General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4250 Views
  • 0 replies
  • 0 Likes

Download executable GP from mobile phones

Hi, I wanted to know if it's possible in Palo Alto, when you connect to the portal via https://vpn.xxx.com and authenticate from mobile phone, that instead of displaying the laptop executables, you get a redirect to the app market or the option to download the GP APK. Something like the FW PA knowing the agent from you are connecting in order to...

BigPalo by L4 Transporter
  • 930 Views
  • 2 replies
  • 0 Likes

VPN tunnel monitoring/alerting

When NOT using tunnel monitoring and keying off events ids for "tunnel-status-up/tunnel-status-down", what is the best logging to alert on for tunnels going up or down?Is it only alertable/trackable by ( eventid eq 'ikev2-nego-ike-dpd-dn' )Or is there a better way to alert when NOT using tunnel monitoring on when a tunnel is hard down? Assumi...

Sec101 by L4 Transporter
  • 641 Views
  • 1 replies
  • 0 Likes

decryption error with Anydesk

Dear Community! I´m trying to use Anydesk and it only works with decryption policy disabled, somehow the predefined exclusion for Anydesk is not working. While checking the decryption logs I can see the following error: "tlsv1 alert insufficient security. Received fatal alert InsufficientSecurity from server" Does anyone have an idea the rea...

Carracido by L4 Transporter
  • 1498 Views
  • 1 replies
  • 1 Likes

Resolved! Source Address - Show ipv4

I just upgraded from a PA 500 to a PA 820 and something is throwing me for a loop. In all of my reports and in the monitoring section under App Scope the firewall is reporting what appears to be ipv6 addresses, they are in the format of: "::678b:540:ffff:0". I'd prefer to see the ipv4 address as it is much simpler to hunt down the offending us...

Screen Shot 2021-07-08 at 8.26.00 AM.png

Can ACC data really display data per user group?

Hello! I´m trying to filter data, in particual user activity, by using filter "user group" however I only have the data filter by user or IP, not using the group. Do you know if you can actually filter data from any widget of the ACC by using the user group? Thanks!

Carracido by L4 Transporter
  • 803 Views
  • 1 replies
  • 0 Likes

versions 10.2, 11.1, 11.2 - which is best?

of the current trains 10.2, 11.1, 11.2, which would be the best in terms of robustness and stability? I am running PA-440 and PA-3250. The later trains dont have any features i need over and above what is available in 10.2.

VPN Fail Over

Dear Team, We Have PA Firewall With Single ISP and Peer End Sophos FW With Dual ISP. Here I need to configure VPN Fail over. What are the step i need done PA side? RegardsKarthikeyan

Failed to extract file panup-all-antivirus-5240-5760.tgz with sha256

Hi All, I have HA firewall PA1 and P2. PA1 is fine but on PA2 having this issue with failed installation antivirus. although it failed for the 1st minutes and PA2 success on 2nd minutes i need to know or some explanation why its failed on the first place. any advise or suggestion are very much appreciated i share the below system logs...

Fariq_Zaidi_0-1752224973584.png

Problem with bound static address on interface PA-VM-11.1.4

Hello. Why I can't bound a static IP manually on web-management as Object-Addreses and when type ip netmask as xxx.yyy.zzz.xxx/25 from internal trusted zone? Even I created management profile for that interface called ping with switched on ping. Nevertheless there is no ping. I know exactly MAC address from ESXi and web-management so it is true....

Demong by L2 Linker
  • 877 Views
  • 2 replies
  • 0 Likes

Create SSL VPN on PA-500

Hello. Week ago friend of mine gave me an old PA-500 w/o license and subscrption. Software Version 6.0.2 Since I had no admin pass therefore device was factory reseted. As Internet firewall device work fine now. Do somebody know is it possible to make up SSL VPN outside connection with such conditions? Thanks in advance!

Demong by L2 Linker
  • 7311 Views
  • 14 replies
  • 0 Likes

PA-VM LAB licensing

We would like to have the possibility to run 3 PA-VMs in a lab environment for training, testing and education purposes. We reached out to our reseller and they told us, that we have these options: 1. "normal credits" (~7000 €) 2. PAN-SOFTWARE-NGFW-LAB with minimum of 500 Credits that we have to purchase (~12.000 €) We would only need about 45 c...

janhoppe by L0 Member
  • 2352 Views
  • 1 replies
  • 0 Likes
  • 24360 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels