General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4227 Views
  • 0 replies
  • 0 Likes

Palo Alto blocks legitim applications

Hi everyone,We have defined Risk App block rule which contains the app by risk category, characteristics and vice versa.After upgrading PA to 10.1.5-h1 version it starts to block ssl, web-browsing, google-base, whatsapp and other apps which are not among apps which is blocked by my defined rule.I'va looked for matching apps in app filters, but t...

OGasimli by L0 Member
  • 2518 Views
  • 1 replies
  • 0 Likes

Okta has 400+ IPs that are all /32. Looking for an EDL solution

Has anybody figured out an edl to allow communications to Okta without manually entering the whole list? My customer is using Okat for MFA and the Okta Portal uses a whitelist so they have policies that anything hitting Okta should use ip x.x.x.x. This is legacy config from a newly replaced firewall. FQDN Address objects are only reporting 2 I...

No change in retention of summary log after the log storage allocation update

Current panorama and log-collector issuesPanorama – mgmt. server only – SW-version: 9.1.12-h3Log-collectors :PAN02- – PAN03 – same SW version as Panorama 1.The summary log retention days did not change after the log storage allocation updatePAN02> show log-diskquota-pctcfg.diskquota.pct.config: 25.000cfg.diskquota.pct.detailed: 80.000 --à...

Pras by L4 Transporter
  • 3012 Views
  • 3 replies
  • 0 Likes

Cortex XSOAR search "contains" instead of "equals"

Hello Is there a way to search a Domain in Minemeld with "contains" instead of "equals"? As example: We have entered *.blabla.com" in one of our Nodes. I would like to search for blubb.blabla.com - which of course does not match. Also "blabla.com" will not work... Does anyone have any Idea about? thanks

Apply QOS for a particular Server published to internet

Hi Team, We have a SFTP server behind our firewall and its NATed to one of the interfaces of the firewall , we need to restrict the bandwidth to the SFTP server from Internet. When clients from internet connects to the server for downloading files they will be restricted to use 10 Mbps only. The generic KB is not helping in this case Thanks,Sam

Resolved! DH Group 24 phase 2

Hi all,could you confirm that pan does not support dh group 24 in phase 2?I've a peer that (just a test, is an android device with native ikev2 psk vpn configured) asks for that group and I got this errorDH group id 24 != 20, responding with INVALID_KE_PAYLOAD Thanks

N2Z2 by L2 Linker
  • 4137 Views
  • 1 replies
  • 0 Likes

Palo Alto Network Service Route IP List

Hello all,please excuse me if I am posting this question in the wrong section. This is my first LIVEcommunity post and I wasn't sure about the section I chose.Several of our customers would like to know exactly which Palo Alto Network services are hosted where. The customers found out that some services are hosted in Amazon IP ranges and they wo...

ThorbenH by L0 Member
  • 2172 Views
  • 1 replies
  • 0 Likes

Upgrade PanOS to 9.1 from 8.1

Hey all. I've come up wtih an upgrade plan to get us from 8.1.10 to 9.1.12-h3 based on reading resources. I would love some feedback on whether this is the correct process. THanks much. 8.1.10 Current SoftWare Version5.2.8 Global Protect VersionFirewall A = currently active firewall, firewall B = currently passive firewall)Download PAN-OS 8.1...

GlobalProtect MFA with Office 365

Hi, II am looking for information on how to configure GlobalProtect MFA with Office 365. I would appreciate if you have any information that you can share. GlobalProtect

Tamaris by L1 Bithead
  • 4470 Views
  • 2 replies
  • 0 Likes

Where is support?

Have a high severity ticket open for 2 DAYS now and not even an email. Stuck in support queue.Called support number this morning and on hold for 1 HOUR trying to speak with someone..This isn't what my company paid $$$ for.

Resolved! Unable to see vCenter Tags or vCenter Custom Attributes on FW or Panorama

I have the Windows User Agent configured with VM Information sources and I'm able see see a lot of information about the VM with the exception of vCenter Custom Tags an vCenter Custom Attributes. I can see annotations no problem, as soon as I change or add notes they appear immediately in both Panorama and the firewall, but what I really need i...

  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels