General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Struggling to Unset Virtual Router from Interface via API – Manual Works, API Always Fails

Hi everyone, I’m working on automating Palo Alto firewall configuration via the API and I’ve run into a puzzling issue. What I’m Trying to Do: Unset the Virtual Router assigned to a specific Layer3 Ethernet interface (e.g., ae2.4008) using the API. Manually, I can easily go to the GUI and set the Virtual Router to none, and everything works ...

AK_20201 by L0 Member
  • 657 Views
  • 0 replies
  • 0 Likes

Renew Palo Alto Global Protect Certificate issued by Public CA

Dear All, I need some immediate assistance with this. Can you anyone help me out. We have a Palo Alto VPN Gateway at our office where client connect to the internal Network via Remote Access VPN. Now recenlty the certificate was expired the following is what I did. 1. Generated a Private key using OpenSSL. 2. Generated a CSR using that Pri...

Zone rename effects on Shared Policies

After a company acquisition we have inherited about 25 firewalls which I have recently migrated to a single Panorama instance, along with shared policies and templates, and in the process of building shared policies for the entire fleet. For the shared policies to work, zone names need to be consistent across about 40 odd gateways, unfortunatley...

Is there a need for a book on PAN-OS "Policy as Code" subject?

Dear All, I am looking to determine if there is a demand in the market for a guide to PAN-OS security policy automation ("policy as code"). There is plenty of reference information (https://pan.dev is always a good starting point) but there is no resource/book that would take one of the available automation frameworks and demonstrate how to ...

Assistance Required – Cybersecurity Fundamentals Certificate Not Unlocking

Hello Beacon Support Team, I recently completed the Cybersecurity Fundamentals course on Beacon. However, my progress is stuck on Module 4 even though I have already gone through all the lessons and quizzes. The platform keeps sending me back to Module 4, and my course completion status is not updating to 100%. Because of this, I’m unable to dow...

combiyke by L0 Member
  • 1262 Views
  • 1 replies
  • 0 Likes

About CVSS version

Hello PaloAlto Networks Team, What version of CVSS is listed in Palo Alto Networks Security Advisories? Please tell me which version it is, such as CVSS v3 or v4. Regards,

IPSec HA Failover - Feature Request NSFR-I-26043

As of this post, Palo Alto Firewalls do not sync Phase 1 for IPSec Tunnels. If a remote end is using Dead Peer Detection, this will cause the tunnel to go down after a failover occurs and the remote end DPD hits its threshold. Since the Palo no longer has Phase 1, it cannot respond to the DPD. Despite Phase 2 being up and working, the DPD will p...

spapesh by L1 Bithead
  • 1732 Views
  • 2 replies
  • 1 Likes

Resolved! PCNSE Learning plan under maintenance

I have a question from my CBTS customer: they have a Network Security Engineer who has been going through the Beacon training in preparation for his PCNSE.At some point last month, the course he was working on was changed to "Learning plan under maintenance" . Any idea who I can go to in order to unlock the course or investigate what's going

kbettich by L0 Member
  • 2122 Views
  • 1 replies
  • 0 Likes

Resolved! Access Palo Alto HTML Files

Hello, our user want to deploy Palo Alto Firewall 3410 with Os 10.2.2, for security reason then they do the vulnerability assessment but using different device but with same OS 10.2.2. And the result is that they found 2 vulnerabilityissues, low and information. i took this VA is on the login page on palo alto firewall. The Low vulnerabilityis...

Add Palo alto HA (existing config) in Panorama. Doubts..

Hi, I need to add a cluster A/P FWs in Panorama. I was checking this useful link: https://www.mbtechtalker.com/migrate-a-ha-pair-of-pan-firewalls-to-panorama-management-2/ and videos on internet. I have everything under control, but I'm a little concerned about if its necessary in any point to enable the "force template value" option at some...

BigPalo by L4 Transporter
  • 1271 Views
  • 3 replies
  • 0 Likes

Fetch Device Certificate failure

Hello, I am getting this error (Failed to fetch device certificate.TPM public key match failed.) on a PA460 (11.0.2-h2). I tried multiple solutions without success : This KB https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004NlxCAE but it didn't work. Multiple commit force. I even generated an OTP on the CSP but I do...

Meed by L0 Member
  • 23270 Views
  • 11 replies
  • 1 Likes

XSOAR virtualization support

Dear All, I would like to request official documentation or a clear statement regarding the virtualization platforms supported for Cortex XSOAR on-premise deployments. Specifically, I would like to know: Which hypervisors (e.g., VMware ESXi, KVM, Hyper-V, etc.) are officially supported for installing and running Cortex XSOAR? If there is a c...

VPN Tunnel - Routing and Hidenat from FW public IP

I am a beginner on the Palo Alto firewall. When to do IPSEC and NAT 😊 I need to create a NAT rule that will allow traffic from 77.221.253.132 - the partner only has 1 public IP address and it is on their firewall.If I make a route to the public IP address(77.221.253.132) and route to the Tunnel interface - the IPSEC tunnel go down.how should ...

Resolved! Vsys migration

Hello All, What is the best approach to migrate a Palo Alto firewall configuration with VSYS to another Palo Alto firewall (As is)?

Resolved! Does anyone have any experience with Expedition

Greetings from Detroit Michigan! I have been tasked with migrating our current PA-5220 pair firewalls to a new PA-3420 pair. I have been led to believe that the "Expedition" tool will help with this task. The problem simply put is that the documentation for this is quite spartan in the area of migrating from a PA to a PA. We are using Expedi...

R.Gage by L0 Member
  • 1519 Views
  • 2 replies
  • 0 Likes
  • 24411 Posts
  • 125 Subscriptions
Top Solution Authors
Labels