General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4433 Views
  • 0 replies
  • 0 Likes

PAN-OS 10.1.4-h4

Hello all,We are looking to update PAN-OS to 10.1.4-h4 but wanted to ask if anyone had any issues after upgrading? I had 10.1.4 installed but it had bugs and had to roll back so I am a little bit leery to upgrade again.Thank you,Tom

thoffman by L2 Linker
  • 2107 Views
  • 1 replies
  • 0 Likes

Global Protect 6.0 Client Windows Authentication

Since upgrading to the 6.0 client every hour, when the client does its config refresh interval, Windows defaults to the Global Protect password sign in option when unlocking the computers rather than what the users are normally using (PIN, Face, Finger etc). The same issue occurs when manually refreshing the connection or signing out and in to t...

Interface Status in Suspended state

I have my production firewalls in HA active/passive mode. My question is if I have suspended the passive firewall, what would be the interface status, would it be down or showing up ? I do understand it will not be forwarding traffic but what would you see in the GUI when checking the interface state.

bambox by L1 Bithead
  • 4105 Views
  • 1 replies
  • 0 Likes

Migration Cisco to PAN

Hello,I have run a config through the migration tool and I have noticed the following application generate warnings- icmp- I understand I change this to- pingipsec-esp- I have no idea what this should be changed to?gre(generic routing encapsulation)- No idea what this should be changed to? Any help would be appreciated.

mamuhopo by L0 Member
  • 1902 Views
  • 1 replies
  • 0 Likes

Resolved! Site-To-Site VPN with payed VPN Providers

I would like to test this hypothetical scenario it is possible :* I have an account with 3 vpn providers (i.e. NordVpn, PIA, Boleh)* I would like to create 3 (or more) vpn tunnels (at least one tunnel with each vpn provider)* I will route different traffics (route by source) to each vpn tunnel Is it possible with Palo Alto?Does anybody have I bl...

useridd process is consuming 100% CPU on the PA-5250

PAN-OS is 9.1.10 running on PA-5250. The useridd process is consuming 100% CPU: Tasks: 313 total, 1 running, 309 sleeping, 0 stopped, 3 zombie%Cpu(s): 2.8 us, 1.5 sy, 0.0 ni, 95.7 id, 0.0 wa, 0.0 hi, 0.0 si, 0.0 stKiB Mem : 32640128 total, 197252 free, 5921556 used, 26521320 buff/cacheKiB Swap: 0 total, 0 free, 0 used. 26240004 avail MemPID USER...

dtran by L4 Transporter
  • 7583 Views
  • 8 replies
  • 0 Likes

Leak a specific route from BGP summarization

Hello All, I have a question related to BGP summarization in a PAN firewall. We currently have summary aggregate advertised to the upstream device. But now we need a leak /32 route to the upstream along with the original summary route. What is the best method to achieve this goal? I have seen an option for 'Advertise filter' in BGP summary. If I...

a-techie by L1 Bithead
  • 3516 Views
  • 4 replies
  • 0 Likes

Getting Panorama-Managed firewalls connected to Cortex Data Lake?

Greetings all, As the title suggests, I'm attempting to get Panorama and our two PAN 5250 on to our new data lake. I've got the Device Certs installed using the OTP from the Support Portal and I installed (but didn't configure beyond the re-verifying using the OTP from data lake) the latest Cloud Services plugin on Panorama. I can see all of th...

jsalmans by L4 Transporter
  • 3000 Views
  • 1 replies
  • 0 Likes

Panorama PDF Summary reports not providing data

I'm having some issues generating PDF reports in Panorama and after Google didn't help me, I thought it would be worth asking here. We've created some custom reports in the past, had PDF summaries generated, and the reports get sent out on a regular basis with no issues. We followed our usual steps to create the reports described below. Yesterda...

DNS Security

Hello FolksDoes anyone know why I am having problems with DNS Sinkhole when my computers have dynamic DNS, I have spent days testing and I have detected that with fixed DNS I see the log but with dynamic DNS I don't see any logI have applied the Security profile , Decryption rule, But the behaviour is the same. Also I have DNS Security license.T...

dae_sua by L0 Member
  • 1867 Views
  • 1 replies
  • 0 Likes

MS-Teams issues with disconnections

Hi all, we have some issues with MS-Teams.Our customers have random disconnections during the cals. In the app they recive error - "bad network quality" and after that they reconnect. Call quality itself is good. In MS console there is no allerts for diconnections or bad quality. Evriting regarding MS products was excluded from inspecion decript...

stef by L2 Linker
  • 4193 Views
  • 1 replies
  • 0 Likes

Resolved! SL Decryption Exclusions

Hi All,I'm using SSL decryption and if I wanted to have a URL in the exceptions (not decrypted) list, I would add it to a custom url category I created and just add the domain and apply the cutom url to the policy.But I also noticed that in Device>Certificate Management>SSL decryption exclusion - there are many predefined domains that seem...

roma by L2 Linker
  • 2430 Views
  • 1 replies
  • 0 Likes
  • 24374 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels