General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! meaning of ms.log - update system boot?

Hi all, I am checking the log of firewall to know the states of firewall issue.I found that there are some log in ms.log as show below2022-XX-XX XX:XX:XX.XXX +0800 update system boot: count = YYYY, timestamp = 2022/XX/XX XX:XX:XX What is the meaning of this log? Is it mean the dataplane reboot at 2022/XX/XX XX:XX:XX, total reboot number is YYYY?...

JoeKwok by L2 Linker
  • 4435 Views
  • 1 replies
  • 0 Likes

GlobalProtect - Multiple Gateways on One IP Address

Good day, Our PA-500 is currently on PANOS 7.0.5-h2. We want to configure GlobalProtect - Multiple Gateways using the same IP Address. Is this possible? We tried to follow the instructions here: http://dsg0.com/t/palo-alto-networks-globalprotect-with-multiple-gateways-on-one-ip-address/122 but we are getting an error that the GlobalProt...

WCCP visibility

Hi All.Yesterday we tried to put PAN Device on a POC with a customer just before traffic reach their Proxy solution. Customer redirect using WCCP web traffic from router to Proxy and we used a PAN port on Palo Alto to receive that WCCP traffic. The Proxy device only has one NIC interface, so at TAP port of PAN we should see WCCP traffic redirect...

CPU core and memory list for each model

Dear Team, I can check the log storage and number of NICs on the compare site and spec sheet provided by paloalto. However, I cannot check the CPU core and main memory for each model. If I have a device, I can access the firewall and check it, but if I don't have it, it cannot be checked. I am looking for a model with CPU 4 Core or higher and ma...

Resolved! HTTP OPTIONS Method Enabled on Panorama

Hi All,I got Vulnerability HTTP OPTIONS Method Enabled on Panorama, the status show OK.curl -k -v -X OPTIONS -x "" https://10.10.10.10/restapi * Mark bundle as not supporting multiuse< HTTP/1.1 200 OK< Date: Wed, 27 Apr 2022 02:47:02 GMT< Content-Type: httpd/unix-directory< Content-Length: 0< Connection: keep-alive< Allow: OPTI...

Resolved! User identification and WinRM on HTTP

Hi to all, before to write i red some post here on the community and i just configured my NGFW and windows domain controllers.Becuase i have every 3 sec an alert about "The server-side authentication level policy does not allow the user AAA\BBB SID (XXX) from address Y.Y.Y.Y activate DCOM server. Please raise the activation authentication level ...

Resolved! Does PAN-OS VPN functionality support MFA?

Hey guys, I'm looking at moving off Sonicwall NSA 3600 and onto a PAN appliance. One factor is that I'm currently using Sonicwall's VPN functionality which has some simple, built-in MFA in the form of TOPT codes that the user must put in each time they connect to the VPN. Its not dependent on any other service so its kind of nice that way. I was...

Resolved! Auto-commit blocking changes - auto-commit scheduled in future

Hi,Currently cannot upgrade a new pa820 (10.1.4), its auto-commit is set to run tomorrow and blocking any updates or current config commits. Does not stop when using 'stop job' from GUI or clear job CLI. Enqueued Dequeued ID PositionInQ Type Status Result Completed----------------------------------------------------------------------------------...

orbcomm by L2 Linker
  • 6488 Views
  • 2 replies
  • 0 Likes

Zone Based Policy in PANOS SD-WAN (not PRISMA)

Hello,In PANOS SD-WAN (not PRISMA), you must either use predefined zones (zone-to-branch, zone-to-hub, etc.), or you can map pre-existing zones to the predefined zones in Panorama. Before SD-WAN, using IPSEC tunnels, we could give each tunnel/branch its own zone and control access very easily. Since SD-WAN requires use of predefined zones, it s...

JayGee by L0 Member
  • 2298 Views
  • 1 replies
  • 0 Likes

Resolved! System log filter - email alerts

I would like to receive email alerts on certain system events, such as when there is a successful login and unsuccessful login attempt from GUI and CLI. (Among other events). The filter for the stem log is looking for certain "strings" or "attributes" Andi have no idea where to find them. Any ideas? Thanks.

roma by L2 Linker
  • 2597 Views
  • 1 replies
  • 0 Likes

Resolved! Custom region not reflecting in "show location ip xxx.xxx.xxx.xxx"

I have an IP address that is showing up in the wrong region, say AM (Armenia) and should be CN (China). I have a support case open to get that fixed, but it has been open for over a week so I want to do a workaround. Ideally I could specify to override this IP address to show up in CN. It seems like this could be done via Objects > Regions ...

Authentication failed captive portal

Hi Expert, We got error message "Invalid username or password" when try login to Captive Portal and affected a lot users. There is no changes made and it is working last 2 days. I look into Solved: LIVEcommunity - captive portal authentication failed LDAP - LIVEcommunity - 32582 (paloaltonetworks.com) but never try yet. Is there anything else...

Oblagonte_0-1650948520679.png

Resolved! VM-500 will it run with 6xCPU?

Hi All, We currently have one customer with two clusters running VM-300, but facing dataplane CPU utilization. Support team has upgraded the VMs to 6xCPU (without knowing that VM-300 only support up to 4). Right now VMs are with 6 CPUs allocated and we are planning to upgrade the vm capacity to VM-500. But I was wondering how the current CPUs w...

  • 24393 Posts
  • 123 Subscriptions
Top Solution Authors
Labels