General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4105 Views
  • 0 replies
  • 0 Likes

PA-500 fan too noisy

Hi, I think one of our PA-500's fan is always running at 100% speed,Because it's too noisy than others, Following is output of environmental, it says RPM is just 1, Does anyone know solution for this problem?\ Thanks,

pa-500 output.png

Resolved! Apps & Threats version 8434-6840 fails to install

Hi I've had 2 separate NGFW's fail to install Apps & Threats DB version 8434-6840 with this message:Error: Application group 'Wifi_Allowed_Apps' member 'visual-studio-live-share-direct' does not existError: This content install has failed because app 'visual-studio-live-share-direct' has been removed in content version 8434-6840. To success...

ShaiW by L1 Bithead
  • 4975 Views
  • 5 replies
  • 0 Likes

Resolved! Getting GPG error updating

We installed minemeld a year or two ago and have been running apt-get monthly with no issue. Today running apt-get had CRC errors shown below. I looked through this forum but didn't find anything that looked related. Any help would be appreciated. Thanks

CharlesSFG_0-1627405622967.png

TCP Reset being dropped at firewall

I have a client accessing a Citrix CAG via a firewall at one site on HTTP that I see traversing the FW, exist out towards the internal PA firewall reaches its destination. The destination server is sending a TCP RST, we are told to redirect the browser to HTTPS, that TCP reset is sent all the way back to the firewall nearest the client, receive...

Resolved! Multicast issue

AE1.1 is the static RP(10.1.1.1/24) and ae1.1 has 10.1.1.1/24 assigned to it. All the 10.0.0.0/8 routes are served by this sub interface and RP configured on switch is 10.1.1.1AE1.2 hosts the mcast server and AE1.2 has gateway of 172.16.0.1/24.Multicast clients in 10.5.0.0/24 are able to join MCAST streamed on 172.16.0.20 AE1.3 connects to a sep...

multicast.png
raji_toor by L4 Transporter
  • 3496 Views
  • 1 replies
  • 0 Likes

Resolved! Static Bi-Directional NAT translation

Hi, Is it possible to have 2 static bi-directional NAT rules configured for the same public IP address e.g. mapping one public IP address to 2 internal servers using the below linked config? https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat/configure-nat/enable-bi-directional-address-translation-for-your-public-facing-serv...

Ben-Price by L4 Transporter
  • 3438 Views
  • 2 replies
  • 0 Likes

Internal host detection not Working

I have an external Gateway and I wish to setup always-on except when on local LAN. As a test i am doing this on my own username but it seems to always want to connect to external GW regardless of my settings. I have turned on Internal Host detection and this is returning "0" in the PanGPS logs so i would assume then it would realise i was intern...

welly_59 by L3 Networker
  • 12049 Views
  • 11 replies
  • 0 Likes

LDAP authentication does not work for Global Protect Clients

Hello, We have got a working LDAP server profile. We have made sure user 'test' is listed on the group mapping. Steps: a) Setup group-mapping under Device->User Identification->Group Mapping Settings. Under 'Group Include List' pick a specific cn.b) Device->Authentication Profile. Add a new profile and add the same cn under allowed list...

Farzana by L4 Transporter
  • 11261 Views
  • 9 replies
  • 0 Likes

User-Mapping Server Monitoring

Hi All, Wanted to know the Best Practice for the User-Mapping with Server Monitoring, we have a few Firewall Sites which utilize the server monitoring feature whereas the vast majority others do not and use only windows User-ID agents for probing and mapping. Need to know if enabling server monitoring is the best practice to gather all the IP-us...

Dear Palo Alto Networks:

Your firewalls are generally okay.But, the fact that you cannot get an interface bandwidth graph without configuring some QoS hack to only show an ingress interface traffic graph is stupid.Every firewall vendor in the world has this feature. Except you.Please fix this idiocy.

Path monitored static route not removed from BGP RIB out table when path monitor dest. IP unreachable.

Hi, I have an issue where a Static route that is being path monitored and redistributed into BGP, is not removed from the BGP RIB out table when the monitored path is unreachable. The static route is still populated in the Palo Alto BGP rib out table and is also populated in the BGP peer route table. Any ideas as to what may cause such an issue?

Ben-Price by L4 Transporter
  • 5308 Views
  • 5 replies
  • 0 Likes

getting traffic after the interface is down

Hey guys hope you doing well I got a question I get a challenge one of my user getting traffic logs of NetBIOS by source Pvt IP from LAN to WAN the device from the source side is down the 2 Pvt IP still hitting the cleanup rule. The Policy is denied by the firewall but why do the traffic logs show the two source IP which is down from that side. ...

Resolved! global protect remote vpn unable to reach internal network?

im having big problem , after my remote vpn connects i cannot reach my internal network even though my core switch is directly connected to palo alto , i checked i set the access range for the vpn for 0.0.0.0/0 and i set a security rule from vpn zone to inside zone , also i can ping the inside interface on the firewall itself but not the directl...

chuckles by L2 Linker
  • 24802 Views
  • 5 replies
  • 0 Likes

Disable new apps in content update

Hi Experts, We've a pair of firewalls (9.1.6) managed by the Panorama (9.1.6). We've Threat prevention license in place and client would like to install just the threats and not the apps by selecting disable the new apps in content update.As recommended by the TAC, we've downloaded the latest version and when installing the new version, we selec...

TAC support has gone missing, again :-(

Opened a S2 TAC case @7pm ET 07/21/2021. The SLA response time is 2 hours. TAC didn't get back to me until 5:43am ET 07/22/2021. The response from TAC is very vanilla, not helpful at all. Call back to TAC this morning has been waiting for an hour and had to give up. Awful....

dtran by L4 Transporter
  • 3790 Views
  • 4 replies
  • 0 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels