General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4111 Views
  • 0 replies
  • 0 Likes

Resolved! XFF When Using DNS Proxy Object

Hi All, I am using DNS proxy and as such all the threat logs that are to do with DNS requests only have the firewall IP in them, all users are using Global Protect and I have enabled x-forwarded-for headers for user-id. Is there anything else that I need to do or is this unsupported ? Thank you in advance,

Problems with Windows User-ID Agent and the normalized Users

Hi together, I have here a Windows User Agent (tested with Version 9.1.1-8 & 9.1.2-9), which has connected to one Active Directory (MS2012 R2) where they scan the events. The rights from the agent user looks good and they find many client users. But after a few seconds the usernames normalized here. Domain structure: com...

kan3de by L1 Bithead
  • 7691 Views
  • 6 replies
  • 0 Likes

PA-460

Hi, I need assistance for PA-460 HA1 and HA2 connectivity. PA-460 doesn't have dedicated HA1 and HA2 ports. And please let me know do we need dedicated links for HA1 and HA2 between two devices ? Regards,Suresh

surkumar by L0 Member
  • 4090 Views
  • 1 replies
  • 0 Likes

Help With Configure PA-220

I am trying to build firewall from scratch. Our use case is to secure 3 servers with separate DSP connected to PA-220. We do not have any managed switch or router between ISP to firewall. It is direct from modem to firewall. Can anyone help with this? Palo Alto's documentation isnt helpful as I am not network guru.

Traffic monitor incomplete

I've got a new Global Protect portal/gateway. When I get connected to the gateway, I can see the connection via the GP monitor. Then if I go the to traffic monitor and search the source range 192.168.203.0/24 I only get traffic from previous testing that I've performed. I'm not getting the currently connected device to show up for some reason...

danoman2 by L3 Networker
  • 3519 Views
  • 4 replies
  • 0 Likes

I cannot enter maintenance mode on a PA-220. I recycle power and have console cable connected - tried USB and also roll-over cable. Tried 3 different

I cannot enter maintenance mode on a PA-220. I recycle power and have console cable connected - tried USB and also roll-over cable. Tried 3 different software emulators - Putty, TeraTerm and Mobaxterm.When it comes enter Maintnenance Mode no prompt comes up most of the time, on the few occasions it does I can only type "Ma" and when I press ente...

ICT-FODC by L0 Member
  • 7790 Views
  • 2 replies
  • 0 Likes

URL FIltering

I was curious if anyone knows why even when traffic is flagged as a threat by URL filtering there are still packets being sent and received?

Resolved! Certificate dependancies

Hi, We use a lot of certificates within our Palo Alto/Panorama setups. Is there a way to get a spreadsheet/PDF etc... to tell me what though certificates are attached to providing services for etc...? Is there a way to link certificates to what they do/are used for?

IPv6 and IPv4 addresses in same security rule?

is there an issue with doing this - I have a rule set to match any address except one particular IPv4 subnet (ie using the negate function) - works fine.I added an IPv6 prefix to the rule (still negated) - now the rule negatively matches the v6 address, but no longer the v4 address. Remove the v6 address from the rule and the v4 address negativ...

Resolved! Can someone describe the load balancing algorithm used for Aggregate links?

Reading the documentation and forum posts, it doesn't appear that the PA is using LACP, therefore, it's not using one of the 3 common LACP load balancing algorithms.Could someone describe how it's making the decision to send traffic down a particular link? Also, am I able to modify the behavior? (it doesn't seem like I can through the web inte...

austad by Not applicable
  • 13221 Views
  • 8 replies
  • 0 Likes

Resolved! Renewing Certificate for GUI from External CA

We have followed the below document. After importing the newly signed certificate into the firewall it does not replace the pending csr containing the private key. PAN OS 9.1.11-h3, any one else experience this issue?Obtain a Certificate from an External CA (paloaltonetworks.com)

clewis1 by L3 Networker
  • 3994 Views
  • 2 replies
  • 0 Likes

Resolved! Downgrade panorama ha managed device.

Hi, I have the following situation, a HA cluster managed by panorama. For testing purpose I would like to downgrade it to an 8.1.21 release. Coming from 9.1.12 release.Couple of question:Should I always perform upgrades / downgrades from Panorama, I they are panorama managed?(upgrading cluster I did without panorama using Ansible script and ma...

GOMEZZZ by L2 Linker
  • 2897 Views
  • 1 replies
  • 0 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels