General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! maximum number of bgp routes

hi,is there a maximum number of bgp route entries supported for the 5000 series ? does it support a full ipv4 routing table ? i cannot find any docs or data sheets with this kind of limits detailed...thanks

Split tunnel is not working for Linux/IOS devices

Hi, I have a VPN-SSL GP in a FW PA. I have some "Acess routes" in include for LAN ranges (10.0.0.0/8 and 192.168.x.x) and the rest should go through ISP local user. The issue is that I'm seeing traffic destined for the internet that shouldn't be reaching the FW via the VPN. Goiing to agent logs i can see all routes in Linux client as OK. Default...

BigPalo by L4 Transporter
  • 4737 Views
  • 6 replies
  • 0 Likes

Resolved! Does anyone know the API XPATH to load partial for static routes?

Hello All! I'm trying to use Expedition to migrate 100+ virtual systems from old Juniper firewalls my team inherited to our Palo Altos. We are using Load Partial commands rather than importing the entire Expedition output based on recommendations from Palo Engineers. Some of my Juniper stuff has large routing tables of static routes, so I wa...

Resolved! A question about snat address pool couse a route loop

Dear all I have a question about snat address pool and route loop; If I set a snat policy and assign a public address pool(range)to it, like 110.1.1.1 to 110.1.1.11 PS. It's being used for visit internet; I have a default route to internet on my firewall, nexthop is ISP, and this ISP have a route about 110.1.1.1 to 110.1.1.11 next hop is ...

Aruba Central - Palo Alto - User ID Question

Hey Guys, I have a bunch of access points in Aruba Central, we are currently using UserID as a way to assign username to IP address with Palo Alto. I have found these instructions https://www.arubanetworks.com/techdocs/central/latest/content/aos10x/cfg/services/pan_firewall.htm and preliminary testing seems to be working. Just wondering if any...

Active Directory groups w/ members from multiple domains

I'm using AD groups for some security policies and am expanding to use other domains in our company. While I can add users from another domain into an AD group, the PA only shows me the users in the same domain as the group. For example:Domain 1: DC=first,DC=com User 1: CN=idone,OU=users,DC=first,DC=com Group: CN=cars,OU=groups,DC=first,DC=com ...

Resolved! Unable To Submit Support Case Through Any Method

I have an issue that's affecting sync between HA peers. I've been trying to upload a support file (70mb) for 2 hours now. I have tried using a different browser and even a different computer. If call the North America TAC line the automated system instructs me to enter a ticket online. If this were a critical issue this would be incredibly stre...

CAAdmin by L0 Member
  • 2471 Views
  • 4 replies
  • 0 Likes

Resolved! WEBUI Session Timing Out

Hello, On my PA-820 I started getting the idle timeout message below: "Your login session has expired and you have been logged out for security reasons. Please log in again if you wish to continue." Normally this was never an issue and I simply logged back in after being idle. Starting about 2 weeks ago I cannot log back into the WEBUI under nor...

RH747 by L2 Linker
  • 24521 Views
  • 21 replies
  • 0 Likes

Resolved! TPM public key match failed

I have two PA-400 series devices that failed to renew their device certificates and now I get "TPM public key match failed" when trying to renew their certs. Any way to fix this on my own? I see some posts saying PA support had to fix it, but as of now my 3rd party support provider is being unresponsive 😒

Resolved! OSPFv3 support for IPv4?

Greetings all, I've been looking over some possible improvements to consider as we're moving our firewall deployment closer to production. We've got a lot of Cisco equipment through our core along with a switch VSS that runs various VRFs surrounding the PAN firewall. I noticed the Cisco implementation of OSPFv3 is supporting IPv4 address famil...

jsalmans by L4 Transporter
  • 5103 Views
  • 5 replies
  • 0 Likes

licence activation after full configuration and HA is done

Dear Palo Alto Support,We have configured initial settings and an active/passive HA pair on our firewalls. Before proceeding with license activation, we would like to confirm whether this process has any impact on the existing configuration or HA setup. Could you please advise if the configuration and HA state remain intact after license activation

B.Berasa by L0 Member
  • 620 Views
  • 1 replies
  • 0 Likes

Resolved! WOL and two subinterfaces - problem

Hello I have two subinterfaces ethernet1/4.10 (192.168.1.0/24) and ethernet 1/4.20 (192.168.20.0/24) in the same security zone. What I need to set up to allow to wake up computers using Wake On Lan function on 192.168.20.0/24 from ie. 192.168.1.100 ? With regardsSlawek

_slv_ by L4 Transporter
  • 11981 Views
  • 11 replies
  • 0 Likes
  • 24411 Posts
  • 125 Subscriptions
Top Solution Authors
Labels