General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4104 Views
  • 0 replies
  • 0 Likes

Resolved! What does No Direct access to Local Network actually do and when do we use it??

Team, Can anyone please explain SIMPLY to me what the "No Direct access to Local Network " under Global Protect actually does and mostly when are supposed to use it? This is so confusing to me. I know there is a KB for this but the KB seems to confuse people more then help. Basically what does it block and when should we enable it? Full tunne...

session end reason as 'Threat'

hello everyone, Firewall is showing session end reason as 'Threat' in traffic logs for the traffic blocked under url filtering profile. this is showing repeatedly, i'm afraid is consuming the Data Plane CPU. IT could be the action of blocking or just the report. But i would like to know if there is a way to block this traffic way before is...

YParreno by L1 Bithead
  • 7315 Views
  • 4 replies
  • 0 Likes

User ID: Problems since updating PANOS and User ID Agent

About a month ago, I upgraded PAN-OS on our main PA-3050 HA cluster from 7.0.8 to 7.1.8. This also required an update of the User ID Agent I had installed on a Windows 2012 R2 server from a 6.0.x version to a 7.0.x version; I upgraded to version 7.0.7-13. I've started to receive reports that some individuals are seeing the captive portal and a ...

Resolved! decryption rule

Hi Everyone, I want know how we can check which decryption rule is being used for a particular traffic. Thanks Virender

vsingh31 by L1 Bithead
  • 2878 Views
  • 3 replies
  • 0 Likes

Resolved! App-ID

Good Morning, I am currently working with a PA 3220 firewall that has no licenses. Does App-ID work right out of the box without a license? On security policies I see under the ‘apps seen’ column it is identifying apps. If you use the apps found under the apps seen column will it work? Can you update apps without a license? I was a last minute a...

jaah1231 by L0 Member
  • 4380 Views
  • 2 replies
  • 0 Likes

Configure HA3 on a non HCSI interface for PA220

Hello Everyone, Need to put my PA220s in active-active mode, I know they do not come with a HSCI port, can I use a normal Gigabit interface for my HA3 interface and just set them to HA? Should I be worried about any stability or performance issues doing that? And I am guessing jumbo frames would still be needed here right? Thanks.

Resolved! Certificate Error in GP

Hi Team, I am getting below error while try to connect to GP. When I am try to connect to the portal getting this error, any suggestions? before it was showing continue but not it is not showing. Usually it will give the option to proceed anyway but it is not giving that option. After Reinstallation it is giving that option.

SubaMuthuram_0-1661322421146.png

Issues with resolving Xsoar DNS Alias

Hello, I am hoping someone here may be able to guide me. My company is using Xsoar, and we are having an issue with resolving DNS alias for it. The servers resolve to an AWS url. Half the time it resolves the other half it does not. Even support.paloaltonetworks.com there is an issue resolving half the time. It is intermittent it seems. I looked...

Google captcha error

Most of the users are getting captcha error in google.com Wondering why PA is not blocking such requests. Will the DOS policy in PA help prevent such unlimited outbound queries? Page says our systems have detected unusual traffic from your computer network.

google2.jpeg
ceapen01 by L2 Linker
  • 3662 Views
  • 3 replies
  • 0 Likes

Suitable Palo Alto Firewall

Hi everyone , I have an enterprise network and two simple outside networks that are connected to the enterprise network via Firewall. The enterprise network includes 50 windows users and 2 windows servers and storage. I intend to install a Palo Alto Firewall with Internet access and two external networks. I would appreciate your help in advising...

Resolved! Explanation for why all applications are not available for PBF

Hi All, Just wondering if anyone can explain why the application objects have thousands of objects, but when attempting to create a policy based forwarding rule for a specific app (in my example, ms-teams), it does not appear in the drop down options in the Application drop down. Can anyone guide me on the best way to setup PBF for ms-teams? Th...

ccarter by L1 Bithead
  • 8468 Views
  • 4 replies
  • 0 Likes

Paloalto TAC support

Anyone here using Paloalto products happy with TAC support? I do not use TAC often but it seems like there are not enough TAC engineers to provide support to customers. For example, every time I call into PAN phone support, the average wait time is 25 minutes. As for a specific example,I called into Paloalto TAC support this morning, and I've ...

dtran by L4 Transporter
  • 16311 Views
  • 19 replies
  • 1 Likes

Resolved! Suggestion for support

Hi I notice a lot of my other venders allow for uploads direct from their device. Can palo alto do that. if I go to the support page for the device there should be an option to upload direct from the device with a case number or something like that. save me having to download - usually over slower comms and then re upload Simple thing, mak...

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels