General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4464 Views
  • 0 replies
  • 0 Likes

Resolved! HA failover if Running Config is not synced

If on Active Passive PA both shows running config not sync Say failover happens for somereason or we trigger the manual failover bgy suspending the active PA will then Passive PA becomes active and start passing the traffic even though running config is not syc between two?

MP18 by Cyber Elite
  • 6902 Views
  • 5 replies
  • 0 Likes

Suggestions for Splunk Search/Report

I have several Splunk searches that I use as indicator lists. Has someone already built a miner/prototype to retrieve these? The generic API examples don't seem sufficient for Splunk's two-step routine (search then retrieve results). https://docs.splunk.com/Documentation/Splunk/latest/Search/ExportdatausingRESTAPI

10.1.6 HA running Config not synchronized - PA 850

Hi All, I have two standalone FWs in HA. There running config was working fine but for sometime it's not synchronized and I can see below on the dash board. Need your expert suggestion to resolve this. - disk space is below 80 % on both FWs - ran >request high-availability sync-to-remote running-config on primary and comitted on the peer FW ...

paragkarki143_1-1657261178378.png
paragkarki143_0-1657261867123.png
Pras by L4 Transporter
  • 4169 Views
  • 4 replies
  • 0 Likes

Resolved! "Decrypted" column in exported CSV of Traffic log?

When viewing the Traffic Log in the GUI, there is a column for "Decrypted" (yes/no). However when I export the Traffic Log to a CSV, I don't see a column with the same or a similar name. How would I identify which connections were decrypted by looking at just the CSV file?

Resolved! Sort columns in Monitor tab?

I feel like an idiot, but how do I sort the columns in my monitor tab? The used to be sorted by generate time, but that doesn't seem to be the case anymore.

mcocat by Not applicable
  • 10634 Views
  • 5 replies
  • 0 Likes

Secondary interface on same subnet creates overlapping subnet commit failure

Hello all, I currently have a case open with support on this issue. But I am looking for some customer feedback. We presently have *two routes* and two separate firewalls. 10.0.44.1/22 on my Palo Alto, and 10.0.45.1/22 on a legacy Cisco L3 router. The Cisco has been stripped down and only really serves as a default route to a end of life firew...

Inter Vsys Routing

Can someone give me some advice please. In the attached diagram is a scenario I have where I need to get traffic logs from Virtual Firewall B across to Virtual Firewall A an up to the SIEM at the x.x.x.x address. I have made the virtual systems visible to each and added a route to x.x.x.x on virtual router B to go via virtual router A to get to ...

Global Protect certificate auth user/device information

Currently we have a GP vpn setup for our mobile devices. We have are doing certificate based authentication, certificate is pushed out through an MDM. Basically if your device has this cert, your device connects. Is there a way to capture or pass through connected user information, for example username, email, etc.? Right now when looking at...

Doubt with Subordinate-CA Cert in PA firewall

Doubt with Subordinate-CA Cert in PA firewall Good evening, for issues related to for example decrypt as we need a certificate type CA, we can generate a certificate Subordinate-Ca from for example our CA server enterprise windows, import in our Palo Alto Firewall and as customers trust it, it would be transparent for issues such as the use of...

Metgatz by L4 Transporter
  • 3272 Views
  • 1 replies
  • 0 Likes

twistlock.sh onebox failure

The following warnings are reported when executing "twistlock.sh -s onebox" WARNING: You're not using the default seccomp profileWARNING: IPv4 forwarding is disabledWARNING: bridge-nf-call-iptables is disabledWARNING: bridge-nf-call-ip6tables is disabledInitializing Twistlock environment.Installing Twistlock Console (localhost).WARNING: You're n...

IP Geolocation with Anycast IP addresses

Hi there, I am wondering how geolocation is working with IP addresses where anycast is used. Anycast addresses are shared by multiple server, typically with different locations. How is such an address assigned to a particular country/region in the Geolocation DB? Does anybody know? Thanks, Sylvia

Sylvia2 by L2 Linker
  • 4140 Views
  • 2 replies
  • 0 Likes
  • 24379 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels