General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4222 Views
  • 0 replies
  • 0 Likes

FW lose UIA mapping

Hi, We are having a issue in the FW. Suddenly the FW loses the UIA mappings. We upgrade the FW to 8.1.19 in order to avoid any previous bug but the issue repeated. Its quite random. Upgrade was done last 8th June and it happenened today, In order to solve we need to restart userid process. why this is happening? why

Captura1111.JPG
BigPalo by L4 Transporter
  • 3262 Views
  • 4 replies
  • 0 Likes

Resolved! Bytes received zero for allowed udp ports

Hi, In traffic allowed logs, I am seeing numbers in byte sent however byte received is zero and connections are getting aged-out for UDP voice traffic. Can anyone know about such traffic whether it is dropping or since this is UDP connection hence byte received is zero This traffic is allowing via security policy configured for outside to ...

Prevent WildFire scanning certain URLs

Our external email protection provider (Mimecast) provides safe versions of file attachments on incoming emails. There is also a one time link in the email to request that the original file is sent in case of any formatting issues. When the incoming mails are scanned by WildFire it sometimes follows the link in the email which triggers the relea...

Andy123B by L0 Member
  • 3061 Views
  • 3 replies
  • 0 Likes

Resolved! Unable to access Windows Store (Windows 10 + GP 3.0.2)

Hello, Does anyone else also have problems to access the windows store when connected with global protect vpn?Actually the problem really only is the windows store app. Everything else works perfectly (internet access, accessing corporate ressources, internal websites, fileshares, ...). The store app only displays that I should check my internet...

Remo by L7 Applicator
  • 48219 Views
  • 55 replies
  • 0 Likes

GlobalProtect "Connecting...still working" (Mac OS 10.14.6)

After upgrading to the latest version of GlobalProtect, I have been trying to resolve this for days. Here's some additional info:Have tried uninstalling and reinstallingHave tried going back to an earlier version (5.0.1-9)No prompt is showing in security & privacy for allowing the application.Have tried "spctl kext-consent add PXPZ95SK77" in...

dubsar by L1 Bithead
  • 7993 Views
  • 8 replies
  • 0 Likes

No new Apps category appears

Hi, According to the following note https://live.paloaltonetworks.com/t5/customer-resources/release-plan-for-a-new-app-id-category/ta-p/395753 from the version of apps + threats of 18/5 (8408-6715) we should see the new category "Saas" according to the release notes https://downloads.paloaltonetworks.com/content/content-8408-6715.html?__gda__=...

Resolved! Global Protect do not ask for OTP

Hello, i had configured a radius server (freeradius) that work with google_authenticator and active directory. So far this works that way: - login via Global Protect Client with username and AD Password+OTP (password and OTP in 1 promt) I need to enter the OTP seperate and not together with the password. How can i achieve this?? The portal and ...

Resolved! dns issue

Hi, using an internal Dns serverclient makes request for a domain ???.com and cannot get an answer.from nslookup we see that it cannot resolve the domain.internal dns server to public dns server rule has a spyware profile.There is no threat log for this request.But if we disable spyware profile then client can resolve this name.Any idea about th...

Number of address groups XXX exceeds platform capacity XXX

Dear community, We are trying to push for the first time the DG and we get following commit error: Number of address groups XXX exceeds platform capacity XXX We followed the suggestions in link down below of disabling "Share Unused Address and Service Objects with Devices" but still the same issue. https://knowledgebase.paloaltonetworks.com/KCSA...

Carracido by L4 Transporter
  • 5594 Views
  • 1 replies
  • 0 Likes

Resolved! Single Interface Trunk Hairpin problem for All traffic traversing Firewall?

Have a site that we want to firewall traffic off into a few segmented zones. I would like to do all of this with 1 management interface, and a single palo alto trunked interface that would carry multiple vlans. To be clear, in this instance, the firewall would already be on the inside of the network and not an edge device.The firewalled networ...

Sec101 by L4 Transporter
  • 4114 Views
  • 1 replies
  • 0 Likes

Address group convert to shared

Running version 9.0.12Moving to a multiple vsys enviroment from a single vsys, we are not running Panorama. Looking to change all of the address objects in the first vsys to "shared" so the others can access them. Thus far I have not found a way to do it and I am looking for suggestions. Thank you in advance!

Wildfire updates chenge

Hi, We have configured to download the "wildfire updates" every minute. So whats is the recommended value for this? Sometimes we face this error, and we are thinking to increase the time for WF updates:

wildfire.JPG
BigPalo by L4 Transporter
  • 3347 Views
  • 5 replies
  • 0 Likes

Session timer getting reset for new syn packet

Hi,I got the following scenario.client -> Paloalto -> Server:1234The client initiates a tcp session to server always using the same source port and same sequence number (verified in packet capture). The session time out is the default 60 minutes. The client sometimes looses network coverage and initiates a new sync (with same source port a...

livewire by L1 Bithead
  • 5594 Views
  • 6 replies
  • 0 Likes
  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels