General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 73 Views
  • 0 replies
  • 0 Likes

Join the Fuel User Spark Event on March 19: Dealing with Threats !

 

Join us at the Fuel User Group Spark Event on March 19!

 

Get ready to ignite your cybersecurity knowledge and connect with industry experts at our upcoming Spark event hosted by the Fuel User Group. Whether you're a seasoned professional or just

...

kiwi_0-1709893724672.jpeg
kiwi by Community Team Member
  • 675 Views
  • 5 replies
  • 3 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3323 Views
  • 2 replies
  • 14 Likes

GlobalProtect Data File could not able to download

The GlobalProtect data file, located on the Device tab > Dynamic Updates contains the OPSWAT file. We could not able to download it. 

We have scheduled download but still it is not working and other content update is working fine.

 

Please find below lo

...

bit_byte by L2 Linker
  • 2629 Views
  • 2 replies
  • 0 Likes

Application Aged out

Hey guys can anyone provide  a little insight  I set up action to allow an outbound rule for a group  but I am getting an error of an "aged-out"  and its coming from port 443. Any suggestions would be greatly appreciated 

Which drivers are used in terminal service agent.

Hi,

 

What are the drivers are used in terminal service agent?

 

Following are the debug log and found error for drivers.

 

06/23/20 17:07:37[Info 331]: ------------Service is being started------------
06/23/20 17:07:37[Info 406]: Load debug log level Info

...

Resolved! WAN interface Multiple IP addresses or sub interfaces?

Hi - Looking for best practices advice on WAN interface. Currently the WAN interface has a /26 with multiple IP addresses for incoming web servers translated to different subnets behind the PAN.  Is there a default proxy arp working and is this the b

...

stoff by L0 Member
  • 4794 Views
  • 3 replies
  • 0 Likes

Resolved! policy is clear yet traffic is still DENIED

hi all, we have a policy that clearly states FROM and TO objects and SMB_override (custom app, I presume, created earlier) as the application. The service is configured as Application-default. As per Monitor, it goes straight through to the deny rule

...

igs1917 by L1 Bithead
  • 3841 Views
  • 5 replies
  • 0 Likes

Resolved! PA sending TCP RST for a NAT rule

Hi everybody,


Adding a bidirectionnal NAT rule for an ssl web server and the according security rule, connections from outside are dropped as "Incomplete". Traffic capture show that first SYN packet received is directly rejected by PA with a RST respo

...

Want to Uninstall .bat file Terminal Server Agent.

Hi,

 

While installing the VM the terminal server agent was installed through the .bat file.

Now our requirement has changed, I don't know how to uninstall the terminal server through the .bat file.

While Install the Terminal server agent this error is c

...

NAC VLAN Redirection failing

We are trying to implement a NAC solution. The basics are that the NAC is connected to the switch stack and upon sensing a device connecting, it checks it for authentication against the NAC and if it fail it quarantines it into a specific VLAN. That

...

Nonaxium by L1 Bithead
  • 3467 Views
  • 6 replies
  • 0 Likes

Certificate chain not correctly formed

Hello,

 

I am getting the warning below after importing a certificate. Is there a link/KB I can check to fix this?

 

Warning: certificate chain not correctly formed in certificate dc1pa.abcd.com.au

 

Thanks in advance!

Farzana by L4 Transporter
  • 8240 Views
  • 5 replies
  • 1 Likes

IKE Certificate Authentication Peer ID

Hi,

 

Im trying to setup a VPN connection using certificate based authentication. When Phase 1 tries to establish I'm getting the following error

 

Peer's ID payload ' IPv4_address:xxx.xxx.xxx.xxx' does not match certificate ID, Error: failed to get subj...

Are EDLs updating from passive device?

Dear community,

 

We´ve configured a couple of external dynamic list (IP and URL) on a local minemeld server and the passive device fails to fetch those lists.

 

Error obtained is: "Unable to fetch external dynamic list. Couldn't connect to server. Usin

...

Carracido by L3 Networker
  • 2079 Views
  • 2 replies
  • 0 Likes

HA1 and HA2 Links

Hi Guys,

I have configured each of my HA links to have backup links. I would like to know, are the backup links also sending and receiving traffic like port-channel in which both ports are active? Especially the HA2 if we want to have 20G or more link

...

Nikko by L1 Bithead
  • 2045 Views
  • 3 replies
  • 0 Likes

Resolved! GlobalProtect Split-Tunnel via cli.

I am trying to add the MS IP's via cli for split-tunnelling.

 

the documentation states the following...

set network tunnel global-protect-site-to-site <name> client split-tunneling access-route [ <access-route1>

 

but this is not working on 8.1.9

 

I can g

...

Mick_Ball by L7 Applicator
  • 4697 Views
  • 3 replies
  • 0 Likes
  • 24124 Posts
  • 100 Subscriptions
Top Solution Authors
Labels