General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4105 Views
  • 0 replies
  • 0 Likes

Configuring PA-5250 to act as gateway for guest wireless

Hi All, I'm attempting to configure a 5250 to act as the gateway and DHCP server for my guest wireless. I have a Cisco 9800 WLC directly connected via fiber from Gi0/2 to Eth1/15 on the 5250 over VLAN 825. I then created VLAN 825 on the 5250 as an SVI and associated it with Eth1/15. I have a DHCP server setup to hand out IPs from the 10.14.0.0/1...

Agentless User ID based network administration control using Windows AD server for PAN-OS

Hi All,I am looking for information on if we can use PAN-OS to do user ID based authentication for network administration control. For example, if user are working from home or remote location, getting users authenticated via PA Firewalls by integrating PA FW with AD server. Question I am stuck at is, how policy will look like. I want only this ...

Richa-L by L0 Member
  • 1872 Views
  • 1 replies
  • 0 Likes

URL Filter Security Policy Structure

Hello all. New to PAN, and after reviewing the documentation on URL Filtering, I'm confused on the best practice deployment of the policy structure. Here's what I mean: Let's say I want to break out the policies into multiple granular policies for custom exceptions. It would look something like this: 1) URL Filter Policy: "Vendor Safelist"Custom...

Resolved! Threat log spammed with "Non-RFC Compliant DNS Traffic on Port 53/5353"

A couple days ago, the threatvault added threat id 56505, and since then our threat log is getting spammed with the vulnerability type Non-RFC Compliant DNS Traffic on Port 53/5353 (informational). We use dnscrypt, and every single DNS request is now showing up in the threat log. First of all, is this a false positive? And if so, how do I preven...

Maxstr by L3 Networker
  • 31766 Views
  • 4 replies
  • 0 Likes

session_end_reason eq decrypt-error

I have a high number of sessions, for various webservers and clients, being closed due to decrypt-error. I've attempted to follow the tips from this document, but I'm still not clear on root cause: https://live.paloaltonetworks.com/t5/Configuration-Articles/PAN-OS-7-1-New-session-end-reasons/ta-p/73289 Need help identifying why sessions are endi...

AmyTyler by L2 Linker
  • 17166 Views
  • 6 replies
  • 0 Likes

Query regarding upgrade Path to 8.1.21-h1

I have a PA-500 device running on 8.1.20 currently .From this version can we jump directly to 8.1.21-h1 Or we need to go via intermediate path ?(8.1.20 >8.1.21>8.1.21-h1)Also not able to see any Palo Alto reference article about upgrade path , Is it available ?

AVG132 by L0 Member
  • 2404 Views
  • 2 replies
  • 0 Likes

Resolved! aggregate interface

Hi all, I would like to have the community opinion on two different setups and which one is the recommended by PA, i have looked for documentation about this and i cannot find a straight answer. All i could find was: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008V36CAE&lang=en_US%E2%80%A9 This document states, ...

Blank Setup page after downgrade from 10.0 to 9.1

Hi there, Using a VM-50 that has been running fine on 10.0.2 until there was a need to downgrade the VM.After taking backups then downgrading to the 9.1 feature release, the Setup page in the UI is now blank.I have tried upgrading/downgrading to various 9.1.x feature releases and committed several different configurations to no effect.The setup ...

warface by L1 Bithead
  • 12454 Views
  • 16 replies
  • 0 Likes

Resolved! debug dataplane reset ssl-decrypt certificate-status command

Hi All, I was just wondering if running the below command will have any impact on a production environment or is it merely resetting the cache status and shouldn't have issues to run in production? >debug dataplane reset ssl-decrypt certificate-status Thanks.

Ben-Price by L4 Transporter
  • 3649 Views
  • 1 replies
  • 0 Likes

Global Protect AutoVPN and Windows 10 Login Screen

When I login to my laptop computer - underneath my user name for sign in SOMETIMES is the statusmessage: GlobalProtect Status: Connected (and under it the name of the GP portal/gateway.) But at other times I see no such message or "sign in options". If sign on options are there one includes the GP logo w check on it. A third issue now I've seen...

palomed by L3 Networker
  • 21588 Views
  • 7 replies
  • 0 Likes

User-ID agent

We have User-ID agent installed on windows VM server. We want to increas the RAM on this VM to improve the performance. If I shutdown this VM, what will be the impact on user authentication during VM remain shut down? Please refer me to some KB so that I can do this activity.

Resolved! Palo Alto Test Pages - Inconsistent Results

Hi All, I noticed that the Palo Alto test pages for 'newly-registered-domains' and 'command-and-control' do not block when copied from a chat window or manually entered into a web browser. However when I directly click the link on the Palo Alto test pages for 'newly-registered-domains' and 'command-and-control' they do block. This does not appea...

Josh990 by L2 Linker
  • 3286 Views
  • 2 replies
  • 0 Likes

Getting Low Speed

Guys, My Lan users are getting a slow downloading speed. I have checked the ISP cable directly and there I am getting the accurate speed which is 30Mbps. But when I am connecting the ISP cable to Paloalto after that I am running the speed test it's gives me only 4 Mbps. I have tested also one pc with no URL filtering or no profiles applied on it...

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels