General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

How do the 5450 logical card slots and associations work?

I see the documentation that shows information regarding slot 1 and slot 3 and how a NPC associates to a DPC.   And if you add a NPC to slot 2 it will associate to a DPC in slot 4.   What I don't see is if you add more DPC's, how that associates to t

...

Sec101 by L4 Transporter
  • 1430 Views
  • 0 replies
  • 0 Likes

Resolved! PAN URL DB not getting update.

Hi Team,

 

I have 3 firewalls in my different loctions, All 2 firewall URL Update version is up to date. Only one firewall is a lower version. 

 

Also, I identified lower version firewall having a different update server when I checked the show url-cloud

...

VishnuPS by L3 Networker
  • 33560 Views
  • 20 replies
  • 0 Likes

Resolved! End-of-Life Date 8.0 - October 31, 2019

Hi, 

I found, what End-of-Life Date for PAN-OS 8.0 is October 31, 2019

https://www.paloaltonetworks.com/services/support/end-of-life-announcements/end-of-life-summary

 

We are using version 8.0.13 with active subscriptions.

1. Will we receive updates (Ant

...

aaobuhov by L2 Linker
  • 7197 Views
  • 5 replies
  • 0 Likes

Resolved! Management interface is down.

I found on my firewall that management interface is not able to communicate with LDAP server and so on. From the GUI it look everything is configured correctly but when I switched to CLI, I found that management interface is down.

Link status: Runti...

Henley by L1 Bithead
  • 4957 Views
  • 5 replies
  • 0 Likes

Resolved! Cannot Access Web Server External Only Internally

Hello,

 

I am trying to deploy a new PA850 and I am unable to access any web servers externally. I can access internally using the public IP using I believe the u-turn policy. Any help would be appreciated Thank You, MJF

Screen Shot 2021-10-29 at 10.14.43 AM.png
Screen Shot 2021-10-29 at 10.15.04 AM.png

Disable weak cipher suite in SSH

I would like to disable weak cipher suite in SSH for over 100+ Firewalls with the following commands.  The firewalls are running in High-Availability (H/A) mode, version 9.1.10:

 

configure
set deviceconfig system ssh ciphers mgmt aes256-ctr
set deviceco

...

dtran by L4 Transporter
  • 4149 Views
  • 7 replies
  • 0 Likes

User mapping not happening properly

We have recently added a user in the server list.

We are able to see the user in LDAP but when it comes to firewall we are not able to see the user in security policy.

When i checked the user with following command

show user ip-user-mapping all | match

...

Resolved! Globalprotect Portal same IP w/ management interface

Hello,

Before setting up globalprotect portal, I could access the management interface using the public IP externally. Once I configured globalprotect portal for VPN, the IP now directs you to globalprotect welcome login page. Which is normal, cause I

...

icap by Not applicable
  • 7126 Views
  • 5 replies
  • 0 Likes

Generated traffic logs showing weird information

I have a VM-500 panos-8.1.18. I am seeing traffic logs with below flags

Session End Reason- policy-deny (means traffic denied as per policy)

Action -Allow ( how can action be allowed when traffic is denied via policy)

Type- deny

 

We also have ssl decrypt

...

Configure secrets/psk with Ansible 'panos_type_cmd'

Hi,

 

When using paloaltonetworks.panos collection - module 'panos_type_cmd' is there any way to set secrets or psk without using the real password?

 

Configuring via plaintext password works fine and then when viewing the xml config the passwords are st

...

How do I set bgp auth-profile secret in XML?

<auth-profile>
<entry name="BGP">
<secret>-AQ==9wW2MMYTyjIArw6U5IgQlTHDTnc=zwKe7XpB+qQLdlenAO8tkg==</secret>
</entry>
</auth-profile>
 
The configuration appears to be encrypted, maybe using the master key or something. Is there anyway to set this in XML c
...

Resolved! IKE Error

In my system logs I'm seeing the following error:

 

"IKE phase 1 negotiation is failed. Couldn’t find configuration for IKE phase-1 request for peer IP x.x.x.226[500]."

 

The bizarre thing is that the tunnel IS working despite this error!!!

 

The reason fo

...

RSteffens by L3 Networker
  • 4259 Views
  • 2 replies
  • 0 Likes

Can we use SFP+ with PA-820?

Hi, Guys. I plan to use the PA-820.
The PA-820 has only two HA ports.
I am planning to substitute the HA ports with SFP ports.
Can I use the PAN-SFP-PLUS-CU-5M with the PA-820?
The PAN-SFP-PLUS-CU-5M is cheaper than the PAN-SFP-CG, so I would like to use

...

Lisa_35 by L0 Member
  • 2148 Views
  • 1 replies
  • 0 Likes
  • 24130 Posts
  • 102 Subscriptions
This widget could not be displayed.
Top Solution Authors
Top Liked Authors
Labels