General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4111 Views
  • 0 replies
  • 0 Likes

Azure External NAT - Without LoadBalancer

Hello, I have an issue. I have an internal server which needs to be reached from the internet.I have got a public ip but i am unable to assign it interface of the firewall for obvious reasons. Also i only have an option to associate it with a Load Balancer. Is there a way I can get this NAT working without a Load Balancer. (Apologies if this is...

HTNAHSIN by L0 Member
  • 2724 Views
  • 2 replies
  • 0 Likes

Linux User not able to Access an Application

One of My Customer's User Not Able to Open a Stackfive agent application its says its Java base When he Opens That there is an Error According Certificate Invalid or Something. Then the Customer Send him a Certificate I check the logs, and the Security is good I want to know for that application what application do I just need to add I added th...

Resolved! Correct way to upgrade Cortex XDR agent on Terminal Servers

Hi all,In our environment we have installed the Cortex agent on some terminal servers via the command line and with the TS_ENABLED = 1 attribute.Now it's time to update them to the latest version (7.4.0). The terminal policy provides for automatic updating however they haven't done so.We noticed that from the web console you can manually launch ...

Resolved! Getting issue while printing from Wifi Network series (172.27.13.0) To Lan (172.27.11.0)

Getting issue while printing from Wifi Network series 172.27.13.0 To Lan 172.27.11.0I Checked the Monitor Traffic from ETH1/5 (172.27.13.0 ) to ETH 1/3 (172.27.11.0) Port 9100 as for Printer the 9100 is commonly Use the traffic shows allow and the byte is also Received by that end in CLI I Can also Ping but still its not printed properly So the...

FW lose UIA mapping

Hi, We are having a issue in the FW. Suddenly the FW loses the UIA mappings. We upgrade the FW to 8.1.19 in order to avoid any previous bug but the issue repeated. Its quite random. Upgrade was done last 8th June and it happenened today, In order to solve we need to restart userid process. why this is happening? why

Captura1111.JPG
BigPalo by L4 Transporter
  • 3221 Views
  • 4 replies
  • 0 Likes

Resolved! Bytes received zero for allowed udp ports

Hi, In traffic allowed logs, I am seeing numbers in byte sent however byte received is zero and connections are getting aged-out for UDP voice traffic. Can anyone know about such traffic whether it is dropping or since this is UDP connection hence byte received is zero This traffic is allowing via security policy configured for outside to ...

Prevent WildFire scanning certain URLs

Our external email protection provider (Mimecast) provides safe versions of file attachments on incoming emails. There is also a one time link in the email to request that the original file is sent in case of any formatting issues. When the incoming mails are scanned by WildFire it sometimes follows the link in the email which triggers the relea...

Andy123B by L0 Member
  • 3029 Views
  • 3 replies
  • 0 Likes

Resolved! Unable to access Windows Store (Windows 10 + GP 3.0.2)

Hello, Does anyone else also have problems to access the windows store when connected with global protect vpn?Actually the problem really only is the windows store app. Everything else works perfectly (internet access, accessing corporate ressources, internal websites, fileshares, ...). The store app only displays that I should check my internet...

Remo by L7 Applicator
  • 47557 Views
  • 55 replies
  • 0 Likes

GlobalProtect "Connecting...still working" (Mac OS 10.14.6)

After upgrading to the latest version of GlobalProtect, I have been trying to resolve this for days. Here's some additional info:Have tried uninstalling and reinstallingHave tried going back to an earlier version (5.0.1-9)No prompt is showing in security & privacy for allowing the application.Have tried "spctl kext-consent add PXPZ95SK77" in...

dubsar by L1 Bithead
  • 7884 Views
  • 8 replies
  • 0 Likes

No new Apps category appears

Hi, According to the following note https://live.paloaltonetworks.com/t5/customer-resources/release-plan-for-a-new-app-id-category/ta-p/395753 from the version of apps + threats of 18/5 (8408-6715) we should see the new category "Saas" according to the release notes https://downloads.paloaltonetworks.com/content/content-8408-6715.html?__gda__=...

Resolved! Global Protect do not ask for OTP

Hello, i had configured a radius server (freeradius) that work with google_authenticator and active directory. So far this works that way: - login via Global Protect Client with username and AD Password+OTP (password and OTP in 1 promt) I need to enter the OTP seperate and not together with the password. How can i achieve this?? The portal and ...

Resolved! dns issue

Hi, using an internal Dns serverclient makes request for a domain ???.com and cannot get an answer.from nslookup we see that it cannot resolve the domain.internal dns server to public dns server rule has a spyware profile.There is no threat log for this request.But if we disable spyware profile then client can resolve this name.Any idea about th...

Number of address groups XXX exceeds platform capacity XXX

Dear community, We are trying to push for the first time the DG and we get following commit error: Number of address groups XXX exceeds platform capacity XXX We followed the suggestions in link down below of disabling "Share Unused Address and Service Objects with Devices" but still the same issue. https://knowledgebase.paloaltonetworks.com/KCSA...

Carracido by L4 Transporter
  • 5568 Views
  • 1 replies
  • 0 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels