General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4105 Views
  • 0 replies
  • 0 Likes

Problems to upgrade the OS.

Using the http portal I´m trying to download the OS version. I have installed the 9.0.5 version and trying to reach 10.1.10 h1. the problem is when I press check now to see the OS versions availables, does not appears nothing new, and in don´t the chance to download/install newer versions. I´m using dns 8.8.8.8 4.4.2.2 also tried 1.1.1.1  

PA downloads.jpg

questions to advanced url filtering

Hi all, I renewed licenses and bought the new adv url subscription which is already activated in my customer portal. However, my firewall still has the legacy url license active. 1) Do I need to import the adv url license manually? What happens to the legacy license? 2) Is there any impact when switching from legacy to adv? 3) There is a PA 220 ...

DVB_Bank by L1 Bithead
  • 3109 Views
  • 3 replies
  • 0 Likes

Resolved! Auto-commit failing: interfaces down, not able to force commit

We are struggling with the following error and Palo Alto TAC is not able to provide the proper support, they are just asking us to do an RMA or to factory reset, but the truth is that we are having the same issue in 2 different firewall clusters with different configs and specs. After the firewalls powers on/reboot the "auto-commit" gets stuck a...

MarcelST_1-1606948327447.png
MarcelST_0-1606948079053.png
MarcelST by L3 Networker
  • 31335 Views
  • 9 replies
  • 0 Likes

Auto-commit after upgrade to 10.0.0 fails

Hi all, After upgrading a PA-220 from 9.1.13 to 10.0.0 Data plane is not coming up as auto-commit keeps failing. The only info i got so far is as shown:I have downgraded the PA back to 9.1.13 and the auto commit is successfull after reboot. However when i upgrade back to 10 it fails.As anyone experience this? How can i troubleshoot this further?...

GnContente_0-1646686454846.png

Upgrade 9.1.0 to 10.0.0 PA220

Hello, im experiencing issues with upgradeing my PA220 from 9.1.x to 10.0.0.The new software installs, but autocommit fails after upgrade. So i figured i had something in my config that is either changed or not supported in 10.0.0, so i wiped my box clean witha debug command and booted it up in 9.1.0 without config. Then tried to upgrade to 10.0...

UI issues in PAN OS 10.1.5-h1

Hi All, I seem to have run into some minor UI bugs in PAN OS 10.1.5-h1: 1. When you open a security policy rule, the tags section is squashed and you cant re-size it or click the drop down (see below)2. When you click on the contextual help in the Web GUI, the help webpage that usually loads just seems to go into to some sort of loop and never f...

BenPrice_0-1650351175218.png
Ben-Price by L4 Transporter
  • 8410 Views
  • 10 replies
  • 0 Likes

Resolved! HA failover if Running Config is not synced

If on Active Passive PA both shows running config not sync Say failover happens for somereason or we trigger the manual failover bgy suspending the active PA will then Passive PA becomes active and start passing the traffic even though running config is not syc between two?

MP18 by Cyber Elite
  • 6742 Views
  • 5 replies
  • 0 Likes

Suggestions for Splunk Search/Report

I have several Splunk searches that I use as indicator lists. Has someone already built a miner/prototype to retrieve these? The generic API examples don't seem sufficient for Splunk's two-step routine (search then retrieve results). https://docs.splunk.com/Documentation/Splunk/latest/Search/ExportdatausingRESTAPI

10.1.6 HA running Config not synchronized - PA 850

Hi All, I have two standalone FWs in HA. There running config was working fine but for sometime it's not synchronized and I can see below on the dash board. Need your expert suggestion to resolve this. - disk space is below 80 % on both FWs - ran >request high-availability sync-to-remote running-config on primary and comitted on the peer FW ...

paragkarki143_1-1657261178378.png
paragkarki143_0-1657261867123.png
Pras by L4 Transporter
  • 4082 Views
  • 4 replies
  • 0 Likes

Resolved! "Decrypted" column in exported CSV of Traffic log?

When viewing the Traffic Log in the GUI, there is a column for "Decrypted" (yes/no). However when I export the Traffic Log to a CSV, I don't see a column with the same or a similar name. How would I identify which connections were decrypted by looking at just the CSV file?

Resolved! Sort columns in Monitor tab?

I feel like an idiot, but how do I sort the columns in my monitor tab? The used to be sorted by generate time, but that doesn't seem to be the case anymore.

mcocat by Not applicable
  • 10405 Views
  • 5 replies
  • 0 Likes

Secondary interface on same subnet creates overlapping subnet commit failure

Hello all, I currently have a case open with support on this issue. But I am looking for some customer feedback. We presently have *two routes* and two separate firewalls. 10.0.44.1/22 on my Palo Alto, and 10.0.45.1/22 on a legacy Cisco L3 router. The Cisco has been stripped down and only really serves as a default route to a end of life firew...

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels