General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4327 Views
  • 0 replies
  • 0 Likes

Email attachment issue

Hi Team, We have configured Email alert scheduler to get logs daily and monthly. We getting daily logs with attachments and not getting monthly logs and attachments. Sometimes we getting monthly logs email but attachments are not there. PANOS 10.0.5 and tried to restart the mgmt server but the issue is still the same and we observed the firewal...

VishnuPS by L3 Networker
  • 3565 Views
  • 3 replies
  • 0 Likes

Does anyone use HIP check on the local LAN as a NAC solution?

I understand that a HIP check can be used on the local LAN when the GlobalProtect client connects to the internal gateway. How effective is this as a NAC solution for the internal LAN?Without 802.1x authentication, does a machine without GP installed simply bypass the internal gateway (and HIP check)?Thanks

Maxstr by L3 Networker
  • 6137 Views
  • 3 replies
  • 0 Likes

Resolved! Vulnerability protection profile changed his icon

hey guys, i think it might related to configuration issues, but i cant find what went wrong.the vulnerability profile icon looks like this:but in the policies tab, i get this big red exclamation mark: any ideas if something went wrong?pan-os ver is 10.0.1 thanks in advance,Ishai.

1.jpg
2.jpg

HA Clustering session synchronization

Hello!I have some question about session synchronization in HA Clustering (geographic cluster). All firewalls in HA clustering use the first rule for traffic that should not match it, this only happens on geoclustered firewalls. Later, the rules are processed correctly, but the first one is always used, so I see incorrect traffic in the logs.Exa...

Block Access to private Gmail but allow corporate

Hi all.Im looking for a solution to block user access to private gmail accounts but allow a corporate accounts to be used.I'm aware that there is a solution involing proxy server and X-forwarder.Is there any other way to do this without dedicated proxy serever? RegardsLeo

Resolved! IPSec VPN Ingress traffic from two different interfaces not passing traffic.

Hey All, We're having a problem in adding new traffic to an existing VPN Tunnel. We've had a VPN tunnel up for a few years working just fine, but now we are trying to put traffic from a different interface into the Tunnel and the PA is dropping the packets (found them in Traffic Capture). The VPN is out to the Internet on Eth1/1 and the origin...

rswinter by L1 Bithead
  • 5640 Views
  • 3 replies
  • 0 Likes

Authentication of Users through Captive portal query

Hi Team, We had configured captive portal on the firewall recently. In Authentication policy we had selected source users as any and we are using Active Directory for Authentication. Also we had configured agentless user-id mapping on the firewall and server monitoring to fetch details from AD server for User-IP mapping to feed onto the firewall...

Creating subinterfaces on Active Active HA

Hello , I have to create 6 Subinterfaces on A/A cluster So i need 3 IP addresses from each VLAN - 1 for FW1 , 1 for FW2 and 1 as Floating IP My question is , do i have to go to each firewall separately to configure the respective IP ?If yes , what will happen if i do commit the 2nd FW , will it create an issue ? Also ,under HA , in active , ac...

Error while creating a user

Hi All, Facing an error (application icloud-uploading not found) while creating a user on my palo alto 850 using panorama. Attaching the image for better idea. Pls help

IPSEC VPN tunnel getting disconnected.

IPSEC VPN tunnel got disconnected abruptly. We need to find out what could have caused this from the logs and adjust the VPN parameters accordingly. From logs i found this. ikemgr.log2021-10-15 03:35:112021-10-15 03:35:11.814 +0000 [PNTF]: { 5: }: ====> PHASE-2 NEGOTIATION STARTED AS RESPONDER, (QUICK MODE) <====ikemgr.log2021-10-15 03:3...

RPrasad3 by L0 Member
  • 5881 Views
  • 2 replies
  • 0 Likes

Adding a port to existing SSN

Hi - I have an existing SSN configured for a device with ports added in Objects, like to add few more ports. what are steps I need follow? Please let me know....Thanks!

Andyz88 by L0 Member
  • 2005 Views
  • 1 replies
  • 0 Likes

problem with userIDAgent in RDP

hello We have a problem with users when they connect in RDP We found a solution whit this KB: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleBCAS but we have new questions: 1.- Is there a way to know what information the userIDAgent gets from the AD? 2.- Is there any way to limit the type of events it reads (a...

BigPalo by L4 Transporter
  • 2221 Views
  • 1 replies
  • 0 Likes
  • 24363 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels