General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4469 Views
  • 0 replies
  • 0 Likes

VPN Drops after 1 minute with the error ike-nego-p2-proxy-id-bad

Hi, I am new to the palo and have run into this problem that I can't figure out. We have a VPN between the Palo and a Meraki. It's usually on permantly but recently it has been having drop outs, sometimes for days. I have realised that if I disable the tunnel and re-enable it, it comes back on but only for a maximum of 1 minute and then I get th...

Palo Alto Routing course

Howdy everyone, I have taught the foundations course...that was pre-covid. Now I am tasked with teaching routing. Which Palo-Alto class would the community recommend from your experiences that I teach? Thanks, JB

DIP NAT on inter vsys traffic

Hello, I have a FW that has many nat rules. And I found a bug, pan-130550:(PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls) For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.Workaround: Use source NAT with Dynamic IP and Port (DIPP)...

yhlee1 by L2 Linker
  • 3226 Views
  • 2 replies
  • 0 Likes

Critical System Log Msg

Hi All, Have you guys seen the below critical msg in the system log? Backtrace execution for the restarted process stopped due to an error accessing memory. Possible memory corruption? P.S: this is the passive firewall when the active FW went down. Many Thanks,

Pras by L4 Transporter
  • 3101 Views
  • 3 replies
  • 0 Likes

Resolved! Paloalto ms-kms application

Dear Team, The description of the ms-kms application is as follows. DescriptionMicrosoft Key Management Service (KMS) activates computers on a local network, eliminating the need for individual computers to connect to Microsoft. To do this, KMS uses a client-server topology. KMS client computers can locate KMS host computers by using Domain Name...

ConnectWise Control connection getting reset

Latest spyware signatures appear to be blocking legitimate connections to ConnectWise control. The 5/2 AppThreat-8564-7375 update categorizes the connection/file (GetSessionDetails) as threat Generic PHP Webshell File Detection.Produces "unknown error" on the ConnectWise portal page.The only way I can get around it is to exclude the connectwise ...

WAN Interface IP change - after Wildix phones still work, Yealink phones don't!

Hi all, looking for advice following what is in my opinion very unusual behavior. Where I work for, we have a PA220 running Firmware version 9.0.3 that is used as the firewall for VoIP traffic for physical desk phones. We have two brands of IP based desk phones; Yealink and Wildix. Both types/brands connect to our cloud hosted Wildix PB...

eveares by L1 Bithead
  • 5078 Views
  • 3 replies
  • 0 Likes

DLP product that will integrate with PA decryption broker?

All the DLP products I have researched require ICAP capability which the PA doesn't support. Does anyone know of a DLP product (network appliance or VM not client based) that will actually work with the decryption broker solution? Please don't suggest the Palo Alto DLP as it was not adequate in our testing.

Resolved! RDP through GP tunnel with a different user.

Hi All, I have a client that has recently run into an issue, after upgrading to PAN OS 10.1.2. When they connect to Global Protect with their username and then try to RDP through the GP tunnel to a server on site using a different user account that is not in the allowed GP user AD group, the GP tunnel looks to freeze (doesn't disconnect) and all...

Ben-Price by L4 Transporter
  • 9744 Views
  • 11 replies
  • 0 Likes

Traffic Logs show 2 different source users from same IP

We are using User Identification and have the user-id agent running on 2 different AD servers. Also using global protect. When looking at traffic logs I can filter on my GlobalProtect VPN IP, I can see the source user of my user account, and a source user of another account. When looking user-id mappings, and look at my VPN IP, I only see my ...

image.png
image.png

failover between sites

Hi, Hi , I have two sites , between sites layer 3 connection is there .single firewall deployed in each site .Now I want to make active standby with these firewalls .How can I do that , does it work without any problem ?What need to be dome to make it work Thanks

site to site.JPG
simsim by L4 Transporter
  • 3661 Views
  • 4 replies
  • 0 Likes
  • 24379 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels