General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1910 Views
  • 0 replies
  • 0 Likes

Resolved! IPSec VPN routing across multiple tunnels

Hi folks/.

 

I have a situaiton that is doing my head in, and I need some help.

 

I have an installation which looks like this

 

"A" end - Palo Alto Active/Passive cluster, public IP for IPSec VPN termination

 

"B" End - Juniper SRX cluster, Active/Active wi

...

darren_g by L4 Transporter
  • 15393 Views
  • 8 replies
  • 0 Likes

MAC addresses for HA interfaces

I have 2 virtual instances of PA-8.0 on a laptop in a home lab for learning purposes.  High Availability is configured in Active/Passive mode with HA1 using the management interface and it is working but HA2 is failing to sync and complete initializa

...

Resolved! VA scan issue

Is there anyway to solve those VA issue?

 

1) 90317 - SSH Weak Algorithms Supported
2) 42873 - SSL Medium Strength Cipher Suites Supported (SWEET32)
3) 70658 - SSH Server CBC Mode Ciphers Enabled
4) 71049 - SSH Weak MAC Algorithms Enabled

 

Kindly help plea

...

Vector by L0 Member
  • 2789 Views
  • 2 replies
  • 0 Likes

Global protect certificate expiry

Hi team,

Can we renew the server certificate used for gp before expiry can you please let me know if there would be any impact after renewing the certificate before expiry??

 

Or we need to renew the certificate before 1 day ???

 

 

Resolved! CLI commands to add a device in devicegroup as master device

Hi Team,

 

I found some command to add a device in device group and template but couldn't find how to set a device as master device in device group with CLI,

Tried to search cheat sheet but the information/commands are not available.

Is it possible or th

...

Srikant by L1 Bithead
  • 5350 Views
  • 1 replies
  • 0 Likes

Dual ISP, PBF traffic not returning

I have two ISPs configured with path monitoring and I can successfully monitor the primary route and fail over to the secondary, however what I would like to do now is use PBF to always send some of my traffic out the secondary ISP.  Everything I've

...

NAT.jpg
PBF.jpg
Traffic.jpg
Cooper80 by L0 Member
  • 3333 Views
  • 2 replies
  • 1 Likes

unable to block google chrome updates

I blocked 'google-update' app in firewall rules but I still see some of the users' browsers getting updated. I can't find any helpful logs for those users. 

 

Please let me know a solid way I can blocked google updates on Palos.

 

TIA.

Resolved! HA down PA-220

I've a pair of PA-220 configured as cluster. After power off - on HA is down. But I can connect to both firewalls via https & ssh.
Active fw1 shows that HA ports 7 & 8 are down (red in GUI). On passive firewall fw2 all ports are grey.
But the real stra

...

ChrisCon by L2 Linker
  • 5112 Views
  • 3 replies
  • 0 Likes

Certificate renewal impact before expiry

In Palo Alto some certificate are expire in this months. Request you to help us to know will there be any impact at user end if certificate expires and we renew on firewall before expiry.

SurajN by L2 Linker
  • 3381 Views
  • 2 replies
  • 0 Likes

Resolved! tunnel monitor works improperly

hello

 

I am trying to enable the tunnel monitoring for an IPSec tunnel(not sure what device the other end is using) and got very interesting result.

The proxy id config is

local:172.16.17.3/32

remote: 146.48.211.0/24

 

My client subnet 172.16.2.0/24 will b

...

DongQu by L2 Linker
  • 3818 Views
  • 1 replies
  • 0 Likes

Automation of GlobalProtect installation

Hi all,

 

I am trying to automate the deployment of GlobalProtect software in laptops with Ubuntu installed and I have faced an issue not easy to explain. The operating system is being deployed automatically in chroot mode, and one of the last steps in

...

What does it means Stage e Events GlobalProtec Fields?

Dear, we are doing a large and hard troubleshooting to forensic analysis into our company, so we need know more information about the "GlobalProtect Stages and Events columns Logs Monitor".

Example: what it means the stages: before-login, tunnel, host

...

rennersf by L0 Member
  • 2094 Views
  • 1 replies
  • 0 Likes
  • 24258 Posts
  • 117 Subscriptions
Top Liked Authors
Labels