General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4226 Views
  • 0 replies
  • 0 Likes

GlobalProtect Split-Tunnel - Some Clients get Invalid Address Errors to Excluded Domains

We've published GlobalProtect 5.0.5 I added some Exclude Domains and Applications to our Gateway's Split-Tunnel configuration over the weekend. Afterwards, about 5-10% of our VPN clients can not access these domains at all while on VPN. The domains work fine when disconnected. We've had reports of problems with Mac and Windows, but all of my ...

Resolved! Log : disk usage for / exceeds limit, 95 percent in use, cleaning filesystem

Dear Team, I checked the following log in the system log. > disk usage for / exceeds limit, 95 percent in use, cleaning filesystem However, when checking with the 'show system disk-space' command, the free space is checked as shown below. I know that if the disk capacity is full, it is necessary to take action through the 'debug softwa...

CHOEKyungJun_0-1659340889213.png

Resolved! adding Switches to HA Pair

I would like to add a 24-port switch to each Palo. To maintain HA redundancy, I just have to run the HA Control across the switches right? Does the Session Link have to go through the switches too?

i have the palo alto vm 10.0.3 version , need help

Using this image for labbing on EVE-NG pro and i cannot create a working active standby cluster as both instances of the node that i created have the same serial number, is it possible to change the serial number of the node upon creation? what is the solution? i do have 9.1.2 which might work for clustering but this is the only 10.x image i h...

kbk983 by L0 Member
  • 2048 Views
  • 2 replies
  • 0 Likes

Config changes retention in Palo Alto For non root user with read only admin access

Config changes retention in Palo Alto For non root user with read only admin access Hello All, I have recently come across the issue of read only admin access config change 10-15 days back but same not reflecting in the commit when I checked. So, my main query is that for many days the changes will remain as it is in commit for read only adm...

LalitaS by L0 Member
  • 1680 Views
  • 1 replies
  • 0 Likes

GlobalProtect Cloud Services Route Precedence

We have had overlapping subnet scenarios where someone is connecting using GlobalProtect Cloud Services from a subnet that overlaps our internal subnet and, as they have a more specific route, access to internal resources is failing as the taffic is being routed via the local router instead of over the VPN due to the more specific route. Due to ...

TCP session timeout behaviour

Hello, I have a question about the mechanism of TCP session timeout on PA FW. Assuming that default TCP timeout on PA device is 3600 seconds. What happen after a TCP session is idle after 3600 seconds ? Does the FW send TCP RST at each endpoints ? Or does it just delete the session from its sessions table ? And in this case if a new packet is se...

How do I remove KEX diffie-hellman-group1-sha1 from SSH on PAN-OS 8.1?

Our vulnerability scanner has detected a weak KEX algorithm (diffie-hellman-group1-sha1) on our firewall. Is there a persistent way to disable the weak KEX algorithm? I found this article (below), but it says every time the firewall reboots the weak algorithm becomes enabled again.https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=k...

pdwilson by L1 Bithead
  • 3078 Views
  • 2 replies
  • 0 Likes

Resolved! User-ID-Agent wrong mapping with specific IPs

Hello,since a few days we see strange things with User-ID-agent.For some specific IP-addresses there are shown wrong users. This users even are not in the internal AD, they are just external VPN users invited from Azure. But they are mapped to internal ip addresses. Even if they are not online over VPN.When looking into Monitor - User-ID in the ...

Global Protect error Windows 7 Client

Good afternoon, first of all thank you very much for the help and support for this case: "The virtual adapter was not set up correctly due to a delay. GlobalProtect will try again soon. If the issue persists, please restart your system" -Windows versión: Windows 7 64bit SP1-Global Protect Client: 5.1.8 64bit I have already restarted the computer...

Error_Gprotect_Win7_2021-08-24 at 17.52.48.jpeg
Metgatz by L4 Transporter
  • 3270 Views
  • 2 replies
  • 0 Likes

Resolved! VPN to AWS with BGP

Hello, I have 3 locations that I need to create VPNs to AWS for. Each location is dual ISP using PBF. Since AWS uses 2 tunnels each VPN connection, seems there will be 4 total tunnels per location (2 per ISP). My initial thought was to use static routing but I'd like to avoid any asymmetric routing from AWS. In these locations, we are usi...

mnashe by L1 Bithead
  • 12166 Views
  • 5 replies
  • 0 Likes

bgp cmd

Hi All , Just checking what cmd we can use to validate receive and adversities BGP route from a peer like we have in cisco . @PavelK

  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels