General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! log forwarding to syslog | drops and queue

Hi everyone, Can anyone advise what's wrong here. Issue with log forwarding to syslog PA 3250 running on 11.1.6-h10. Only few logs are being sent to server, others are dropped. Here is the flooding messages in the logrcvr log file:2025/08/11 16:34:09 2025-08-11 16:34:09.382 +0400 Error: pan_logforward_enqueue_new(pan_logforward.c:2996): LOG...

Traffic Logs missing from subset of datetime range when using certain filters?

Has anyone run into a problem with Traffic Logs not returning any results with a certain period of a larger time range? I have been running a daily traffic analysis of a particular destination network (do to a vendor issue). Today's analysis of yesterdays traffic partially failed as a roughly 15min period is completely missing from the Traffic L...

Resolved! maximum number of bgp routes

hi,is there a maximum number of bgp route entries supported for the 5000 series ? does it support a full ipv4 routing table ? i cannot find any docs or data sheets with this kind of limits detailed...thanks

Split tunnel is not working for Linux/IOS devices

Hi, I have a VPN-SSL GP in a FW PA. I have some "Acess routes" in include for LAN ranges (10.0.0.0/8 and 192.168.x.x) and the rest should go through ISP local user. The issue is that I'm seeing traffic destined for the internet that shouldn't be reaching the FW via the VPN. Goiing to agent logs i can see all routes in Linux client as OK. Default...

BigPalo by L4 Transporter
  • 5090 Views
  • 6 replies
  • 0 Likes

Resolved! Does anyone know the API XPATH to load partial for static routes?

Hello All! I'm trying to use Expedition to migrate 100+ virtual systems from old Juniper firewalls my team inherited to our Palo Altos. We are using Load Partial commands rather than importing the entire Expedition output based on recommendations from Palo Engineers. Some of my Juniper stuff has large routing tables of static routes, so I wa...

Resolved! A question about snat address pool couse a route loop

Dear all I have a question about snat address pool and route loop; If I set a snat policy and assign a public address pool(range)to it, like 110.1.1.1 to 110.1.1.11 PS. It's being used for visit internet; I have a default route to internet on my firewall, nexthop is ISP, and this ISP have a route about 110.1.1.1 to 110.1.1.11 next hop is ...

Aruba Central - Palo Alto - User ID Question

Hey Guys, I have a bunch of access points in Aruba Central, we are currently using UserID as a way to assign username to IP address with Palo Alto. I have found these instructions https://www.arubanetworks.com/techdocs/central/latest/content/aos10x/cfg/services/pan_firewall.htm and preliminary testing seems to be working. Just wondering if any...

Active Directory groups w/ members from multiple domains

I'm using AD groups for some security policies and am expanding to use other domains in our company. While I can add users from another domain into an AD group, the PA only shows me the users in the same domain as the group. For example:Domain 1: DC=first,DC=com User 1: CN=idone,OU=users,DC=first,DC=com Group: CN=cars,OU=groups,DC=first,DC=com ...

Resolved! Unable To Submit Support Case Through Any Method

I have an issue that's affecting sync between HA peers. I've been trying to upload a support file (70mb) for 2 hours now. I have tried using a different browser and even a different computer. If call the North America TAC line the automated system instructs me to enter a ticket online. If this were a critical issue this would be incredibly stre...

CAAdmin by L0 Member
  • 2572 Views
  • 4 replies
  • 0 Likes

Resolved! WEBUI Session Timing Out

Hello, On my PA-820 I started getting the idle timeout message below: "Your login session has expired and you have been logged out for security reasons. Please log in again if you wish to continue." Normally this was never an issue and I simply logged back in after being idle. Starting about 2 weeks ago I cannot log back into the WEBUI under nor...

RH747 by L2 Linker
  • 24930 Views
  • 21 replies
  • 0 Likes

Resolved! TPM public key match failed

I have two PA-400 series devices that failed to renew their device certificates and now I get "TPM public key match failed" when trying to renew their certs. Any way to fix this on my own? I see some posts saying PA support had to fix it, but as of now my 3rd party support provider is being unresponsive 😒

Resolved! OSPFv3 support for IPv4?

Greetings all, I've been looking over some possible improvements to consider as we're moving our firewall deployment closer to production. We've got a lot of Cisco equipment through our core along with a switch VSS that runs various VRFs surrounding the PAN firewall. I noticed the Cisco implementation of OSPFv3 is supporting IPv4 address famil...

jsalmans by L4 Transporter
  • 5176 Views
  • 5 replies
  • 0 Likes

licence activation after full configuration and HA is done

Dear Palo Alto Support,We have configured initial settings and an active/passive HA pair on our firewalls. Before proceeding with license activation, we would like to confirm whether this process has any impact on the existing configuration or HA setup. Could you please advise if the configuration and HA state remain intact after license activation

B.Berasa by L0 Member
  • 659 Views
  • 1 replies
  • 0 Likes
  • 24432 Posts
  • 125 Subscriptions
Top Solution Authors
Labels