General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4455 Views
  • 0 replies
  • 0 Likes

Migration from 5250HA to 3250HA

Hi Everyone We plan to migrate 5250HA to 3250HA. See if anyone has past experience. 5250HA Policy and objects tab are managed by Panorama, All rest is still on local. Main change is interface on 5200.e.g internet or DMZ zone includes 1G and 10G interface 1/4 and 5 and On 3200 It will be changed to interface 20 and 21 for example.If modify the in...

Resolved! How to make upstream connected devices learn that downstream core switches are down

Hi all, We have active passive setup of firewalls in both DC and DR site. The scenario I am trying to work on is, if my downstream connected core switches are down in primary DC, how can make ISP and MPLS connected devices on my upstream learn that all traffic should be routed to DR site firewalls. Basically, How can we make ISP and MPLS router...

Sukhmeet by L1 Bithead
  • 5216 Views
  • 3 replies
  • 0 Likes

dual catergory url checking

hello community. I notice that this site https://www.pokmi.com/ is in dual category for Adult and catagory low Risk. I made an url filtering rules that allow low risk category but that block adult category. when I apply this rules to my traffic I have access to this site. off course as my site category is adult I want's that the firewall block ...

fcorfdir by L2 Linker
  • 2052 Views
  • 1 replies
  • 0 Likes

inter-compatibility

Hi All, PA3020 and PA200 are used to form an IPSEC tunnel. Would there be any compatibility issue if we upgrade PA3020 to PANOS 9.1.12-h4 while keeping PA200 on PANOS 8.1.21?Any known issues if we upgrade PA3020 to PanOS 9.1.12-h4? PA3020 Current PanOS: 8.1.20-h1

ongkai by L1 Bithead
  • 2355 Views
  • 2 replies
  • 0 Likes

Clientless VPN oracle app is not working.

Dear Team, I have configured a clientless VPN. when I open a portal and launch the oracle app it is not working getting the below error:- Troubleshooting:- - I have checked, I can open the same oracle application by an internal network. (Traffic is not going through the firewall). - Checked DNS proxy setting it is working fine. (I can resolve ...

Jafar_Hussain_0-1584981578187.png

SSL decryption - Connection is not Private

Hi Team,I am configuring SSL decryption on Palo Alto using a self-signed CA. I have created two certificates, one for forward trust and second for forward untrust. I have installed the forward trust certificate into the trusted root CA of the machine.The issue is that I keep getting Your connection is not private message for all the sites that I...

Resolved! Decryption Exclusion methods

From what I can tell there are three methods to exclude traffic from decryption: 1) Custom URL Category - Requires a Commit to the device group when adding URLs2) SSL Decryption Exclusion List - Must be added to each Firewall template and then Commit3) External Device List - edit text file on external server Seems to me that the EDL is the best/...

Resolved! Clarity with wildcards used for custom objects

I'm trying to have a clear understanding of wild cards and ending tokens when using them for custom URL categories. What's the difference in behavior when using *.site.com/ versus site.com/ ??? The pop-up doesn't seem to mention wild cards in the scenario. "if you want to allow xyz.com and enter the domain as 'xyz.com,' you will allow xyz.co...

dgagnon by L1 Bithead
  • 3846 Views
  • 3 replies
  • 0 Likes

PA-5000 SSD replacement

We have 2 PA-5020 working as active/passive. We have dual SSDs configured in RAID and the SSD model on the active and passive device is SSDSA2CW12. We have to replace SSD in active firewall. However the RMA sent is a different model and is of size 240 GB. We went through a document Configuring RAID with Non-matching Models of SSDs for the replac...

RUNTEAM by L0 Member
  • 2332 Views
  • 1 replies
  • 0 Likes

ECMP Configuration Questions

Hi, New to the board. I have two WAN circuits going to two separate ISPs. I would like to run ECMP with weighted round robin over ISP1 & ISP2. However, I want to verify this can be achieved successfully in my environment. I have 15-20 VPN connections to various agencies which all must go out the correct circuit (ISP1) and IP address. I ...

Integrate Captive Portal with ADFS using SAML Authentication

Another post regarding an additional method for gaining userID info for non-domain joined assets. There are lots of examples of using other idPs, but not much I could find regarding ADFS, so hope this is helpful for others looking for a similar option. To begin, create an Auth policy and list the matching criteria. In my config, I used,- src...

jbworley_0-1643155992357.png
jbworley_1-1643155992361.png
jbworley_2-1643155992364.png
jbworley_3-1643155992371.png
jbworley by L1 Bithead
  • 7984 Views
  • 1 replies
  • 3 Likes

Resolved! Wildfire Blocking on Informational

On my PAN 3220 which is handling Global Protect I am seeing a lot of Wildfire activity where the verdict for thesefile upload is benign, severity only informational but the action is to Block. Any insight as to what might be going on?

palomed_1-1643222066995.png
palomed by L3 Networker
  • 2881 Views
  • 1 replies
  • 0 Likes

Resolved! Behaviour of A-URL subscription in PANOS 8.1

Hi all,Knowing that PAN-DB URL4 license is no longer for sales since last Nov, we have renewed our subscription to A-URL now. After renewal, I can see my other WF, TP licenses have been renewed successfully in Device -> License, however, still showing my PAN-DB license is going to expired in WebUI, and cannot see my A-URL license? Our firewa...

Resolved! Failed to Send Email Reports

Hi Team, We have configured, Email Scheduler for the Daily report, We are tested the email severs communication and the email scheduler communication also fine. But we are not receiving the report, We are receiving the below error in system logs, " Failed to email PDF reports to 'xxxx@xxx.com' for email profile Administrator " Please help me w...

  • 24376 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels