there anything that I need to setup that would allow them to be able to print to their local LANs even though the agent is connected back to the FW? I am currently testing this right now, but users most definitely will need to print when not in the office, so I am hopi...

ccaruso by L0 Member
  • 11258 Views
  • 2 replies
  • 0 Likes

Resolved! Is Installing Application and threats from file possible without a license for PA-820?

Hi Community, I have a spare firewall PA-820 that I need to upgrade from 10.1.6-h3 to 10.2.0 but it returns an error asking me to update the content version. Please see picture below:  But when I try to upload the content version, it asks me for a license.   I remember doing the same procedure last year without the device requesting a license....

Screenshot 2022-09-20 102653.png
Screenshot 2022-09-20 102840.png
Rachid5 by L0 Member
  • 3093 Views
  • 2 replies
  • 0 Likes

SNMP manager for Palo Alto NGFW

Hello, We are trying to use Cisco Prime as an SNMP manager for polling/snmp traps for our Palo FWs but according to Cisco, they only support Cisco MIBS. I was wondering if anyone could recommend an SNMP manager tool for Palos that we can use for polling and snmp traps using Palo MIBs where I can automatically collect the data over a period of ...

JJoseph by L1 Bithead
  • 1946 Views
  • 2 replies
  • 0 Likes

getting PA-200 updated with latest updates

We have purchased Threat Prevention subscription for our older PA-200. I asked for both Premium Support and Threat Prevention but we were sold only Threat Prevention because supposedly PA-200 is no longer sold by PAN. But I cant seem to be able to proceed with Threat Prevention license activation because I also need the firmware updated to 9.0 o...

PA-200_activate_warning.jpg
Nils by L0 Member
  • 5783 Views
  • 2 replies
  • 0 Likes

how dose firewll to panorama log forwording?

Hello. I followed the video while watching it, and I want to send the log to the panorama server. https://www.youtube.com/watch?v=B_ttlugnARE The log is not being checked. Is there a different setting to check the firewall log on the panorama server?

Resolved! Anti-Virus section is not visible on PA-TAC Team

Hi Team, We have 3 PA-410 installed with PAN-OS 10.1.3. We have Advanced threat prevention license installed on the firewall and we are not able to see the Anti-virus update on the firewall . The firewall is able to communicate with the Update server, License is installed on the firewall, App and threat update is also installed on the firewall. ...

How Registration firewall to panorama?

Hello Guys. To register the Paloalto firewall in the panorama, I watched the video and copied it, but it failed. https://www.youtube.com/watch?v=UvtRuYE66DY I tried it the other way, but it failed the same way. https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/add-a-firewall-as-a-managed-device How do I regis...

410 (1).PNG
410 (2).PNG
410 (3).PNG
PA (1).PNG
qmso475 by L3 Networker
  • 2324 Views
  • 2 replies
  • 0 Likes

Resolved! Change VR name

Hello, I have a 5250 with 3 Virtual Routers that talk with each other and one L3 switch via BGP. I have to change the name of one of the VRs, this activity generate outage on the BGP and/or the active sessions managed by the VR?I found these info:"What renaming a virtual router does in reality is deletes the router and readds one with the same c...

Watch SASE Converge 2022 On-Demand Now

Did you miss Palo Alto Networks' SASE Converge 2022 conference? It's not too late to hear from Palo Alto Networks leadership and industry experts talk about the latest trends and innovations in SASE: Watch SASE Converge 2022 on demand now!

Screen Shot 2022-09-20 at 1.04.53 PM.png
jforsythe by Community Team Member
  • 1977 Views
  • 1 replies
  • 1 Likes

Resolved! Unable to resolve FQDN after upgrading PAN OS to 10.1.5 - " ping: unknown host FQDN"

Hi Every one, We have recently upgraded PA-820 to PA-OS 10.1.5. After that, we observed we cannot resolve any FQDN from the firewall. *. We have verified the DNS setting Device>Setup>Services> Primary as 8.8.8.8 and local. *. We have tested by changing the service route of DNS to LAN, WAN, and default and allowed complete access in pol...

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels