General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

How Do I Actually Get Support From Palo Alto?

So I purchased premium support for my device but when I go to the website to create a support ticket, I get to a point where the ticket is blocked by a window telling me that I am being redirected to the live community. If I click continue a new tab opens to to this site. If I click cancel they close my ticket. There is no way to go back to the ...

Radius Accounting

Is there a way to configure the boxes to act as a NAS by sending a Radius Server (like Freeradius) accounting information? I am particularly interested on the session start and session stop attributes. I am about to provide Globalprotect VPN access to a community of users and need to account the resource use in the same Radius server where the a...

Error while disabling tunnel.

Hi All,We are running PA with firmware 9.0.4 Getting errors while "disabling" not required/unsed IPSec tunnel. Error: tunnel interface tunnel.50 encap interface is not set.Error: parse tunnel member failed.Error: error parse qos tunnel groupError: error parse tunnel-traffic group listError: alloc obj iterator failedError: QoS configuration error...

Jimmy20 by L2 Linker
  • 6820 Views
  • 3 replies
  • 0 Likes

Rules from One Zone to another Zone

Hello All, from the GUI i can get all the security policies from one zone to another, However, from the CLI, is there a way? for example : i need all the policies from Orange_Zone to Free- App_Zone "Orange to DEVDB11-1; index: 1333" {from Orange_Zone;source 172.24.x.x/24;source-region none;to Free-App_Zone;destination 172.24.x.x;destinatio...

User-ID Agent

Hello! I have a Palo Alto with version 9.1.5 installed and I want to install a User-ID Agent, which version can I install?

Rate increase in flow_ipv6_disabled

Hi All, Is there any way to check which source of this flow_ipv6_disabled? Our monitoring tool keeps on alerting us due to these parse packet drops. When I run the command below, I don't see any logs on Palo Alto's monitor. debug dataplane packet-diag set log counter flow_ipv6_disabled Thank you in advance.

mudvayne15_0-1661210191059.png

Resolved! URL Filtering Version

Hello - I have a question about versioning. Some of my HA pairs have all zeros, some have a matching versions and some a mismatch of zeros and a version. Seems to be no rhyme or reason. How can I correct this? For example: fw(passive)> show url-cloud status PAN-DB URL FilteringLicense : valid Cloud connection : not connected URL database...

Resolved! IPSec tunnel slowness issue

Hi Folks, We had recently configured an IPSec tunnel between the PA and the Cisco Meraki firewall. The PA firewall is located in India and the Cisco firewall is located in USA. We are trying to upload an file from an Linux host located behind the PA firewall to an server located behind the Cisco firewall using wget http option from linux ...

Quic / HTTP/3 whats palo doing about this

Hi Wondering what the road map is for allowing this - but safely - ie decrypting etc looks to me like http/3 is going to be moving ahead and looking at a lot of the material its going to be very beneficial - especially in the space of speed / latency. So simply blocking QUIC at the firewall is not going to be an acceptable solution any more....

Dual ISPs VPN failover across both

Trying to provide some tunnel redundancy to some of our AWS environments. I have 2 ISPs both with an interface/static IPs on my HA PANs. ISP-A is my default with a default route to the internet pointing to its next hop. ISP- A Eth1/8 9.9.9.9/24 ZONE-A ISP-B Eth1/7 10.10.10.10/24 ZONE-B Currently have all my VPN tunnels across ISP-A and want...

drewdown by L4 Transporter
  • 3173 Views
  • 2 replies
  • 0 Likes

Resolved! Issues with Dual ISP Failover

I followed these instructions to set up ISP failover : https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO When the primary ISP1 goes down, it does indeed fail over to secondary ISP2, in every respect except that traffic doesn't use ISP2's NAT automatically. Upon failover, traffic continues trying to use the NAT r...

Rule Shadow count not working

Hi, everyone. I'm currently working on a new config for a couple of firewalls, but everytime i commit my config I get rule shadow warnings (valid ones) but I can't use the count link to get a list of the shadowed rules. I'm running 10.1.6; is this a bug or am I missing something here? Additional info: already tried rebooting the fw and refresh...

CMachado_1-1660849741876.png
CMachado by L2 Linker
  • 2960 Views
  • 3 replies
  • 0 Likes

Resolved! Best practices - Multi large upgrades pan-os Firewall HA

Best practices - Multi large upgrades pan-os Firewall HA Good afternoon, as usual, thank you very much for your support and collaboration. We have the possibility with a customer to perform multiple upgrades in one day, maintenance window. We need to move from 8.1 to 9.1, i.e. 8.1.x to 9.0.x and from 9.0.x to 9.1.x. So the question is the fo...

Metgatz by L4 Transporter
  • 4808 Views
  • 4 replies
  • 0 Likes
  • 24428 Posts
  • 125 Subscriptions
Top Solution Authors
Labels