General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

High Availability - Active goes down due to non-functional

Hello all,Last Sunday (6/26) at 5:37:27 PM, a failover occurred due to an Ethernet 1/22 interface down on the customer's Active Firewall. I have looked around the log to analyze the cause, but the CPU was not high and I couldn't find the cause. The figure below is ha-agent and route log. Do you know why such an error occurs? <routed.log>&l...

스크린샷 2022-06-27 오전 10.46.00.png
스크린샷 2022-06-27 오전 10.41.40.png
스크린샷 2022-06-27 오전 10.39.31.png

Incoming Email Not Flowing

Having an issue with my deployment. Incoming email is not flowing when deploying the PA. The cloud spam filter will not connect to the spam appliance (in DMZ) I can connect to the spam appliance with the external IP address so I believe NAT is not the issue I am also testing with any service until it connects. I included policy screenshots above...

Screen Shot 2022-07-17 at 1.15.31 PM.png
Screen Shot 2022-07-17 at 1.11.28 PM.png

Resolved! Aged Out in allowed traffic logs

Hi All, I have a doubt regarding aged-out feature in palo alto firewall.We are getting logs with allowed traffic towards different ports like port 23, 1433 etc.The device action is allow and in reason aged-out. I want to know that whether the traffic is really allowed or not. This is making too much confusion and kindly help me with this doubt....

ahmdsmr by L1 Bithead
  • 341247 Views
  • 11 replies
  • 0 Likes

SDWAN Zone Mapping

Trying to make sure I understand this correctly. For each zone to used within the SDWAN they must be mapped to the pre-defined SDWAN zones. For the following example would this be the correct method of mapping: Pre-SDWAN zones (same zones at all sites)UntrustPrivate WANTrust-1Trust-2Trust-3 SDWAN Zone MappingZone Internet: Untrust Trust-1, Tru...

Resolved! Can there be fallback authentication for GlobalProtect?

I ran into a scenario that rendered me useless remotely, and I'm wondering if I can configure secondary authentication for GlobalProtect...I used GP to VPN in remotely. My GP is set up to authenticate through Active Directory, and it works fine. I was updating my VMWare environment and SAN, in which I needed to power down all VMWare servers (i...

uscit by Not applicable
  • 5061 Views
  • 2 replies
  • 0 Likes

GlobalProtect agent download from direct URL

Hi everyone, Do you know if it's possible to block the download of the globalprotect agent via the direct URL ? The goal here is to force users to authenticate in the portal web page to be able to download the agent. Ex. for the 64bit agent :https://<my-portal-address>/global-protect/getmsi.esp?version=64&platform=windows If yes, could...

FabienJ by L2 Linker
  • 18324 Views
  • 19 replies
  • 0 Likes

can we allow sign in to webex only using defined company account ?

I have followed below article and tried to configure http header insertion in URL filtering profile , but still able to login using other company account.https://help.webex.com/en-us/m0jby2/Configure-a-List-of-Allowed-Domains-to-Access-Webex-While-on-Your-Corporate-Network#task_C0E05337A65BA687DD68241E79076D38 Also in url filtering log, no logs ...

Deepak25 by L3 Networker
  • 6225 Views
  • 4 replies
  • 0 Likes

Resolved! Aged Out Traffic

Hi All, Please help me on this. If I am doing telnet from one server then telnet is working fine but in firewall I can see the traffic is aged out.I need to know if any traffic is getting aged out, then it should not allow the traffic but how the traffic is allowed and also the person can do telnet.

PPradhan by L1 Bithead
  • 3945 Views
  • 1 replies
  • 0 Likes

Web Management GUI-SSL/TLS - Palo Alto Firewalls HA Active-Passive

Certificate doubt for Web Management GUI-SSL/TLS - Palo Alto Firewalls HA Active-Passive Good afternoon community,, I have an important question regarding the use of custom certificates for web-gui management. I understand that there are configuration parameters that are not synchronized and are detailed in these two links: https://docs.palo...

Metgatz by L4 Transporter
  • 5661 Views
  • 4 replies
  • 0 Likes

Problems to upgrade the OS.

Using the http portal I´m trying to download the OS version. I have installed the 9.0.5 version and trying to reach 10.1.10 h1. the problem is when I press check now to see the OS versions availables, does not appears nothing new, and in don´t the chance to download/install newer versions. I´m using dns 8.8.8.8 4.4.2.2 also tried 1.1.1.1  

PA downloads.jpg

questions to advanced url filtering

Hi all, I renewed licenses and bought the new adv url subscription which is already activated in my customer portal. However, my firewall still has the legacy url license active. 1) Do I need to import the adv url license manually? What happens to the legacy license? 2) Is there any impact when switching from legacy to adv? 3) There is a PA 220 ...

DVB_Bank by L1 Bithead
  • 3272 Views
  • 3 replies
  • 0 Likes

Resolved! Auto-commit failing: interfaces down, not able to force commit

We are struggling with the following error and Palo Alto TAC is not able to provide the proper support, they are just asking us to do an RMA or to factory reset, but the truth is that we are having the same issue in 2 different firewall clusters with different configs and specs. After the firewalls powers on/reboot the "auto-commit" gets stuck a...

MarcelST_1-1606948327447.png
MarcelST_0-1606948079053.png
MarcelST by L3 Networker
  • 32098 Views
  • 9 replies
  • 0 Likes
  • 24436 Posts
  • 125 Subscriptions
Top Solution Authors
Labels