General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 3005 Views
  • 0 replies
  • 0 Likes

Resolved! Delete Vsys

Any advice on deleting a vsys? 7050 OS 9.0.11

 

Simple as selecting vsys under Device Tab and deleting?

 

Thanks

clewis1 by L3 Networker
  • 5922 Views
  • 6 replies
  • 0 Likes

Regarding threat visibility not being shown.

We have deployed Palo Alto in tap mode to get traffic visibility, we have configured PA VM 100 with active trial license,  We have visibility of Traffic logs but the threat logs are not visible. 

In policy configuration for tap mode we also have assig

...

Users and group mapping

Hello everybody!


Sometimes users' group memberships are not recognized by the firewall integrated user id agent. In the useridd.log we see this message:


2019-03-29 10:12:45.317 +0100 Warning: pan_user_group_user_prime_uid_lookup(pan_user_group_multi_at...

Resolved! Policy base routing for internal trafique

 

Hello everyone,

 

I have two ISPs wan1 and wan2, for lan 1 it must go out through wan1 and lan2 through wan2. in the event of a problem with one of the wans, the associated lan will have to exit through the other wan temporarily. To do this, configure

...

Capture.PNG

One IPSec SA Stops Passing Traffic

I have a B2B tunnel with a business partner.  There are 22 proxies, all defined host-to-host.  The VPN peer is a Cisco firewall, I'm not sure of the model.  Phase 2 lifetime is 8 hours.  One particular SA stops sending and receiving traffic at each P

...

pnelson by L2 Linker
  • 4358 Views
  • 3 replies
  • 0 Likes

Resolved! One session is utilizing 5-12% of CPU of my 5220 firewall

One session is utilizing 5-12% of CPU of my 5220 firewall.

 

Session ID: 2155872259

 

show session id 2155872259

 

 

Session 2155872259

Bad Key: c2s: 'c2s'
Bad Key: s2c: 's2c'
index(local): : 8388611

I am not able to check the session information. Getting bad K

...

NijithPN by L1 Bithead
  • 5371 Views
  • 3 replies
  • 0 Likes

X-VPN not getting decrypted

Hello,

 

We would like to block the application X-VPN (used on apple iOS system as a VPN app). Using PAN-OS 8.0.1
The firewall sees the traffic as either SSL, web-browsing or google base traffic and doesn’t appear to be decrypting it.

The session ID says

...

1.png
2.png
Farzana by L4 Transporter
  • 12028 Views
  • 7 replies
  • 0 Likes

Resolved! Failed to download dynamic updates

Hello,

 

I haven't been able to download any dynamic updates to our Palo VM-100 for a little over an hour.

 

The message Failed to download file appears and in the system log I see connection to update server closed.

For example, I also tried to download

...

  • 24286 Posts
  • 122 Subscriptions
Top Solution Authors
Top Liked Authors
Labels