General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4436 Views
  • 0 replies
  • 0 Likes

Debug Dataplane Help

Hello, I am trying to troubleshoot an error in a traffic log regarding cert decryption. I have found an article from PA on it: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boONCAY but I am unable to reproduce the steps to help in troubleshooting. The fourth bullet says 'Dataplane Debug shows the following..." and ...

COlson by L2 Linker
  • 2417 Views
  • 1 replies
  • 1 Likes

New Product mention feature

Hey everyone, We just enabled a feature on the LIVEcommunity that allows for products to be linked inside of discussions or articles.. this helps cross link information throughout the site, especially useful if you are looking for specific information for a certain product.. Like Prisma SD-WAN or Cortex XSOAR or even if just NGFW It is si...

jdelio by L7 Applicator
  • 5586 Views
  • 1 replies
  • 4 Likes

Resolved! SAML (SSO) not in authentication sequence ?

I am trying to create authentication sequence to first try my SAML profile then local emergency account. But in authentication sequence I can only pick LDAP, RADIUS or local based profiles ? How I can include SAML (SSO) in my auth sequence ?

niuk by L3 Networker
  • 5935 Views
  • 3 replies
  • 0 Likes

Resolved! Fiber port on PA850

Hi All,We are in the process of moving ISP providers and the hand is SMF/LC, our PA-850 is using copper for our current connection, can we configure a port on the PA to handle Fiber?

ATanveer by L0 Member
  • 3453 Views
  • 2 replies
  • 1 Likes

deactivate VM License question

I have an odd scenario going on where we installed a VM-300 license but did not have the proper resources applied to the VM. When we clicked install on the license the VM then locked up and errored on boot complaining about memory. We fixed the memory allocation issue in ESX (set to 9GB) and the VM booted with no issues and shows the VM-300 li...

geewiss by L2 Linker
  • 3088 Views
  • 2 replies
  • 0 Likes

Resolved! Packet Captures issues

Hello Friends I am trying to take packet captures on my firewall. But in captures I do not see all the packets. What may be the issue? Am I missing anything?

d.spider by L2 Linker
  • 9228 Views
  • 8 replies
  • 0 Likes

VPN not working (changed IP Public)

Hello guys, I have a problem that i've been the whole day trying to make it work but i can't and i have to solve it asap.I have around 12 vpn connections peer to peer working. I have to change those vpn connections to another IP Public little by little (my peer IP).I tried today with 3 vpn sites modifying: - IKE Gateway: modifying Interface, loc...

Resolved! PAN Microsegmentation of DMZ

I am spinning up a new DMZ and wonder if there was a some means of restricting traffic between hosts on the DMZ using the PAN. I have a Cisco Nexus switch and the hosts are VMs in Cisco UCS. Thank you.

palomed by L3 Networker
  • 3437 Views
  • 2 replies
  • 1 Likes

Detecting UserAgent spoofing

Does anyone know if PanOS v10+ can identify when a UserAgent is being spoofed? I've been looking through the discussion boards and online user documentation and haven't been able to find any results. I'm trying to see if we can catch when a device tries to circumvent restriction policies by claiming to be a different device.

Resolved! HIP Profile Windows 11

As stated in Where Can I Install the GlobalProtect App? (paloaltonetworks.com) the official client for W11 is > 5.2.10Personally, I've used version ~5.2.7 without issues, the only thing I noticed was that detected host for HIP Profile was Microsoft Windows 10 Pro. Now that I've updated to version 5.2.10-6, detected host is Microsoft Windows 1...

etoribio_0-1641305326992.png
etoribio by L0 Member
  • 7257 Views
  • 2 replies
  • 1 Likes

Resolved! User-ID Agent - not populating PAN

We have been using the User-ID Agent and it has been working for over a year. On the 17th, the PAN stopped populating the traffic log with the user-id information. The Agent is working fine (user ids show up in the monitor) and the PAN is connecting the Agent, but no user information is showing up. I have checked through the config logs, and not...

craymond by L4 Transporter
  • 11089 Views
  • 11 replies
  • 0 Likes

Resolved! Panorama - Template objects not shared by firewall cluster

I added an existing firewall Active/Active Cluster with multiple Vsys into Panorama Before the integration, some Device objects like "certificates" or "Local user database" were shared by the firewalls member of the cluster. Now I need to create the objects twice times in each template of the firewalls. Is it possible to manage it like before a...

User-ID Windows agent failing to query

Beginning sometime last week (possibly on 12/26) our Windows-based User-ID agent stopped being able to query our DCs for user-to-IP mappings. The PA shows 1000s of request for IP mappings msgs with little to no response msgs from the agent. The agent server debug log shows a long queue of pending lookups with occasional WMI/Netbios access errors...

  • 24374 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels