General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Panorama import devices with simi lar config

Hi, I have to import several FWs (branches) in Panorama. All the FW has similar config/object related to interfaces IP, objects, etc. It could be any issue in the device groups or templated if all branches have same same internal IP interface. I thought to create a template and Device Group unique for each branch. Thanks

BigPalo by • L4 Transporter
  • 1066 Views
  • 1 replies
  • 0 Likes

VPN Gateway fails to authenticate clients with new certificate uploaded

Dear all, We have a Palo Alto VPN gateway at our office, where our clients and customer’s Palo Alto connects to! Our certificate at one of our customers site has expired and the vpn connection is down and hence to the isp! Now I have generated a private key, using that I have generated a CSR sent the CSR to the CA and they have returned the ...

Replacing HA Hardware

Hi All, I need to replace 3220 in HA to 1420 in HA. - The 3220 running 11.1.3-h3 - I installed 11.1.3-h3 on the new 1420s. - Installed the same version of the apps and threats. - exported the running config from the 3220 - imported the config to the 1420 and ran a commit. I read that i cannot run the HA with different platforms. Is there a way...

SFP Compatibility

hello tech enthusiast, I want to connect a fiber cable between two PA firwalls, thats what i did but i have the interface down on both ends even, and i dont know what to put as a SFP Plus, when i run the command show system state filter sys.s1.p6.phy i have a vendor-part-number: SFP-10G-LR-PO but when i do that on a working interface a have v...

Can`t proceed to customer support portal

The first i created an account for Customer support portal and I'm Stock with this Your account is currently waiting for your company’s Super User Approval. Access will not be provided until this approval is received. To help speed things along, you must reach out to your Super User for approval.You can click here to send your Super User a rem...

VM Trial License

HiI am trying to obtain a TRIAL LICENSE for a VM. I am using EVE-NG and need to set up a training lab. I dont want to associate it with' our current Palo Altos. How can i go about obtaining one? Thanks

mzedalis by • L0 Member
  • 2182 Views
  • 3 replies
  • 0 Likes

Struggling to Unset Virtual Router from Interface via API – Manual Works, API Always Fails

Hi everyone, I’m working on automating Palo Alto firewall configuration via the API and I’ve run into a puzzling issue. What I’m Trying to Do: Unset the Virtual Router assigned to a specific Layer3 Ethernet interface (e.g., ae2.4008) using the API. Manually, I can easily go to the GUI and set the Virtual Router to none, and everything works ...

AK_20201 by • L0 Member
  • 739 Views
  • 0 replies
  • 0 Likes

Renew Palo Alto Global Protect Certificate issued by Public CA

Dear All, I need some immediate assistance with this. Can you anyone help me out. We have a Palo Alto VPN Gateway at our office where client connect to the internal Network via Remote Access VPN. Now recenlty the certificate was expired the following is what I did. 1. Generated a Private key using OpenSSL. 2. Generated a CSR using that Pri...

Zone rename effects on Shared Policies

After a company acquisition we have inherited about 25 firewalls which I have recently migrated to a single Panorama instance, along with shared policies and templates, and in the process of building shared policies for the entire fleet. For the shared policies to work, zone names need to be consistent across about 40 odd gateways, unfortunatley...

Is there a need for a book on PAN-OS "Policy as Code" subject?

Dear All, I am looking to determine if there is a demand in the market for a guide to PAN-OS security policy automation ("policy as code"). There is plenty of reference information (https://pan.dev is always a good starting point) but there is no resource/book that would take one of the available automation frameworks and demonstrate how to ...

Assistance Required – Cybersecurity Fundamentals Certificate Not Unlocking

Hello Beacon Support Team, I recently completed the Cybersecurity Fundamentals course on Beacon. However, my progress is stuck on Module 4 even though I have already gone through all the lessons and quizzes. The platform keeps sending me back to Module 4, and my course completion status is not updating to 100%. Because of this, I’m unable to dow...

combiyke by • L0 Member
  • 1520 Views
  • 1 replies
  • 0 Likes

About CVSS version

Hello PaloAlto Networks Team, What version of CVSS is listed in Palo Alto Networks Security Advisories? Please tell me which version it is, such as CVSS v3 or v4. Regards,

IPSec HA Failover - Feature Request NSFR-I-26043

As of this post, Palo Alto Firewalls do not sync Phase 1 for IPSec Tunnels. If a remote end is using Dead Peer Detection, this will cause the tunnel to go down after a failover occurs and the remote end DPD hits its threshold. Since the Palo no longer has Phase 1, it cannot respond to the DPD. Despite Phase 2 being up and working, the DPD will p...

spapesh by • L1 Bithead
  • 1934 Views
  • 2 replies
  • 1 Likes
  • 24457 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels