General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4104 Views
  • 0 replies
  • 0 Likes

Adobe Creative Cloud update and PaloAlto Content-ID

Hello, We have several of our users that are using well-known Creative Cloud client to download/manage/update/upload/assess/enhance/whatever their wonderfull Adobe softwares (Aftereffect, DreamWeaver, ...) We have a PA with application-based policies. We deny all traffic that rely on "ms-update" application by default (because we have WSUS in pl...

PAN-OS 11.2.8 ETA

Hi All, i would like to know the ETA of the PAN-OS 11.2.8 as per last PA TAC mention that the 11.2.8 tentative release date of june 25 but so far no info of the release yet this is to fix for GUI display issue with SAML SLO url. thank you

Advice on dual isp, getting dns to work

Hello all, I currently have a PA440 and I have 2 isp's, ATT and comcast which will be our backup and it's my 1st time setting this up, we are a small business of about 80 users, I already followed how to configure dual isp redundancy on the links provided here, but can't seem to get the right direction on how to get dns to work once the failover...

cdcirexx by L3 Networker
  • 3004 Views
  • 8 replies
  • 0 Likes

Moving an AE1 OSPF transit link into another AE port what changes will be required?

Hi all, I am looking to move an existing AE1 interface which operates as an single OSPF transit to another AE3 port with other sub interfaces also configured. What changes should be completed and considered when doing this to retain network connectivity? Existing port New port I have amended the virtual router to use the new AE3.3501 int...

MAllen_0-1755771816444.png
MAllen_1-1755771857850.png
MAllen_2-1755771937970.png
MAllen_4-1755772823439.png
M.Allen by L1 Bithead
  • 1401 Views
  • 1 replies
  • 0 Likes

PA-820 Support renewal

Hi All, Our current PA-820 support is due to expire in October, so I requested a renewal quote, and our vendor is stating that paloalto is declining to extend support. Has anyone had similar feedback from resellers and or paloalto regarding their non-EoL PA device who's support is due to expire (in approximately two months time)? According to pa...

Palo Alto Kerberos for sso

Anyone hit the same issue before? 2025-08-16 20:35:38.768 +0800 debug: pan_auth_cache_get_authprof_info(pan_auth_cache_authprof_n_authseqprof.c:218): prof "KRB-SSO", vsys "vsys1" (method: Kerberos pre-auth) has sso hash table id: 1 (0 means no or invalid keytab) 2025-08-16 20:35:38.789 +0800 debug: pan_auth_request_process(pan_auth_state_engine....

prevent-brute-force-attacks

Hello Everyone I am looking for suggestions on how we could protect our GlobalProtect VPN. We have been seeing people trying to perform brute-force attacks on random user accounts daily. We do have MFA set up, but is there any automation we could implement with Palo Alto Firewall to automatically block IP addresses after a certain number of fa...

dshastri by L0 Member
  • 3676 Views
  • 6 replies
  • 0 Likes

Resolved! Advanced-routing ignores BGP local-pref

Troubleshooting a routing issue I've just discovered that the local preference isn't used for forwarding decisions when ECMP is enabled. Has anyone seen this before? I'm about to log a support case, but I thought I'd ask here in tandem. What I see is that the inbound route map sets the local-preference, and ECMP then ignores this and uses all re...

dmgeurts by L2 Linker
  • 2508 Views
  • 3 replies
  • 0 Likes

web browsing slowness

Hello, Is there a Palo Alto expert who can help explain an issue we are facing? At times, we experience internet slowness on our firewalls (not always on the same unit). When this happens, we check resources, CPU, and interfaces, and everything appears normal. However, once we reboot the firewall, performance immediately returns to normal.

Resolved! PANO and NGWF

Can you provide the implications of not renewing the subscription of PANO and NGFWs.What do we lose access to, services, updates, support..?

Solution for "SSL decryption bypass for Anydesk"

Hello, I am being asked a lot about why is Anydesk getting a "decrypt-error" end reason when SSL Decryption is active.Here is a simple explanation and how to overcome this. What you usually going to do with this kind of errors is creating a Decryption bypass rule for Anydesk (in this example)Since is it impossible to bypass based on application,...

OZamir by L1 Bithead
  • 42765 Views
  • 32 replies
  • 7 Likes

Resolved! Browser not prompting/selecting client cert for GP portal

Does anyone know exactly what is needed for browser to either select or prompt for client certificae when connecting to GP portal?I know you need a client sert in personal user store and certificate profile on GP portal. But still i find the behaviour very random.I have 3 GP portals with self signed CA. And a few test machines.For 1st portal get...

santonic by L6 Presenter
  • 5775 Views
  • 7 replies
  • 0 Likes

Globalprotect for Android failing to connect

We're having an issue with GP where all other clients (Windows, Linux, MacOS, iOS) are able to connect with the exception of android devices. Users authentication successfully, get the MFA prompt from DUO, and then get this error: The network connection is unavailable or the gateway is unresponsive. Check the network connection and reconnect. ...

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels