General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4119 Views
  • 0 replies
  • 0 Likes

Unable to SSH to Passive firewall, GUI OK

hello everyone,I lost SSH access to my PA-3020 passive firewall on mgmt. interface.. I can access it via GUI.for Active Firewall, both SSH and GUI are OK.I think it happened after I did fixing weak ciphers and keys on mgmt. interface. interface for SSH access.I did the following procedure on both active/passive FW.https://knowledgebase.paloalto...

zinkt101 by L1 Bithead
  • 8050 Views
  • 2 replies
  • 0 Likes

Need help understanding how to setup conditions for Firewalls

As it stands m firewall looks at rules in a sequential sense and applies rules in that way. meaning if it reaches a Deny it will immediately cancel a packet (which isn't necessarily bad) but it also means if a rule permits a user to do something interferes with another that denies him something - the user will get access to things they shouldn't...

Resolved! Unable to see groups in group mapping setting in Palo alto

Group with three to 4 user was added in ad with group name (vpn group for laptop) and this group was under OU group id, but in group id i was able to see groups till alphabet N ,so tested creating Group with group name (ATEST users) i was able to see this group ,but (vpn group for laptop) this group was not visibleTried all below commands:->s...

live community_ss_ad.PNG
KashifSh by L1 Bithead
  • 4135 Views
  • 2 replies
  • 0 Likes

Resolved! RADIUS Server failover not working via Authentication Profile

I have two servers listed in my RADIUS Server Profile.If I shutdown RADIUS on the server that is first in the list I do not see my firewall attempt authentication to the second server. Authentication fails.If I completely shutdown the first server in the list I do not see any attempts to authenticate to the second server. Authentication fails....

ebonjour by L2 Linker
  • 26283 Views
  • 14 replies
  • 0 Likes

Tunnel Monitor with AWS

Hello Everyone Does Tunnel monitor work PA - AWS IPSec ?I've heard it will not work, only PA - PA Connection I'd appreciate it if you could help me !Thanks !

Resolved! Issue with Captive Portal

Our domain joined computers are getting prompted to sign into captive portal, however this is a random occurrence as some occasions it wouldn’t and we would be able to connect to the internet. How to stop this issue?

Configuring QoS on VLAN interface

Hi guys,We want to apply QoS on our inside zone for downloads, but it's not hitting the QoS Policy, here's our conifg:For the Inside Zone (users zone) we have an L2 interface eth1/1 and one VLAN interface linked to the subnet.We created a QoS Profile with Class 1 Egress Max = 0.2 mbps (everything else was left at default).In Network > QoS, we...

echahine by L2 Linker
  • 5663 Views
  • 4 replies
  • 0 Likes

Destnation NAT by https kindly help

I have one real ip address and I have three web sites. Is it possible to work on them on the same port 443 , and the difference is according to the site address? i asked for NAT Solution in paloalto kindly help

Osamaps by L0 Member
  • 2204 Views
  • 2 replies
  • 0 Likes

Unable to log case

I am going to raise a case but when I get to the section of selecting the asset affected there are no tick boxes next to any of the assets. The filtering dropdowns on the columns also appear to be missing the images however these options do still work.

BGP Session flaps for every 3 minutes - PAN OS

Hi Team, We have a BGP running over IPSec VPN. The VPN is terminated between PA 5250 and SDN Gateway. The VPN is running fine but the BGP session is flapping for every 3 minutes. Normally this behavior observed due to MTU size detection in during PMTUD in Cisco devices. Please help me to troubleshoot this further in the Palo Alto Firewall side....

Resolved! Autofocus license

Hi there! I'd like to know what is the difference between the autofocus enterprise edition vs standard edition? Could anyone help me? I already searched in Palo alto docs but I didn't find nothing Best!

MonicaR by L1 Bithead
  • 2701 Views
  • 1 replies
  • 0 Likes

Resolved! Custom URL Category override wildcard matches with more specifics?

Is there a way, within the URL Categories, to override wildcarded domain blocks in one category with more specific allows in another category? E.g. we have created custom URL categories for company allowed and blocked domains. I have a wildcarded domain that was put in a custom block category do to Infosec policies. Now I need to add that specif...

  • 24336 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels