General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4105 Views
  • 0 replies
  • 0 Likes

Resolved! Error: Failed to get policy objects: NO_MATCHES(Module: useridd)

Hi all, Just another day with PA3050s and came accross an odd error when trying to commit my changes as usual.I tried to resolve it doing > debug software restart process management-server but it did not help. I am scratching my head to understand what is going wrong? Has anyone had a similar experience? I persistently getting this error : Er...

Resolved! MGMT interface ip address

Hello, is that possible to use for the MGMT interface IP address from a VLAN that configured in one of the data plane interfaces? For example:Eth1/1.100: IP 192.168.1.1/24 Mgmt interface IP: 192.168.1.254/24DG: 192.168.1.1 Thanks,

hasansh by L0 Member
  • 3048 Views
  • 1 replies
  • 0 Likes

DynDNS Certificate

Good afternoon, I am trying to configure DynDNS on the Palo Alto machine.In the steps it talks about using a certification profile, and in the Palo Alto instructions, it talks about importing the SSL certificate from the DDNS provider. My question is how and from where do I get the certificate, I consulted with the provider and they do not under...

Metgatz by L4 Transporter
  • 4971 Views
  • 1 replies
  • 0 Likes

Redundancy VPN between two sites with two ISP

HELLO ALLWe have two PA devices.(850 and 500).They are located in different sites.Both firewalls have two connections to Internet via 2 different ISPsWe want to make Site to Site VPN between these sites.But make it redundant.Two VPN connections between sites through different ISPsI can not find any manual how one can configure this schemaPlease ...

Radmin_85 by L4 Transporter
  • 8093 Views
  • 5 replies
  • 0 Likes

Instagram allowed in the security policy, but the pictures are not displayed correctly on the website

Dear Palo Alto Community Members, I'm tiring to set up a security policy based on app-ID allowing Instagram but blocking Facebook.Unfortunately, I can't get it to work, and I'm not sure what I might be missing here. The security policy allows all the needed applications, and I've double-checked and added all the required application dependencies...

Policy.PNG
issue.jpg

Resolved! Auto Logged out of firewall

Hi, I am automatically logged out of firewall but when I try to login again getting the error attached below, Any Idea about this? how to resolve this?

SubaMuthuram_2-1625670570581.png

Re:Software License

Hi, Can anyone enlighten me what is the use of the Software license in Palo Alto NGFW and what will be the impact on the firewall, If that license expires.

Resolved! DNS license expired.

Hi I have PA820 with image 10.0.Will I still able use URL feature after DNS license expried?Is true that once the license expired the PA820 next generation no longer function and it looks like it only work as standard firewall? Thanks

how to adjust interface metric in ospf to define desired route ?

I have to two virtual routers VR_1 - e1/1 - is connected to wan 1, e1/3 - is connected to internal network, e1/4 is connected to a switch so, VR_1 has e1/1,1/3,1/4 and I want the primary ospf route to be from e1/4. what changes should I make to do set all routes pass through e1/4.VR_2 - e1/2 - is connected to wan 2. currently all interfaces are ...

Screen Shot 2020-01-22 at 12.39.13 AM.png
venkat_g by L0 Member
  • 8769 Views
  • 2 replies
  • 0 Likes

Globalprotect: Adding multiple portal via registry

Hi guys, May I ask for your guidance. I can add multiple portals easily in my globalprotect agent using its's GUI in windows 7/10. However, I need to deploy multiple portals via registry so I can push it in GPO. I have tried this link but this only show 1 portals.https://docs.paloaltonetworks.com/globalprotect/9-0/globalprotect-admin/globalprote...

RemusDV by L1 Bithead
  • 6710 Views
  • 3 replies
  • 0 Likes

linux GP agent deployment

Hi I see from panorama / deployment / Global protect client section that there is linux agent files.What is the purpose of that ? When I try to download and activate no device is coming at selection window.Any idea ? Thanks Panorama version 9.1 Regards

Resolved! Firewall requests to suspect dns domain names

Starting this morning (6:20AM CST), we are seeing threat notifications of suspicious dns requsts going to a group of domains that have been named in the Solarwinds Sunburst hack. avsvmcloud[.]comwebsitetheme[.]comzupertech[.]cometc We've been trying to backtrack these all day. Our internal dns servers tell us that the requests are coming from t...

Resolved! VPN client certificates rejected until firewall reboot

I had to reboot my firewall this morning because it erroneously rejected client certificates required by a VPN.Firewall system logs show critical event "Out of memory condition detected, kill process 3" at 4:06am I had the exact same issue on May 5th as well (and reporting to PA) where Clients getting VPN certificate errors despite being nowhere...

Hacking URL, direct thru Palo, deny reason "block URL", via a search thru google, gets a reset page.

When you go directly to "shodan.io", which is categorized as a hacking site, the palo will block that URL. When searching thru google for that site, then click on it, a reset page is sent, need to understand why? Is it considered a "threat" if google makes the request? so the threat settings would be used instead of the URL Filtering Security se...

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels