General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 314 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3660 Views
  • 2 replies
  • 14 Likes

Cisco CAPWAP AP stuck in Discovery

Hi All,

 

Has anyone had problems with CAPWAP AP's separated from the WLC by a PA-220 firewall get stuck in a DISCOVERY OperationState?

 

>show capwap client rcb
AdminState : ADMIN_ENABLED
OperationState : DISCOVERY
Name : ***
SwVer : 8.5.151.0
HwVer : 1.0.0.

...

KevinJB by L1 Bithead
  • 7303 Views
  • 6 replies
  • 0 Likes

NPTv6 seems bugged (PAN-OS 9.1.9)

Hi,

we're running into an issue with IPv6 NPTv6 which we use to route traffic through IPS on PA.

The address isn't translated as expected.

We tried NPTv6 in 2 configurations, both translate the same. We either used:

xxxx:xxxx:xxxx:ffe0::/60 -> xxxx:xxxx:

...

Freaky by L0 Member
  • 1921 Views
  • 3 replies
  • 0 Likes

Knowledge sharing: Palo Alto checking for drops (rejects ,discards), slowness (latency) and counters using captures, global counters, flow basic etc.

Hello To All,

 

 

I will create a short summary about how to do basic checks if the palo alto drops or slows down the traffic.

 

 

1. First the pcap capture on the drop stage will show if the firewall drops the traffic and after that we check why the firew

...

NikolayDimitrov_0-1619596411072.png

HIP check report interval

1. What is the interval for HIP reports that the GP client sends to the gateway? 

2. Is it configurable?

3. What triggers HIP report sending?

ET by L2 Linker
  • 15591 Views
  • 5 replies
  • 0 Likes

Resolved! Experiences with skipping the base image.

Hello.

so slowly but surely I'm upgrading a large number of palo alto's from versions 7.1.x to eventualy version 8.1.6( or higher)

 

In my palo alto training. and from some upgrades done before of pavm100 specifically. I always loved the fact that you c

...

Split Tunnel Routing Config Help

Looking for some help on split tunneling.

We are on PAN os 9.1.9 GP client 5.26, for our LAN we also use Cisco Umbrella to block sites.

What I want to do is when GlobalProtect connects I want all LAN traffic going through the VPN traffic, and all Inter

...

PA-5050-Data plane showing high

Dear Team,

 

Our Core firewall Data plane  CPU reaching to 99% , When we checking the traffic logs some MS-SQL application getting high usage, and system logs are showing "dataplane under severe load palo alto".

 

Pan os : 8.1.15-h3 ,Device : PA 5050.

 

Ki

...

VishnuPS by L3 Networker
  • 2855 Views
  • 6 replies
  • 0 Likes

Resolved! IPSec VPN certificates

I’m very new to Palo Alto and testing things out on a home virtual lab on local computer.  I’m trying to configure IPSec vpn between 2 sites using certificates.  My problem is that when I export the certificate from PA-1, I cannot import it to PA-2 b

...

ldapjazz by L0 Member
  • 2267 Views
  • 2 replies
  • 0 Likes

Storage V-Motion

Hello,

 

Our Virtualization team Storage vmotioned all the VMs on a specific host and that included VM-Series Firewalls for NSX as well.

 

Resulting that the firewalls pass 0 kbps of throughput and dropping all the packets. We were able to identify this

...

ayazdani by L1 Bithead
  • 2060 Views
  • 2 replies
  • 0 Likes

Resolved! Unable to export certificates

PanOS 7.0.1

 

Tested with Google Chrome and Firefox v56

 

When trying to export a certificate from Device tab --> Certificate Management --> Certificates, no matter which export format I choose, nor which certificate I choose, nothing happens.  Browser w

...

Incoming traffic being not logged on external IP

Hi 

 

Any help greatly appreciated.

 

I have 4 internal IPs w x y and z that need to route out on one of my external IPs (1.2.3.4).  And then I need the ingress traffic on 1.2.3.4 to be routed to w x y and z based on the incoming port number.  I am also

...

  • 24189 Posts
  • 100 Subscriptions
Top Liked Authors
Labels