General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4108 Views
  • 0 replies
  • 0 Likes

DH - VPN

Hi , How can I allow multiple Diffie-Hellman (DH) group in IKE & IPSec profile while creating a VPN

hanuman by L0 Member
  • 3052 Views
  • 4 replies
  • 0 Likes

"export to CSV" - limit

What is the maximum limit on the number of lines to return? can it be increased?want to know what they do during siesta? see for yourself on the spanish porno tube https://pornogratisaqu.com/

ducuxawi by L0 Member
  • 1999 Views
  • 1 replies
  • 0 Likes

Resolved! Can I use CA Root Certificate for Debrypting SSL Traffic?

Hello, I want o start setting using Decryption Policy, to Decrypt & Intercept SSL (443) traffic from users when connecting to Internet. I am wondering, can I use one of the well known Certificate Trusted, e.g., Global Sign by installing it on the Palo Alto without installing the certificate manually on the users' computers?! Thank you ...

mshamsan by L1 Bithead
  • 5605 Views
  • 4 replies
  • 0 Likes

Resolved! Ineffective IP spoofing protection

I have IP spoofing protection enabled on PaloAlto but it is not effective due to the following reason: My external Interface IP is 1.2.3.1/24 . The spoofed attacks are coming from a fictitious source IP for e.g. 1.2.3.25 destined to 1.2.3.50(web server). As per Palo's IP spoofing definition, this is not blocked because 1.2.3.25 is routable over ...

The user Id tab under not able to detect AD Group but Group Incluse List shows the Group

I am unable to find the User group under user column in the Firewall Policy Tab and i see that the User Id agents are connected to the Firewall but when i do the same Search under the Group Inclusion List i see the Group in that Tab. I was wondering what is happening in the User Id tab in the Policy tab as the AD group not showing up

Knowledge sharing: High Data Plane CPU because of DDOS or overutilization (access to Palo Alto Auto Assistant may help)

I have seen for example on a small firewall when the customer enables SSL decryption that the counters for work groups "ecdhe_key_gen", "flow_host " etc. jump. This may show that the firewall can't handle the ssl decryption or that there is an SSL DDOS attack: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmV2CAK ht...

behavior in multi-vsys with shared gateway and DNAT policies

Dear community, We have a firewall with multi-vsys and the following scenario: 1 shared gateway and 1 public IP on external zone 1 virtual system and 1 private IP on internal zone We configured DNAT to allow access to private IP from Internet following this article:https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHxCAK...

Carracido by L4 Transporter
  • 3293 Views
  • 3 replies
  • 0 Likes

Resolved! Traffic Thourhg the intended Security Rule

Hello, I have configured a new Security Rule on top (#9 in the picture down) to Block traffic intended to a Custom URL configured in the profile Block_Files* TOP RULE *Source Zone: anySource Address: anyDestination Zone: anyDestination Address: any * NEXT RULE *Source Zone: Trus...

mshamsan by L1 Bithead
  • 3880 Views
  • 3 replies
  • 0 Likes

HA Active/Passive with Preemption

2 firewalls configured with HA active/passive, And enabled preempt on both of firewallsEverythings find, can synchronize configuration and session firewall-A is active-firewall with priority 100firewall-B is passive-firewall with priority 120HA timer settings is recommended But when I was testing for HA switch over by unplugged a interface on Ac...

Difference between last 24 hour and last calendar date option in reports

Hi All, What is the difference between last 24 hours and last calendar day time frame option that is being used in custom report settings. Also last 24 hours time frame means past 24 hours data will be added to the report the minute report is run. But how does it works for last calendar day. Thanks in advance. Re: Custom Reports contained in Gr...

IKE SA negotiation is started as initiator, non-rekey

Hello :),I have a problem with VPN from PA-220 to Azure. The logs show this information : "IKEv2 IKE SA negotiation is started as initiator, non-rekey. Initiated SA " Every change I made it always is this same error. Is there any way to resolve this issue ? Thanks in advance 🙂

Lukaszm1 by L1 Bithead
  • 52777 Views
  • 9 replies
  • 0 Likes

System Logs

Hi, Do we have any list of critical and high severity system logs? Like what are the examples of hardware failures, serious issues etc...

user-id-agent-sequence is invalid.

Hi Team, I'm seeing configuration invalid when I remove user-id agent from palo alto firewall and not able to commit. PA-220 PANOS version 8.0.3. Same model firewall I have removed I can able to commit. Only in this firewall, I'm seeing this issue.

Screenshot (500).png

Total number of profiles

Hi, We have the problem with the total number of security profiles.As you can see in attached screenshot the maximum number of profiles is 100, for now we have 84, but when I tried to add new one I get the capacity error. Maybe someone had the same problem.Model - PA-820

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels