General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4449 Views
  • 0 replies
  • 0 Likes

Resolved! GlobalProtect with Active/Active HA

I'm having a hard time finding much, if any, documentation on this scenario. I've tried a couple ways of doing it and they work, but I'm trying to figure out what the best way to do it while being as redundant as possible. What I like the best so far is to have the portal and a gateway up on a floating IP so it can bounce from one firewall to t...

GlobalProtect on HA

We get SSL connect select error: 0(Resource temporarily unavailable), time left: 0P26083-T33415 08/07/2025 00:31:33:272 Debug( 468): SSL connect failedP26083-T33415 08/07/2025 00:31:33:272 Debug( 66): detailed SSL error info:P26083-T33415 08/07/2025 00:31:33:272 Debug( 956): connect() failedP26083-T33415 08/07/2025 00:31:33:272 Debug(3388): Conn...

gabe_0-1754592974792.png
gabe by L1 Bithead
  • 945 Views
  • 1 replies
  • 0 Likes

Resolved! Pushed template to Palo and now unable to SSH or HTTPS to device

Migrating a firewall and pushed a cloned and modified template to a new Palo alto. Did not push device group. Now I am unable to ssh, ping, https the device. I am on the device by console. Everything with the management interface looks on and I can ping the management default gateway from the Palo. What could be causing this?

M.Allen by L1 Bithead
  • 1488 Views
  • 2 replies
  • 0 Likes

Resolved! Warning certificate chain not correctly formed in certificate

Hello All I have imported a cerfificate into the PA as a PFX. I have also import the intermediate certs and root CA. The cert is signed by Go Daddy with 2 intermediate certs and a Root CA. All imports fine, but when I get up global protect portal and use the imported cert (from the pfx) I get an error which says "Warning certificate chain not co...

live.png

Resolved! Multi Vsys query.

When managing a multi-vsys firewall, is the correct way to map each vsys to a unique Device Group? Lets say I have vsys_prod and vsys_dev, I would do: Device Group "prod_device_group" mapped to "vsys_prod" Device Group "dev_device_group" mapped to "vsys_dev" The reason for my confusion. I can see that Panorama allows me to add multiple vsys'...

Resolved! LDAP Authentication works when testing it via SSH command but fails on web interface

Hi When I'm running "test authentication authentication-profile "'LDAP Auth Profile" username myldapUser password" on the ssh cli, it authenticates successfully. however when i try to log in on the web interface of global protect, i get this on the webui log: failed authentication for user 'myDomain\myldapUser'. Reason: Invalid username/passwor...

gabe by L1 Bithead
  • 1600 Views
  • 2 replies
  • 0 Likes

Devices pinging only after clearing ARP table

I am having an strange issue PA firewalls reachability to some of the nodes on the network. I have 10 identical devices connected behind this access switch and all 10 devices are accessible from the access and the core switch at any time. However, only 6 of them are reachable from the firewall at any time. The remaining 4 devices only pings whe...

BishnuA by L0 Member
  • 1639 Views
  • 1 replies
  • 0 Likes

Is it possible to configure PA to send a reset(rst) packet when a session timeout occurs?

Hello. I'm running a PA-1420 device.The PAN-OS version is 11.0.3-h12. Is it possible to configure the PA to send RST packets to both sides when a TCP session times out due to aged-out?I read in a previous post that this wasn't possible on the PA, but I'm wondering if this is still the case.(https://live.paloaltonetworks.com/t5/general-topics/pa-...

What is the replacement of PCNSA certification?

Good morning, everyone I was planning to take the PCNSA certification, but I surprised when I noticed that this certification was retired in January 2025. My question is: What is the new certification that replace PCNSA and what is the study guide or book that I must buy to pass this new certification Thank you, Carlos.

No Linux dowload available

Hi everyone, I’m trying to get GlobalProtect VPN up and running on Linux, but the university portal only offers Windows/macOS installers—no native Linux package. I also tried signing in on Palo Alto’s site with both my personal and CPP email addresses, but I keep hitting this error: “An unexpected error has occurred. Please contact support.” H...

adongre by L0 Member
  • 727 Views
  • 1 replies
  • 0 Likes

PAN OS 11.1 USER ID ,POLICY BLOC GROUPS

Hi Paloalto 11.1, user ID agent configured, it's pulling users with ip. But using policy to block or allow the internet is not working It blocks all users; if all domain users are allowed, the internet will be allowed. If a particular group is selected to enable through policy, it is blocked. I can see users in the user ID section and logs. P...

V.John by L0 Member
  • 887 Views
  • 1 replies
  • 0 Likes

User-ID stopped working / Failed to add group to id manager

Hi Folks, just to let you know, since I found no KB Articel for this issue. Policy Push from Panorama respectively local Commit on the Firewalls ended in strange Error Message according Group Assignment to Policy. vsys1Error: Failed to add group to id managerError: Failed to parse security policy(Module: device)Commit failed Cure comes with CLI ...

enssenje by L1 Bithead
  • 7711 Views
  • 2 replies
  • 2 Likes

Issue with GP Access for JIO Users on PA-820

Dear Friends, One of our customer is facing an issue with users on PA-820. According to the customer, many users are connecting to the internet via mobile hotspot using JIO SIM cards. While they can successfully connect to GlobalProtect, but they are unable to access internal servers.This issue is specific to users who are using JIO SIM cards ...

  • 24376 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels