General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4109 Views
  • 0 replies
  • 0 Likes

Netflow is not working

Dear Team, Netflow hasn't been working. When we enable and disable Netflow on an interface our SolarWinds server receives a tiny bit of Netflow traffic but then stops again. Netflow traffic is however leaving the firewall and destines for the SolarWinds server. We have not found any drops in the PCAP. We found some error in the global counters, ...

VishnuPS by L3 Networker
  • 3236 Views
  • 2 replies
  • 0 Likes

PANOS firewall Upgrade from panaroma Error

I have paloalot firewall that is managed via panaroma. The firewall doesn't have internet connectivity and only panorama does. On the panaroma I have downloaded both the 9.1.0 base and 9.1.9 maintenance version. When trying to install 9.1.9 from panaroma I get the below error. Image uploaded. Installation initiated. Loading into software manager...

Djanju_0-1626189845109.png
Djanju by L0 Member
  • 4153 Views
  • 5 replies
  • 0 Likes

EDL for Specific Azure IPs/Tags Using Minemeld

I'm looking for a way to use the JSON file from Microsoft which lists Azure IPs and services tags (https://www.microsoft.com/en-us/download/confirmation.aspx?id=56519) to create an EDL. However, I only want to include the IPs for Storage.EastUS2 in the resulting EDL. I've seen reference to a prototype called azure.public-cloudIPsWithServiceTags ...

invalid syntax delete rulebase security rules (rulename)

Hello There, I am running PA-OS 8.1.19. i attempt to delete a security policy via CLI, However, I get an error of Invalid Syntax. Does anyone know what did i miss.i looked at several docs and all indicate i am using a correct CLI command Login to the PAN via console (serial) PAN>configurePAN#delete rulebase security rules LANInvalid Syntax.[e...

KurdTech by L1 Bithead
  • 5492 Views
  • 6 replies
  • 0 Likes

Static Redistribution to BGP

Hi All, I need some help/advice as I am unable to achieve the wanted results.Scenario: a) I have 2 PA firewalls sitting on separate DC operating independently.b) I would like to add a static route on PA (DC1) and as long as the path monitoring for that IP is up the route should be added to the redistribution to BGP which is controlled using a pr...

kanes39 by L1 Bithead
  • 2605 Views
  • 1 replies
  • 0 Likes

GlobalProtect icon disappears from taskbar in Windows 10?

We're having a problem with GP 4.0.6 and 4.1.1 clients on Windows 10 where the icon dissapears from the task bar. It doesn't happen all the time, but when it does it causes a fair amount of user frustration. With the 4.0.6 client, I could search for global protect and bring up the connect window. With 4.1.1, I have to kill the the GlobalProtect ...

uvdes by L2 Linker
  • 22330 Views
  • 6 replies
  • 0 Likes

Resolved! How to determine if high dataplane is an issue

Our Data plane CPU usage is constantly on or above 90%. We have a PA PA-3020. PANOS 9.1.6 It is usually High only during business hours and after hours it is back to normal.It has not affected the firewall performance and any traffic yet.However we are worried what could be causing it and how can we optimize it.We have followed this KB article...

Resolved! API or cli Request App-id in which App Group?

Is there a way to see which application is in which app group using the API or CLI? I can do a config-output-format set and then show the entire config- but that isn't efficient. Without using the GUI, is there a good way to see what app-ids are in a group if you know the name of the group?

Sec101 by L4 Transporter
  • 5727 Views
  • 5 replies
  • 0 Likes

Management interface routing

I'm working on isolating the management interface onto its own network. The firewall will be the router for this traffic and the network switch it connects to will be L2 only. If my management IP is 10.10.20.10/24 and the gateway is 10.10.20.1 where do I configure the gateway address 10.10.20.1 on the firewall? Is this created as part of the man...

Phase 2 tunnel status

Please excuse me as I am still learning and am relatively inexperienced. I assume the phase 2 status can be red for following reasons (assuming IKE phase 1 is all correct and working) Authentication, Encryption, DH settings being incorrect/mismatched or lifetime expiring. Are there any other reasons it would be red perhaps to do with remote or l...

ipsec tunnel status.jpg

FW in Palo IP changed

Hello -I have an HA pair of palo's that were added to Panorama. The management IP for each of those palo's has changed and are now showing in a disconnected state. How can I correct this? Thanks in advance.

require admin users being member of LDAP groups

HelloWe are using LDAP for authentication of the admin users (for Panorama as well as the firewall nodes).Is it possible to adjust this, enforcing the user being a member of a specific AD group?Last info found was regarding PAN-OS 8.1 (https://live.paloaltonetworks.com/t5/general-topics/add-ldap-group-as-administrator/td-p/260754). Here the outc...

Setup VPN Global Protect DynDNS

Setup VPN Global Protect DynDNS Dear community:Good afternoon, is it feasible to be able to configure VPN access with Global Protect, on a Palo Alto with the following scenario:Palo Alto with:-Public IP Dynamically ( DHCP )-Firewall configured with the DynDNS service.-FQDN provided by DynDNS ( vpnaccessgprotect.dynalias.net ) Please confirm if t...

Metgatz by L4 Transporter
  • 4684 Views
  • 4 replies
  • 0 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels