General Topics
Showing results for 
Search instead for 
Did you mean: 
General Topics


Thank You for Filling Out the LIVEcommunity Experience Survey!

If you've visited LIVEcommunity anytime recently, you've probably seen a pop-up asking for your feedback. We've deployed this survey since April 2020 for new and returning visitors alike as a way to gather feedback from our users. 


In the past six


jforsythe by Community Team Member
  • 1 replies

8.0.2 Management SLOW, SLOW, SLOW on PA500

Has anyone else noticed that the management functions through the web interface are incredibly slow with 8.0.2?  Committing even a simple change brought these timings:

- 1:10 just to get the progress bar beyond zero

- 3:42 to complete the commit.




Migration from Palo Alto Multivsys to single Vsys

Hi Team,

Is there a we can migrate a PA 5050 multivsys configuration from one appliance and migrate it to two different 3220 appliances. Where Each Vsys from single PA 5050 goes to different 3220 appliance. For instance (Vsys1-PA 5050) should converte


Migration from 5060 to 5260

Hi Team, 


Currently working on a PA migration 5060 to 5260. I tried to import the config in to the expedition tool, which  is exported from PA-5060 appliance. I found the below error on expedition.

I also tried to import it after converting to zip fil



Resolved! Equal Cost Multiple Path (ECMP) - Limit 4 (PA-5220)

Hi All,


I need your inputs here. I have a client using ECMP (4 Links.) and they recently procured another ISP making it 5. Based on the documentation of Palo Alto Networks, the max ECMP is 4. Is there any other work around to make ECMP 5 or utilize t


Resolved! SSL inbound inspection cert

Might be silly question, For inbound inspection does the cert has to be a CA.

We use a wildcart so that will have to imported as CA, correct?

raji_toor by L4 Transporter
  • 11 replies

Resolved! Panorama IP Variable set to none/null possible?

I'm pretty sure this isn't supported and I haven't been able to get this to work.  I am attempting to use a single network interface template for multiple sites.  Some use 30 sub-interfaces and some may only use 3.  I want to push every sub-interface


Palo alto splunk syslog view


Hi Community,


While exporting syslog from palo alto splunk in default format, what is the default format for config logs.


Where I can see the default format. Next to hostname what is that value "1" where it comes from?



SSL Inbound // decrypt-unsuppot-pram

What can i do here..Is it something we have to fix on server side or firewall.


Not Working, Block sessions with unsupported cipher suites, Selected.

Protocols allowed min SSL3.0 to MAX



Working, with Block sessions with unsupported cipher suites, Un-s


raji_toor by L4 Transporter
  • 3 replies

Session Keep Alive packet size

 Good Afternoon Community!


I believe there is a minimum packet size for an application keep-alive packet for Palo Alto to register a session match. I am just having a hard time finding that documentation.


Does anyone know and could share or am I mist


Multiple MFA vendors at the same time

Good morning,

We are currently using Symantec VIP for MFA with our PA. Management would like to move to Okta and would like to know if both can be used at the same time? 




Block Dynamic Domain from Security Rulebase

Already the specified Malicious URL getting a block from URL Filtering and detected in Threat Prevention with action.

it’s a dynamic FQDN/IP that has to block from the security rule base too, but the does not want to add each IP to block as he receive


Resolved! File Blocking profile

Currently we can only see the logs for the files being blocked.

Can we set up the logs to allow us to see the successful transfer of a file?


Does Alert/Continue Action of File Blocking Profile log entry in the Monitor > Logs > Traffic?



Top Solution Authors
Top Liked Authors