Kerberos error
Recently we have down the one of our DC server. Since after we are getting Kerberos error. Please share solution to fix this.
Recently we have down the one of our DC server. Since after we are getting Kerberos error. Please share solution to fix this.
Hi, We need to configure SDWAN with only one internet (transport) line. Is that possible in Palo Alto SDWAN or you need two o more lines? Someone who can confirm. thanks
hi guys, I am trying to open a TAC case in PA portal, however it seems there is latest change happen which requires a TSF file upload mandatory. SInce we are a restricted site, we cannot share or upload anything on the portal. Because of this issue, i cannot create a case. The "File Case" button is not activating.
I can't find information about this NGFW-Engineer exam on the official site. And yes, how to prepare for this exam, with which practice tests can I prepare for this exam? I have consulted many certified people and they have mentioned many sources.
Hello, I am attempting to use the XML API for Panorama to capture the output of a report. I am able to successfully pass the custom report name to the API and get some results, but the results are missing the Source User field outlined in the report definition in the Pano. For example, the report definition (and the emailed report, when it ...
Hi Palo Alto Community, I hope everyone’s having a great day! We’re working to enhance our network’s security by blocking torrent and other risky P2P communications. I’ve set up a deny policy using the “bittorrent” and “bittorrent‑sync” App‑IDs, but I noticed these require the “web‑browsing” App‑ID to function. When I include “web‑browsing” in...
I'm having a hard time finding much, if any, documentation on this scenario. I've tried a couple ways of doing it and they work, but I'm trying to figure out what the best way to do it while being as redundant as possible. What I like the best so far is to have the portal and a gateway up on a floating IP so it can bounce from one firewall to t...
We get SSL connect select error: 0(Resource temporarily unavailable), time left: 0P26083-T33415 08/07/2025 00:31:33:272 Debug( 468): SSL connect failedP26083-T33415 08/07/2025 00:31:33:272 Debug( 66): detailed SSL error info:P26083-T33415 08/07/2025 00:31:33:272 Debug( 956): connect() failedP26083-T33415 08/07/2025 00:31:33:272 Debug(3388): Conn...
Migrating a firewall and pushed a cloned and modified template to a new Palo alto. Did not push device group. Now I am unable to ssh, ping, https the device. I am on the device by console. Everything with the management interface looks on and I can ping the management default gateway from the Palo. What could be causing this?
Hello All I have imported a cerfificate into the PA as a PFX. I have also import the intermediate certs and root CA. The cert is signed by Go Daddy with 2 intermediate certs and a Root CA. All imports fine, but when I get up global protect portal and use the imported cert (from the pfx) I get an error which says "Warning certificate chain not co...
When managing a multi-vsys firewall, is the correct way to map each vsys to a unique Device Group? Lets say I have vsys_prod and vsys_dev, I would do: Device Group "prod_device_group" mapped to "vsys_prod" Device Group "dev_device_group" mapped to "vsys_dev" The reason for my confusion. I can see that Panorama allows me to add multiple vsys'...
Hi When I'm running "test authentication authentication-profile "'LDAP Auth Profile" username myldapUser password" on the ssh cli, it authenticates successfully. however when i try to log in on the web interface of global protect, i get this on the webui log: failed authentication for user 'myDomain\myldapUser'. Reason: Invalid username/passwor...
I am having an strange issue PA firewalls reachability to some of the nodes on the network. I have 10 identical devices connected behind this access switch and all 10 devices are accessible from the access and the core switch at any time. However, only 6 of them are reachable from the firewall at any time. The remaining 4 devices only pings whe...
Hello. I'm running a PA-1420 device.The PAN-OS version is 11.0.3-h12. Is it possible to configure the PA to send RST packets to both sides when a TCP session times out due to aged-out?I read in a previous post that this wasn't possible on the PA, but I'm wondering if this is still the case.(https://live.paloaltonetworks.com/t5/general-topics/pa-...
When I sign into Palo Alto, there´s a problem with the "Customer Support Portal (CSP)" section. It appears in error, but when I try to contact them as indicated, nobody attends to me. What should I do?
| Subject | Likes |
|---|---|
| 2 Likes | |
| 2 Likes | |
| 1 Like | |
| 1 Like | |
| 1 Like |

