General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! IPSEC aggressive exhange mode and enable passive mode

I woulld like to understand the advanced IPSEC gateway configuration.between to ike gateway on with a static ip address and the other with a dynamic ip allocated.to established the phase 1, i need to set the aggressive mode on both firewall or only on the one with dynamic ip allocated?and when I need to activate the enable passive mode?thank's

Gregoux by L4 Transporter
  • 20302 Views
  • 5 replies
  • 0 Likes

Subinterfaces with same VLAN tag

HelloWe are designing a setup with PA 3060. On that we plan to have 2 vsys, lets call them V1 and V2.I have an aggregated interface, lets call it ae22. I want to create 2 subinterfaces:ae22.1 ----- will be assigned to V1ae22.2 ----- will be assigned to V2 Question: Can ae22.1 and ae22.2 have the same vlan number lets say vlan 100 ? Thanks and Re...

PA 10.0.1 not booting on eve-ng

while booting PA10.0.1 on eve-ng getting the below message and getting stuck after that. "Booting 'PANOS (sysroot()' root (hd0,1) Filesystem type is ext2fs, partition type 0x83 kernel /boot/vmlinuz ro root=/dev/sda2 init=/sbin/init_single_core console=ttys 0,9600n8 console=tty0 alternate_root=/dev/vda2 alternate_root=/dev/xvda2 hugepa ges=0 al...

vj.smit by L1 Bithead
  • 2830 Views
  • 1 replies
  • 0 Likes

Resolved! SNMP monitoring on PA3250 PSU

Hi, Is there any way to monitor PA3250 power supply status via SNMP? We need to know in case there is power failure or outage in our environment. In the gui, we never see any alarms regarding on the power loss event. However it is only appear in system log. Thanks

iFAST-SG by L0 Member
  • 6594 Views
  • 2 replies
  • 0 Likes

SNMP traps for power supply monitoring on PA-5260 MIB

Hi Team, We have an PA-5260 deployed in our environment. Need to monitor the firewall using SNMP manager for power failure or when the power supply removed. Firewall is running on PAN-OS 10.0 and we had downloaded the MIB file from the below link and loaded the MIB file for PANTrapshttps://docs.paloaltonetworks.com/resources/snmp-mib-files But ...

Panorama software upgrade disk space issue

I am getting following error when trying to download firmware in Panorama VM.Error: There is not enough free disk space to complete the desired operation. Delete older software, dynamic update, or client versions to free additional disk space before trying the operation again. Use the 'set max-num-images count' CLI command to adjust the number o...

raji_toor by L4 Transporter
  • 21880 Views
  • 6 replies
  • 1 Likes

PA GP not allowing users to connect

Hi guys, The other day suddenly none of customer users were able to connect to their VPN, upon further inspection we tried to access to the portal through web and instead of showing the login we were returned "502 Bad Gateway" error. In order to solve the problem we just restarted the sslvpn process and afterwards the VPN started working fin...

ssl-inbound inspection problem

Hello everyone. i'm configuring decryption with ssl-inbound inspection towards a nas synology via DNAT port-forwarding but i'm having trouble working with the following error that gives me the browser "PR_END_OF_FILE_ERROR". DNAT without ssl-inbound inspection works fine without certificate errors if I try to reach the web server from outside....

porq91_0-1662322178791.png
porq91_1-1662322223915.png
porq91_2-1662322296995.png
porq91_0-1662322701882.png
porq91 by L1 Bithead
  • 2993 Views
  • 2 replies
  • 0 Likes

GCP Deployment challenges

I thought I'd share with you a few of the Google Cloud Platform VM-Series deployment challenges I ran into recently. First off, read the documentation carefully, this is a new product and the docs are being updated regularly, not to mention that GCP and their documentation is also constantly undergoing tweaks. One thing that wasn't immediately ...

HA Passive Link State Auto - Vwire Interfaces

HA Passive Link State Auto - Vwire Interfaces Hello good evening, thank you very much for the collaboration. In HA I have configured the passive link in AUTO, in the layer 3 firewall, this works correctly and the secondary firewall interfaces appear as green UP. But in the equipment with "Vwire", in the secondary equipment they appear in red...

Metgatz by L4 Transporter
  • 2884 Views
  • 2 replies
  • 0 Likes

Admin account - Minimum Password Complexity - Firewall - Panorama

Admin account - Minimum Password Complexity - Firewall - Panorama Hello good evening, as always, thanks for the time and for the collaboration. In the "Device / Setup / Minimum Password Complexity" section, the settings made there, including password length, password forcing time, etc. These settings are also applied to the default account (...

Metgatz by L4 Transporter
  • 2546 Views
  • 1 replies
  • 0 Likes

Palo Alto Updates Detected as a Threat

Hello all, im using content update app and threat 8628-7631 and antivirus 4233-4746 on this day. is there any url database update on app and threat 8628-7631 and antivirus 4233-4746? i have a problem on firewall palo alto, that firewall detected palo alto updates as a threat. the management traffic is traverse the firewall. i have policy to a...

2.jpeg
1.png
DennyChanditya_1-1665547623985.png
DennyChanditya_0-1665546592673.png

Help Explaining Interface Counters

I have a couple of ports on different PA's showing various interface errors. Just looking for some help deciphering and find a solution for the interface. PA-7000 series running PAN-OS 9.1.13. Output for the "show counter interface" command is below for each interface. Thanks!! Interface: ethernet2/7------------------------------------------...

  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels