General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4138 Views
  • 0 replies
  • 0 Likes

Inbound traffic to DMZ issue

We have reports of certain users not being able to access our public website but majority of users are able to. The traffic log shows that the application is incomplete. Packet capture reveals the 3-way handshake does not complete and the session times out. The same person who is NOT able to access the public website is able to access another we...

x by L1 Bithead
  • 7873 Views
  • 5 replies
  • 0 Likes

VPN IPSec Configuration Disappeared from GUI

An issue where I can’t view any configured IPSec Tunnels in GUI,From CLI, the IPSec tunnels appear normally. Tried failover, restarting management service, even rebooting both Palo Alto units, using different browsers, different computers, and export; import and load the configuration file with no success. Device Model: PA-5220 HA Mode Active-st...

PA-850 Migration to 10Gb SFP+ Interface

Hi, I have a customer who was a PA-850 firewall. There connection to their LAN is currently using a 1Gb Ethernet port (Port 4). They are in the process of upgrading the network backbone to be 10Gb and wanted to change their connection to the Firewall to 10Gb too. Is there any easy way to migrate all of the settings they have setup from port 4 to...

dvdkevin by L0 Member
  • 4736 Views
  • 2 replies
  • 0 Likes

Resolved! Block Windows 7

I am trying to block Windows 7 clients from accessing the internet. I have followed the steps here: https://live.paloaltonetworks.com/t5/Configuration-Articles/Custom-vulnerability-signature-for-identifying-Windows-XP/tac-p/72273#M1496but I am unclear on what to set for the Pattern. Any suggestions/help to accomplish that goal will be apprecia...

GlobalProtect and "client sleep mode"

Hello,as described in the "GlobalProtect 1.1.6: Addressed Issues" (issue point 35361) the unnecessarily reconnection after sleep/hibernate mode should be fixed.We are using the GlobalProtect Version 1.1.7 . The portal configuration are:"On demand" mode, as authentication "certificate profile" only,single sign-on on, agent user override disabled,...

Hithead by L4 Transporter
  • 13418 Views
  • 7 replies
  • 0 Likes

Resolved! Custom App for CRL downloads

Hi,I am trying to create a custom app that will match CRL downloads, to allow them without any questions ask. Shouldn't be too hard : on a previous web security gateway, I would match a pattern like the following: "http://([^/:])*crl.*\.crl"When translated to an app signature, I already know I am looking for two patterns, on the following contex...

dennisss by L1 Bithead
  • 27204 Views
  • 20 replies
  • 0 Likes

Resolved! PAN-OS 9.1.11-h3 upgrade file

Hi support, May I know the upgrade file for PAN-OS 9.1.11-h3? I could not confirm it. Below is my environmentPA-5200 platformVM seriesPanorama M images Thanks !!!

Global Protect HIP Check - Defender ATP

Hi, we're implementing Defender ATP as an anti-malware solution. I would like HIP checks to restrict Global Protect connections from clients without a recent AV scan performed, without Real Time Protection Enabled or with out-of-date virus definitions, however the GP Host profile on the client doesn't collect this information: Many full scans h...

Screenshot 2020-03-27 at 09.48.22.png
it_dist by L1 Bithead
  • 10768 Views
  • 5 replies
  • 0 Likes

Bypassing "Packets dropped: forwarded to different zone" limitation

Dear community! I´d like to consult with you for a possible solution for this scenario:We have 2 internet lines from two interfaces of the PAN firewall connected to two different routers. Each interface is in a different zone.When incoming and returning packets follow different paths then we have an asymmetric routing condition. Situation simila...

Carracido by L4 Transporter
  • 7494 Views
  • 5 replies
  • 0 Likes

Resolved! GP VPN agent issue

Hi Team, We have a setup like GP VPN and cisco duo. When a user is trying to connect to GP it will send a request to the cisco duo and once the cisco duo will approve the connection, the user will access the GP. One of our system is not working properly. It will give the error "Unable to establish the connection and please restart your computer"...

VishnuPS by L3 Networker
  • 2694 Views
  • 1 replies
  • 0 Likes

Resolved! How to release a vpn tunnel?

I have alot of tunnels between nodes, and it seem periodically one will hang, almost like a zombie process.Is there away to break/kill this tunnel down without taking the other tunnels down?

erantanen by Not applicable
  • 9842 Views
  • 2 replies
  • 0 Likes

Licenses on Airgapped Panorama

Hi guys, I was wondering if anyone has any experience using a totally airgapped panorama/firewalls deployment.At the moment I have a case where none of the devices are allowed any outside connections.I thought it would be do-able since both software and content updates can be manually uploaded to panorama and deployed like this, and license keys...

How to configure FQDN

Hello, I need know how to allow create FQDN in PA firewall 3020 and to use URL name instead of adding all IP ranges. Appreciate your help Thanks

mmarie by L1 Bithead
  • 2572 Views
  • 1 replies
  • 0 Likes
  • 24340 Posts
  • 124 Subscriptions
Top Liked Authors
Labels