General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.


Ensuring a Safe and Secure Community: How You Can Help


Dear LIVEcommunity Members,


Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun


jforsythe by Community Team Member
  • 0 replies

SSH to Management interface (RADIUS Auth) PAN OS 10.0.4

Working on an HA Pair of PA-820 firewalls and just finished configuring auth for management interfaces. Went to test, and found that the firewall said auth succeeds, but the SSH connection immediately drops.



  • Auth profile is RADIUS (Windows NPS

D_Baerry by L1 Bithead
  • 2 replies

Enabling multi vsys on a prod firewall.

I’m planning to create multi vsys on my palo alto. I just wanted to know if my existing configuration (interfaces, aggregate interfaces and rulebase) will be moved as it is to vsys1 or they need to be mived manually?


I have aggregate interfaces layer


Resolved! Authenticating a PC based application

We have an old vertical application that can connect to a web server via https and that populates the data
in the desktop application (thick client). Mgt Team would like there to be two factor authentication. But if the thick app does not support two


Reconnaissance query

Hi Team,

Is it possible to whitelist on the basis of destination for scanning port. I can see in Reconnaissance configuration we can only whitelist on the basis on source address. But more than 500 sources are available to scan port so its difficult t


PA-220 advertising BGP routes

Hi everyone, hope you're well. I hope somebody can help with this.



I'm looking to introduce a local Internet breakout, by installing a Palo Alto 220 firewall, as the site has been reporting slow Internet recently.

BChana by L0 Member
  • 1 replies

Template setting not working

WildFire looks like this on the Palo:


But if I click on it to change it, it has a template setting:


I took a look at the Stack and the one at the top has the correct setting, the one at the bottom is set to none. So that should be right, any idea why



Resolved! Pruning weak key exchange algo in Pan OS 8.19

In Palo Alto v8.19, they added functionality to prune multiple weak key exchange algo in one line: (


I followed the guid


Resolved! Unauthorized Request Panorama.

Hey All; I had a weird error this morning with Panorama, "Unauthorized Request" Login and Logout and it still does it. This was when editing the LDAP settings on version 5.0.2 on the hardware version.

Anyone have the same thing?

amansour by L4 Transporter
  • 3 replies

Custom Category traffic flow issue

Hello all,


 I have created a custom URL category for a site and have a security policy to allow specific applications to that category but the results are inconsistent and when I review the log, when the traffic was successful the URL Category shows


EmptySet by L1 Bithead
  • 8 replies
  • 23700 Posts
  • 110 Subscriptions
Top Solution Authors