General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Basic PA FW Training Delivery

Hello PA World, Need the good community's help to deliver a basic PaloAlto FW course to trainees as part of a Networking Curriculum. Any open source resources that are available for training delivery are invited and thanked for in advance. Have already applied for the Trail VM but it may take 3 or more working days for review, dont have th...

Jpin108 by L0 Member
  • 1987 Views
  • 1 replies
  • 0 Likes

Resolved! Issue with Ticket Support Application (Get Help)

Hello, I have a problem while creating a new ticket. When I arrive to select asset or serial, at the step that says "Find Asset Tenant ID/ Serial #" I can't select the asset and because of this, I can't end the ticket. Could anybody help me? Thanks.

How to view transceiver values on the cli

I need help finding the transceiver values in a PA-5220. In Cisco world the command is 'sh int e 1/5 transceiver details'. And it produces this output.Ethernet1/5transceiver is presenttype is 10Gbase-SRname is CISCO-JDSUpart number is PLRXPL-SC-S43-CSrevision is 1serial number is JUR1932GG49nominal bitrate is 10300 MBit/secLink length supported ...

Resolved! Captive Portal Custom Page

Hello, I want to implement a custom response page for our captive portal and I am not sure how the profile selects which page to us. Do I have to delete the default page or is there a way to select between two pages? Thank You

PA 3060

Hello I have A/P cluster PA 3060 with 9.0.9 I want to upgrade to 9.1.11 Can i directly do it ? Or do i have to download 9.1.0 first ? and then download+ install 9.1.11 Is downloading 9.1.0 necessary ?

Resolved! Captive Portal doesn't work for remote offices

Greetings to allI have the scenario described in the graph: I use Captive Portal based authentication for certain devices. It works fine for the LAN zone, but not for the WAN zone.In the WAN Zone we have remote offices that connect through the MPLS of a service provider. Then, over that data link, we build an IPSec tunnel to establish the connec...

adiazm_0-1630073510049.png
adiazm by L1 Bithead
  • 4615 Views
  • 4 replies
  • 0 Likes

Layer 2 vlan subinterface restriction?

HelloI am using PA VM-50 and wonder if there is any restriction on the number of Layer 2 subinterfaces that I can create under 1 interface. I have more than 50 vlan subinterfaces created and the one I have added recently does not seem to pass traffic. Thanks

Workstations no internet after receive IP from firewall DHCP Server

Hi,We have a PaloAlto firewall which is connected to a Cisco switch and on this Cisco swtich an AP is connected.On the firewall I use ethernet 1/2 port to handle the free wifi clients. This port is in Layer 3 mode.This port is connected with the Cisco switch. The port on the Cisco switch is configured in access mode and in vlan 5.On my AP I set ...

ZEBIT by L3 Networker
  • 5411 Views
  • 3 replies
  • 0 Likes

Resolved! Firewall upgrades guidance

Hello we have a customer with central location acting as Datacenter with PA 3000 series. The panorama also stays in same DC. All the other locations worldwide are connected to central DC over IPSEC tunnels. Most of the firewalls running at remote sites are having 8.x version. We want to upgrade all of them to 10.x . I checked hardware wise all m...

Resolved! high CPU (management plane) after enabling ECMP

Hello We have an active/passive cluster (PA-820) which we use for IPSec tunnels (with 30 different partners).One of the partners insisted on having a redundant connection using two IPSec tunnels with different peers. So we came up with the idea of enabling ECMP. Based on the routing table, this looks fine (same destination network listed twice, ...

Resolved! GlobalProtect monitoring

I need to graph GlobalProtect current users + traffic via SNMP. I cannot find anything in SNMPwalk or in the available MIBs.I looked through some older discussions but it seems there is no immediate answer. Any update?Thanks

Routing issues when using NAT over VPN

I'm looking at this document. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClipCACIt says our selected NAT addresses (2.2.2.0/24 on PA-2020 in this case) need to be routed to a tunnel interface, in order for policy lookup to work. Let's imagine I'm using 2.2.2.0/24 on the PA-2020 for NAT'ing traffic not only towards...

mathiasj by L1 Bithead
  • 2468 Views
  • 2 replies
  • 0 Likes

Customer Support Portal Inquiry: devices in assets under customer profile does not show the updated PANOS version.

Customer updated all devices to latest PANOS version after receiving the email for CVE-2021-3064. However, the PANOS versions for the devices are still showing the older version (8.1.6) in the customer support view. Customer can open each devices and change the PANOS version manually. Cx asks, Shouldn't It update the PANOS version on this view b...

assets-devices.JPG
morahman by L1 Bithead
  • 2139 Views
  • 1 replies
  • 0 Likes
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels