General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

PA-VM LAB licensing

We would like to have the possibility to run 3 PA-VMs in a lab environment for training, testing and education purposes. We reached out to our reseller and they told us, that we have these options: 1. "normal credits" (~7000 €) 2. PAN-SOFTWARE-NGFW-LAB with minimum of 500 Credits that we have to purchase (~12.000 €) We would only need about 45 c...

janhoppe by L0 Member
  • 3047 Views
  • 1 replies
  • 0 Likes

Does static route path monitoring work with multiple virtual routers ?

Hello, I need to implement a static route monitoring where route A with metric 5 is only applied if google is reachable, route B with metric 10 is backup link through WAN, and both routes are on VR default. I have another VR, Apps VR, where I need to make sure the default route (0.0.0.0) in this VR also has a static route monitoring where if Int...

bambox by L1 Bithead
  • 4622 Views
  • 3 replies
  • 0 Likes

Resolved! Configure Split tunneling by domain

Hi, I just configured split tunneling by domain using this domain test: *.portal.microsoft.com (port 443) But i can not see this traffic going into the tunnel. how can i tshooting this? thanks

BigPalo by L4 Transporter
  • 2475 Views
  • 4 replies
  • 0 Likes

how to disable the url-cloud-connect

the customer firewall pa3220,version :10.2.1, the mgt interface could not access internet,so that firewall could not upgrade the url database.but the system log dispaly some high log:url-cloud-connect-failure,the customer want don't see these log.first solution:delete the PAN_DB_URL_Filtering keyAre there any good other solutions?

Felixcao by L3 Networker
  • 6122 Views
  • 4 replies
  • 0 Likes

Customize Authentication Complete URL

Hi, i would like to customize the URL Authentication complete in GP. i was checking this KB: https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-user-authentication/set-up-external-authentication/set-up-saml-authentication/customizing-the-saml-cas-acs-landing-page The problem is that we dont have the option: ...

BigPalo by L4 Transporter
  • 2530 Views
  • 6 replies
  • 0 Likes

Queries regarding .crx3 chrome extension

We are currently experiencing a significant increase in bandwidth consumption on our network due to users downloading .crx3 files, which are Chrome extension packages. Our Palo Alto Firewall does not natively recognize or allow us to block the .crx3 file type using the File Blocking profile, as this file extension is not currently supported in t...

Connection Failed unreachable macbook

Unable to connect in mac mini 06/29/2025 12:07:37:787 [Info ]: Started the Portal pre-login06/29/2025 12:07:37:787 [Info ]: CPanMSService::PreloginPortal CheckServerCert return 0x2000 06/29/2025 12:07:38:055 [Info ]: Portal pre-login result received06/29/2025 12:07:38:057 [Info ]: Portal Login starts06/29/2025 12:07:38:057 [Info ]: Failed to o...

DHCP Lease Issue

Device details: Model - PA 3020 Software version - PAN OS – 8.1.3 Problem Description: Please be informed that we are frequently encounter DHCP lease full (100%), and it cause interruption for our users at region side. Customer side have two vlan for DHCP lease which are vlan.960 (IP pool of XX.XX.XXX.X to XX.XX.XXX.XXX) and vlan.959(XX....

GlobalProtect - Multiple Client Settings

Following a change to move from LDAP (Local Domain Controllers) to Azure SAML with MFA enabled we are experiencing an issue with the use of multiple Client Settings Configs on a single Gateway. We use the users section to identify a subset of users that only require RFC1918 IP ranges to traverse the VPN and all remaining users will hit the sec...

PT1559 by L0 Member
  • 2032 Views
  • 3 replies
  • 0 Likes

UnAuthorized Access

Dear, Anyone can help me to solve my account. " Your account has expired. To get this resolved, you must reach out with your Super User for assistance.You can click here to send your Super User a reminder notification." i have clicked to send a reminder notification but nothing happen Thanks you so much for your help

Congdoan by L0 Member
  • 886 Views
  • 1 replies
  • 0 Likes
  • 24427 Posts
  • 125 Subscriptions
Top Solution Authors
Labels