General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.


Resolved! NAT, Routing and license requirements

Hello Bros,

                I have an unlicensed and out of support single paloalto 3220 appliance, and this device is not licensed now as we have upgraded to paloalto ha.

my question is I wanted to re-use this appliance for some network services such


Resolved! Authentication issue with Global Protect

We are having difficulty with our Active/Passive pair of PA_820’s where they are setup to allow auth to GlobalProtect based on AD group membership.

If we create a new OU in AD and move a user to the newly created AD OU whilst still having the same gro


Group Mapping.jpg
Auth Profile.png

Resolved! Welcome Page - Iframe


we want to include a (external or internal) website via iframe in the welcome page. My test HTML site:

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Frameset//EN"


Hithead by L4 Transporter
  • 13 replies

Resolved! Change speed/duplex on 10G SFP port for PA-5220



Is it possible to hardcode speed/duplex for 10G SFP port on PA-5220 device? i am getting below error:


>set network interface ethernet ethernet1/5 link-speed 10000 link-duplex full 
Server error : ethernet1/5 -> link-duplex 'full' is not


skanani by L2 Linker
  • 4 replies

Policy not matching actual traffic

Hi All,


I have a security rule to allow ip "A" to ssh to ip "B". I can see the traffic actually hitting the fw but it gets dropped with interzone-default. The test policy match also verifies that it matches the traffic.


IP "B" is actually the firewal


olloczky by L1 Bithead
  • 3 replies

Why tcp aged-out?

Hi all,

Our developers are connecting from Zone1 to Zone2 with tcp (on ports between 2000 and 3000)

The tcp session timeout on firewall is 3 hours.

The security policy allows any application, any port from Zone1 to Zone2. But there are all default secur


Global protect Notification



When I connect global protect Gateway. Once is connected I received this notification.

I have check the internet connectivity it's working fine.


Can you please let me know how to avoid this notification 




Need help with logging in case of App-Id



I have below rule in my Palo Alto and another default rules which are Intra-zone and Inter-zone.


Source Zone: Trust

Destination: Any

Destination Zone: Untrust

Application: ssl, web-browsing, dns, Facebook-base, YouTube-base, etc



GlobalProtect and RDP

Hi All,


I have made a change to our GlobalProtect app config to cater for RDP connections by amending the "User Switch Tunnel Rename Timeout" value to 60 seconds. 


I was hoping to be able to confirm this setting had been applied to the GP clients via



Resolved! Is it possible to write a rule matching any IP ending in .xx

Hi all,

I have a question, is it possible to write a rule that matches only a part of the IP address? For example match any IP ending in .51? Using wildcards this would be  *.*.*.51

Put another way, i would like to match all IP's that are x.x.x.51 wher


Saqib by Not applicable
  • 8 replies
  • 24012 Posts
  • 102 Subscriptions
Top Liked Authors