General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 410 Views
  • 0 replies
  • 2 Likes

"export to CSV" - limit

What is the maximum limit on the number of lines to return? can it be increased?

want to know what they do during siesta? see for yourself on the spanish porno tube https://pornogratisaqu.com/

 

 

 

 

 

ducuxawi by L0 Member
  • 1567 Views
  • 1 replies
  • 0 Likes

Resolved! Can I use CA Root Certificate for Debrypting SSL Traffic?

Hello,

 

I want o start setting using Decryption Policy, to Decrypt & Intercept SSL (443) traffic from users when connecting to Internet.

 

I am wondering, can I use one of the well known Certificate Trusted, e.g., Global Sign by installing it on the Pal

...

mshamsan by L1 Bithead
  • 4030 Views
  • 4 replies
  • 0 Likes

Resolved! Ineffective IP spoofing protection

I have IP spoofing protection enabled on PaloAlto but it is not effective due to the following reason:

 

My external Interface IP is 1.2.3.1/24 . The spoofed attacks are coming from a fictitious source IP for e.g. 1.2.3.25 destined to 1.2.3.50(web serv

...

Resolved! Traffic Thourhg the intended Security Rule

Hello,

 

I have configured a new Security Rule on top (#9 in the picture down) to Block traffic intended to a Custom URL configured in the profile  Block_Files

* TOP RULE *

  • Source Zone:                     any
  • Source Address:              any
  • Destination Z
...

mshamsan by L1 Bithead
  • 2955 Views
  • 3 replies
  • 0 Likes

HA Active/Passive with Preemption

2 firewalls configured with HA active/passive, And enabled preempt on both of firewalls

Everythings find, can synchronize configuration and session

 

firewall-A is active-firewall with priority 100

firewall-B is passive-firewall with priority 120

HA timer

...

IKE SA negotiation is started as initiator, non-rekey

Hello :),

I have a problem with VPN from PA-220 to Azure. The logs show this information : "IKEv2 IKE SA negotiation is started as initiator, non-rekey. Initiated SA " 

Every change I made it always is this same error. Is there any way to resolve this

...

Lukaszm1 by L1 Bithead
  • 35168 Views
  • 9 replies
  • 0 Likes

System Logs

Hi,

 

Do we have any list of critical and high severity system logs? Like what are the examples of hardware failures, serious issues etc...

user-id-agent-sequence is invalid.

Hi Team,

 

I'm seeing configuration invalid when I remove user-id agent from palo alto firewall and not able to commit.

 

PA-220 PANOS version 8.0.3.  Same model firewall I have removed I can able to commit.

 

Only in this firewall, I'm seeing this issue.

 

...

Screenshot (500).png

Total number of profiles

Hi,

 

We have the problem with the total number of security profiles.

As you can see in attached screenshot the maximum number of profiles is 100, for now we have 84, but when I tried to add new one I get the capacity error.

 

Maybe someone had the same p

...

Resolved! Packet Flow Query - FW Inspection

Hi Everyone,

 

I've been madly studying the Packet Flow Diagram that outlines the different checks/stages that a Packet goes through via a PA FW and I had a question with the 3rd check in the Ingress phase called 'FW Inspection applicable'. If Inspecti

...

  • 23695 Posts
  • 110 Subscriptions
Top Solution Authors
Labels