General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4129 Views
  • 0 replies
  • 0 Likes

PA3250 in No Rules/Allow All mode and Public IPs

We are currently testing out/learning with a new 3250 in no rules / allow all traffic mode flowing from ISP > Palo > Cisco ASA (Being Retired). We have two public ips routed to two local static IPs and those have stopped working. Would a policy need to be created so the Palo does the routing and not the Cisco.

jpierce by L0 Member
  • 2451 Views
  • 2 replies
  • 0 Likes

strange behavior of bidirectional NAT

hello All, Today I've spotted weird behavior: We have 2 static bidirectional NAT translations between UNTRUST and DMZ interfaces for public IPs. Also we are allowing certain applications in for those public NATed IPs from any IP addresses using only applications and not service/ports. From logs we see that traffic which is properly allowed and w...

Resolved! Redistribution host address between protocols

Dear experts I set a PA firewall as an ASBR, connects to a RIP and a OSPF area with eth1/1 and eth1/2 respectively. And created 2 loopback interfaces on PA, advertised them into RIP and OSPF respectively. Then I can reach them within RIP and OSPF area separately. Now I create redistribution profiles RIP-2-OSPF and OSPF-2-RIP, and apply them to O...

DexinLi by L1 Bithead
  • 4284 Views
  • 4 replies
  • 0 Likes

Resolved! Accidentally Deactivate License

Hello we have PAN that license uploaded manually before, because a network issue that we cant get the dynamic update/retrive the license.we think that the license problem, so we want to remove the license and then add again to the firewall. but we choose the deactivate, not the Delete command from CLI. after that, we want to upload manually, but...

Email Scheduler Not Working (Urgent Action Required)

Hi Team, We've configured to schedule reports for email delivery on daily basis, It was working fine without any issues but last week we had restarted the Palo Alto firewall, Since from that day we're not getting custom report email. When we check "send test email" on Email Sheduler its working fine. Verified all the configuration which is fine ...

Site to Site VPN failing when IKEv2 and different PANOS

Hello, I’ve recently ran into an issue where I’m using IKEv2 preferred and the two firewalls are using different versions of PAN-OS. It will fail with “invalid sig.”. If both firewalls are the same PAN-OS version (this has been happening on 9.1.11-9.1-13h3… I don’t have any other versions to test), it works fine. But since I can’t update all fi...

COlson by L2 Linker
  • 3792 Views
  • 2 replies
  • 0 Likes

Session behavior when resource limit is reached.

Hi,I have been checking my PA-2050 with PAN 4.0.3 and I realised about new command in sesion configuration. The exact command is:set deviceconfig setting session resource-limit-behavior with the options bypass and drop. Default option is drop.I had problems in my infrastructure reaching the limit sessions. Synthax seems clear but before install...

Resolved! Passive device aggregate interface down

I have the firewall 3220 model in the 9.1.11 version in HA mode.I can see all the aggregate interface in passive firewall is showing down. i want to know is this expected behaviour or not because I checked the below KB for some mode it is expected behaviour. Aggregate Interface Down on Passive Device - Knowledge Base - Palo Alto Networks moreove...

Increase CPU on VM-series

HelloAs PAN-OS CLI is locked, I don't have the ability to run a script and increase the CPU of my VM-series instances in Azure VMS.I'd like to test and demonstrate the scaling (IN/OUT) feature regarding CPU level (high/low). Did someone knows a way/solution for that (appart of reducing Azure VMSS scaling levels)? Regards.

FatihT by L1 Bithead
  • 2477 Views
  • 1 replies
  • 0 Likes

Resolved! Full cone/Port Restricted/Restricted NAT

Hi all,I need to make work a voip server behind my pa-3020. The server is using stun protocol and requires that nat is not symmetric.I've tested a public stun server (for example stun.telbo.com on port 3478) using pystun3 (a python tool to retrieve nat type).That's what I got (A.B.C.D is my public ip) ~# pystun3 -H stun.telbo.com -dDEBUG:pystun...

N2Z2 by L2 Linker
  • 5877 Views
  • 3 replies
  • 0 Likes

can't access to menu palo alto "error: file '/boot/' not found"

Hello,After a factory reset of the Palo Alto PA-3220 (Firmware 10.1.1), then a reboot, I cannot access any of the PANOS partitions (maint-sysroot0, maint-sysroot1, etc.).And this message appears when I select one of the partitions in the menu (grub):error: file '/boot/vmlinuz' not found.Press any key to continue... Can you help me,Sincerely,

Resolved! Dropbox uploaded files not determined correctly

Hello, after implementing SSL decryption we're trying to improve visibility and noticed that files to dropbox web aren't shown correctly When downloading from the dropbox website, the file names are correctly shown, but when uploading the files are registered in the data filtering logs as "presentation.xml" and "put_block_returning_token" Tried ...

Megrretz by L1 Bithead
  • 3570 Views
  • 2 replies
  • 0 Likes

Query about EDL in an VSYS environment

Hi Folks, We had 5 vsys active on the firewall. We had configured separate EDL for each vsys. My query is when we check the EDL Maximum capacity on the firewall will it show the Total EDL capacity utilized for 5 vsys capacity utilized by each vsys individually.

Resolved! IpSec Tunnel Phase2 Red But Ike Side Green

Hi, I have several TpLink Archer Mr400 4G Router. I setup Ipsec VPN tunnel between PA-220 and them many times. But new one is not success at Phase2. Phase1 IKE is green so devices communicate. But Phase2 Tunnel Info is red and i can't see any tunnel when i click Tunnel Info. I have read the losg and find below things; 2022-04-19 16:50:25.878 +03...

Tplink_ArcherMr400_phase2.PNG
PA_Phase2_ipsecCrypto.PNG
PA_Phase2.PNG
tsenturk by L0 Member
  • 3309 Views
  • 1 replies
  • 0 Likes

The PA-3020 in the HA pair cannot automatically run dynamic updates.

Hi All,I have two PA-3020 that are HA setup, version 9.1.9.Since the beginning of March, I have found that dynamic updates often fail. Strictly speaking, downloading images is normal. However, one firewall updates normally and the other fails to update, causing the two firewall versions to mismatch. But it does not always fail to update automati...

PA-3020-mismatch.png
PA-3020-A.png
PA-3020_B.png
PA-3020 fail detail.png
DevonFan by L1 Bithead
  • 5588 Views
  • 5 replies
  • 0 Likes
  • 24337 Posts
  • 124 Subscriptions
Labels