General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4111 Views
  • 0 replies
  • 0 Likes

SNMP OID for identifying if an power supply had failed or removed from the firewall

Hi Team, We have an PA-5260 deployed in our environment. We need to get alert on our SNMP Manager when the Power supply to the firewall failed or the power supply had been removed from the firewall. Downloaded the Enterprise MIB file but not able to find the MIB OID for monitoring the power supply. Thanks in advance.

Issue with network driver of PAN-OS 10.1.3 deployed in azure

Hi Folks, We have an PA-VM-100 series firewall deployed in the Azure cloud. We have three NIC cards mapped to the firewall interfaces which is configured as below:NIC card 1 <-----> Management interfaceNIC Card 2 <----> Untrust interface(Ethernet 1/1)NIC Card 3 <----> Trust Interface(Ethernet 1/2) Recently we had upgraded the f...

Global Protect Redundancy

Hi, I would like to set up Global Protect VPN on 2 sites, and have a round robin redundancy between them.i.e. user1 logs on the GP VPN and connects to site A, then user2 connects to GP VPN and connects to site B, and so on... Is this possible? regards,

"You have been logged out due to unknown reason"

Any idea what causes this or how to investigate it? I can see the event as "User Me logged out via Web from My_IP" in the System Monitor tab. Happens intermittently otherwise I'd look at this: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClvyCACThis latest time, I did notice that "'Installed antivirus package: panu...

logged out.PNG

OSPF and BGP Redistribute

Can someone walk me through redistribution of OSPF into BGP and BGP into OSPF I am setting up a new VSYS (already done) with a new Virtual Router to an AT&T AVPN WAN There is a /30 between us and AT&T, and we use eBGP to AT&T. On the other router interface, we use OSPF everything in area 0. Probably no very good reason to clean thi...

birkhojk by L2 Linker
  • 9670 Views
  • 4 replies
  • 0 Likes

U-Turn stopped working after update

After Updating PA850 to 10.1.3, U-Turn to 2019 webserver is no longer working.Firefox Message:Secure Connection FailedAn error occurred during a connection to wdafire.townshipofhamilton.com. PR_CONNECT_RESET_ERRORThe page you are trying to view cannot be shown because the authenticity of the received data could not be verified.Please contact the...

Resolved! Login issues after password complexity change

We changed the password complexity and history settings on our firewall a couple of days ago.After committing the changes the local users are not able to login on the firewall.So we tried to boot into maintenance mode by connecting through a console cable in order to roll back to a older running config.This did not do anything though, because th...

ilirrama by L1 Bithead
  • 5519 Views
  • 5 replies
  • 0 Likes

Are there options in the Palo Alto SaaS Security Inline to block in real time cut/copy/paste/print activities?

Are there options in the Palo Alto SaaS Security Inline to block in real time cut/copy/paste/print activities? I have seen this some other CASB solutions to limit what the web browsers can do in real time not out of band (Palo Alto SaaS Security API) I just wanted to ask as I can't find it.

How to check the utilization of current firewall (eg. sessions, throughput, etc)

Hello,we have plan to upgrade our current PA-3020 firewall to new PA firewall.I would like to know how to check the overall utilization of currently firewall in order to determine the size of new firewall. (eg. the usage of sessions, throughput, total users, etc)I found some cpu and session info under PA Dashboard System Resource and ACC tab but...

zinkt101 by L1 Bithead
  • 5353 Views
  • 2 replies
  • 0 Likes

Resolved! Max allowed additional IP addresses on a layer3 interface

From what I researched the below is the only guidance I could find on the max number of IPs I can put on a layer3 interface. Does anyone know where I can find the specific information per model? "You can enter multiple IP addresses for the interface. The forwarding information base (FIB) your system uses determines the maximum number of IP addre...

DHCP-DNS server integration posisble on a PA-500?

Hi, Is it possible to configure a DHCP server running on the PA-500 to automatically update the records in a DNS server that is separate from the PA-500? Ideally, I would like to have the DHCP server dynamically update DNS records with the DHCP client computers’ information whenever the DHCP server assigns the IP address. Thank you in adva...

PLT_IT by L0 Member
  • 4254 Views
  • 3 replies
  • 0 Likes

sip port 5060 same in source port and destination port

Facing issues regarding traffic flow on PA.Cannot see traffic on PA when the SRC port is 5060 and the DST port is also 5060 and application SIP.Have a rule which permits all the traffic from the source to the destination with all the ports allowed ( Any ).Session end reason - Unknown

Question about NAT

How can you use dynamic source translation with dynamic source address. This is my scenario. Site one Public NAT 1.1.1.1 source address 192.168.2.1Site two Public NAT 2.2.2.2 source address 192.168.3.1 If I want to combine this rule into one Nat rule can I do that? Can't use interface because we have 150+ Nat policy. I used dynamic source addr...

hpatel11 by L2 Linker
  • 2197 Views
  • 1 replies
  • 0 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels