General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Custom region not reflecting in "show location ip xxx.xxx.xxx.xxx"

I have an IP address that is showing up in the wrong region, say AM (Armenia) and should be CN (China). I have a support case open to get that fixed, but it has been open for over a week so I want to do a workaround. Ideally I could specify to override this IP address to show up in CN. It seems like this could be done via Objects > Regions ...

Authentication failed captive portal

Hi Expert, We got error message "Invalid username or password" when try login to Captive Portal and affected a lot users. There is no changes made and it is working last 2 days. I look into Solved: LIVEcommunity - captive portal authentication failed LDAP - LIVEcommunity - 32582 (paloaltonetworks.com) but never try yet. Is there anything else...

Oblagonte_0-1650948520679.png

Resolved! VM-500 will it run with 6xCPU?

Hi All, We currently have one customer with two clusters running VM-300, but facing dataplane CPU utilization. Support team has upgraded the VMs to 6xCPU (without knowing that VM-300 only support up to 4). Right now VMs are with 6 CPUs allocated and we are planning to upgrade the vm capacity to VM-500. But I was wondering how the current CPUs w...

Resolved! PAN-OS version is not update on CDL Portal

Hi ,Anyone have some solution for this issue about PAN-OS version is not update on CDL Portal after update to V.9.1.13-h3?Last week I had updated PAN-OS from version 9.1.9 to version 9.1.13-h3 on HA Firewall .I got this issue on the active peer FW.After finished update OS, I check version on the active peer by "show system info" that already sho...

Version_.jpg
Jirapan by L1 Bithead
  • 2791 Views
  • 1 replies
  • 0 Likes

Listing PCAP rules

Does anyone know if there's a way to search for rules within the Palo Alto which have packet capture enabled? I'm trying to see what rules currently collect PCAP and disable the collection of pcap data for noisy signatures.

dgagnon by L1 Bithead
  • 2127 Views
  • 1 replies
  • 0 Likes

Resolved! Global Protect Disable Reason

Global Protect Client is setup so that users can disable VPN however they need to input a reason why they disabled the portal. I wanted to know where those disable reasons are stored. Thanks

SIDD76 by L0 Member
  • 11698 Views
  • 5 replies
  • 0 Likes

List NAT tables with static-ip translations

Hello all!I'd like to compile a list of all my NAT tables for static-ip entries for all my firewalls, I don't know if there's a better way to do it but I'm trying to do it by running the following command on my firewalls and recording the output:show running nat-policy | match index\|source\|translate-toThe issue with this one is that it's showi...

TigeRRR by L1 Bithead
  • 8074 Views
  • 6 replies
  • 0 Likes

What to monitor via Solarwinds

Hello -Just looking to see what others monitor for on their Pano/Palo FW within Solarwinds. Is there like a general consensus (best practices) or is it all over the place depending on requirements.

PA3250 in No Rules/Allow All mode and Public IPs

We are currently testing out/learning with a new 3250 in no rules / allow all traffic mode flowing from ISP > Palo > Cisco ASA (Being Retired). We have two public ips routed to two local static IPs and those have stopped working. Would a policy need to be created so the Palo does the routing and not the Cisco.

jpierce by L0 Member
  • 2568 Views
  • 2 replies
  • 0 Likes

strange behavior of bidirectional NAT

hello All, Today I've spotted weird behavior: We have 2 static bidirectional NAT translations between UNTRUST and DMZ interfaces for public IPs. Also we are allowing certain applications in for those public NATed IPs from any IP addresses using only applications and not service/ports. From logs we see that traffic which is properly allowed and w...

Resolved! Redistribution host address between protocols

Dear experts I set a PA firewall as an ASBR, connects to a RIP and a OSPF area with eth1/1 and eth1/2 respectively. And created 2 loopback interfaces on PA, advertised them into RIP and OSPF respectively. Then I can reach them within RIP and OSPF area separately. Now I create redistribution profiles RIP-2-OSPF and OSPF-2-RIP, and apply them to O...

DexinLi by L1 Bithead
  • 4512 Views
  • 4 replies
  • 0 Likes

Resolved! Accidentally Deactivate License

Hello we have PAN that license uploaded manually before, because a network issue that we cant get the dynamic update/retrive the license.we think that the license problem, so we want to remove the license and then add again to the firewall. but we choose the deactivate, not the Delete command from CLI. after that, we want to upload manually, but...

Email Scheduler Not Working (Urgent Action Required)

Hi Team, We've configured to schedule reports for email delivery on daily basis, It was working fine without any issues but last week we had restarted the Palo Alto firewall, Since from that day we're not getting custom report email. When we check "send test email" on Email Sheduler its working fine. Verified all the configuration which is fine ...

Site to Site VPN failing when IKEv2 and different PANOS

Hello, I’ve recently ran into an issue where I’m using IKEv2 preferred and the two firewalls are using different versions of PAN-OS. It will fail with “invalid sig.”. If both firewalls are the same PAN-OS version (this has been happening on 9.1.11-9.1-13h3… I don’t have any other versions to test), it works fine. But since I can’t update all fi...

COlson by L2 Linker
  • 3975 Views
  • 2 replies
  • 0 Likes
  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels