General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4112 Views
  • 0 replies
  • 0 Likes

PCI Compliance - 86476 Web Server Stopped Responding

First time in years, getting this failed result to a PCI scan. 86476 Web Server Stopped Responding. Their tech suggests it has something to do with my PAN WAF/IDS and they have a bunch of IP addresses/ranges that I can whitelist. I find this odd as I've never had to whitelist them before and I've passed many many scans prior to this. How do ...

cenders by L3 Networker
  • 1434 Views
  • 3 replies
  • 0 Likes

Resolved! block the tiktok application

Dears, I want to block tiktok traffic in my environment. i observe in the traffic logs the firewall is not detecting the tiktok application traffic even i applied SSL forward decryption also the firewall is detecting application as a SSL and web browsing.For this I block the tiktok application but still users are able to access tiktok. Is there ...

upload and download speed issue

Hi, We are using PA820i have a isp connection of 700mps up/down.and i have an internal server that can access from public and the domain is pointed to the public ip.the internal server is in my dmz zone and isp is in untust only untrust interface is configured with Qos.and dmz interface has no Qos configured.when i check the speedtest i see it s...

I cannot delete a virtual wire interface

Hello, I've already looked at similar topics here, but it did not help me. I'm supposed to set up a DHCP server on ethernet1/2 and to do it, I need to set up ethernet1/2 as a layer3 interface on the CLI first. Initially, I tried these commands: Set network interface ethernet ethernet1/2 layer3 ip 10.xxx.yyy.zzz set network virtual-router...

Moving interface configuration and sub interfaces to another interface on same firewall

Hi, I want to move all interface from a 1gb port (1/2) to a 10gb port (1/8) what is the quickest way to do this. Is there a bulk move or clone interface option within the GUI? Model PA-5220 Software Version 10.1.14-h10 Not using Panorama. Have just tested but unable to configure the new 10gb interface as it uses the same IP details as the 1gb....

Resolved! proxy-id information through CLI -IPSEC Tunnels

To all, I have multiple tunnels on PA 850. It was difficult to see through which tunnel specific traffic was sent. I tried "show vpn ipsec-sa" it gave me only Peer IP addresses but not proxy-IDs ( interesting traffic permitted through tunnel). is there any CLI command which can tell not only local peer and remote peer but also permitted encrypti...

DNARNI by L0 Member
  • 15435 Views
  • 6 replies
  • 0 Likes

Problem with dynamic update Failed to download file

Hi, I have a problem with dynamic updates. I see new content version or antivirus, but I cannot download it with message Failed to download file. Ping to updates.paloaltonetworks.com and downloads.paloaltonetworks.com is working.Service route is Use managment interface for all.

Resolved! Traffic hitting policy rule it shouldn't

Hi, PanOS 9.1.0I need to block traffic to certain websites and domains.I created a URL Category object and put just one site inside (example.com).I then created a firewall rule like this: Source zone: LANSource address: anyDest Zone: WANDest address: anyApplication: anyService/URL Category: my URL Category ObjectAction: ALLOW (I put it on Allow ...

TACACS authentication with Cisco ISE not working

Hello, I would like to ask currently I have two firewall that needs to be configure TACACS. One of the firewall is working fine and I'm able to login using my credentials from ISE. However, another firewall is not working for the TACACS authentication. I have followed the same steps based on the working firewall. Below here is the error I got ...

fhassan by L1 Bithead
  • 1717 Views
  • 1 replies
  • 0 Likes

HA Failover Issue on PA-3420 with AE LACP – Both Nodes Active (Split Brain ?)

We’re experiencing a critical issue with our HA setup on a pair of Palo Alto PA‑3420 firewalls running PAN‑OS 11.1.6‑h3 in Active‑Passive mode (HA Group 25, preemptive disabled). Both firewalls simultaneously believed they were active, causing a complete traffic halt and requiring a manual reboot of the actual active node to restore service. We ...

romen54 by L0 Member
  • 1850 Views
  • 2 replies
  • 0 Likes

URL access issue

we have one legal category url where it’s not working checked on palo and found no return traffic .So palo support told need to check with upstream as we didn’t find issue on our azure too as we use azure public IP.As we don’t manage any CDN we don’t have visibility.l weather they are blocking our azure public IP or not any suggestions?

Failed to send CHAP authentication request:

admin@PA-(active)> test authentication authentication-profile ISE-TACACS username XXXX passwordEnter password : Target vsys is not specified, user "XXXX" is assumed to be configured with a shared auth profile. Do allow list check before sending out authentication request...name "XXXX" is in group "all" Authentication to TACACS+ server at '172...

pacavi by L1 Bithead
  • 19175 Views
  • 4 replies
  • 0 Likes

Firewall suddenly stopped reading EntraID groups from CIE

We have been using CIE for about half a year now for a spesific usecase where we use som groups that are maintained in Entra ID to control network access, monday we were made aware that that access did not update for new users. CIE does have the correct group mapping, but the firewalls does not sync with CIE. Debugging the issue we have foun...

StianKantebakke_0-1747212225376.png
StianKantebakke_1-1747212443937.png
StianKantebakke_2-1747212811193.png

Stop Connect "On-Demand" after "Pre-Logon"

Hi ! we use the pre-login feature with client cert logon - this work quite good. after logon we would like to connect on demand with saml login. we made two configs, one for prelogon and one for the user, both with prelogon: At the moment if you login to the client the GP client starts direct with the SAML login - is it possible to stopp this...

2025-05-13 15_00_16-Panorama und 7 weitere Seiten - Geschäftlich – Microsoft_ Edge.png
2025-05-13 15_03_51-Panorama und 7 weitere Seiten - Geschäftlich – Microsoft_ Edge.png
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels