General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4119 Views
  • 0 replies
  • 0 Likes

Resolved! IPSec VPN certificates

I’m very new to Palo Alto and testing things out on a home virtual lab on local computer. I’m trying to configure IPSec vpn between 2 sites using certificates. My problem is that when I export the certificate from PA-1, I cannot import it to PA-2 because I don’t know where FW-1 has saved it on the windows 10 pc being used to manage the firewal...

ldapjazz by L0 Member
  • 3826 Views
  • 2 replies
  • 0 Likes

Knowledge sharing: restarting palo alto processes , reboot , shutdown, factory default reset

In palo alto like any some things are fixed with an restart. 1. If the managment plane in the masterd log (for more about the Palo Alto logs and their meaning you can check https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-palo-alto-general-logs-and-log-files-that-are/m-p/410110#M92552) you see there are issues with a process...

Storage V-Motion

Hello, Our Virtualization team Storage vmotioned all the VMs on a specific host and that included VM-Series Firewalls for NSX as well. Resulting that the firewalls pass 0 kbps of throughput and dropping all the packets. We were able to identify this by looking at the throughput of the firewall which was 0. Does anyone know why storage vmotion br...

ayazdani by L1 Bithead
  • 3121 Views
  • 2 replies
  • 0 Likes

Resolved! Unable to export certificates

PanOS 7.0.1 Tested with Google Chrome and Firefox v56 When trying to export a certificate from Device tab --> Certificate Management --> Certificates, no matter which export format I choose, nor which certificate I choose, nothing happens. Browser window just refreshes and reloads the certs page. Nothing is downloaded.Has this ever happe...

Incoming traffic being not logged on external IP

Hi Any help greatly appreciated. I have 4 internal IPs w x y and z that need to route out on one of my external IPs (1.2.3.4). And then I need the ingress traffic on 1.2.3.4 to be routed to w x y and z based on the incoming port number. I am also changing the incoming port to a standard internal port number.The out going NAT rule seems to fin...

Resolved! IPSec VPN routing across multiple tunnels

Hi folks/. I have a situaiton that is doing my head in, and I need some help. I have an installation which looks like this "A" end - Palo Alto Active/Passive cluster, public IP for IPSec VPN termination "B" End - Juniper SRX cluster, Active/Active with TWO IP addresses (separate links) for IPSec VPN initiation I have configured two tunnels from ...

darren_g by L4 Transporter
  • 16711 Views
  • 8 replies
  • 0 Likes

MAC addresses for HA interfaces

I have 2 virtual instances of PA-8.0 on a laptop in a home lab for learning purposes. High Availability is configured in Active/Passive mode with HA1 using the management interface and it is working but HA2 is failing to sync and complete initialization. The HA2 interface is red in the GUI and will not go green. I think this may be a problem ...

Resolved! VA scan issue

Is there anyway to solve those VA issue? 1) 90317 - SSH Weak Algorithms Supported2) 42873 - SSL Medium Strength Cipher Suites Supported (SWEET32)3) 70658 - SSH Server CBC Mode Ciphers Enabled4) 71049 - SSH Weak MAC Algorithms Enabled Kindly help please..Thank you

Vector by L0 Member
  • 2999 Views
  • 2 replies
  • 0 Likes

Global protect certificate expiry

Hi team,Can we renew the server certificate used for gp before expiry can you please let me know if there would be any impact after renewing the certificate before expiry?? Or we need to renew the certificate before 1 day ???

Resolved! CLI commands to add a device in devicegroup as master device

Hi Team, I found some command to add a device in device group and template but couldn't find how to set a device as master device in device group with CLI,Tried to search cheat sheet but the information/commands are not available.Is it possible or this can be done via GUI only. Appreciate if anyone have provide commands cheat sheet which are not...

Srikant by L1 Bithead
  • 5752 Views
  • 1 replies
  • 0 Likes

Dual ISP, PBF traffic not returning

I have two ISPs configured with path monitoring and I can successfully monitor the primary route and fail over to the secondary, however what I would like to do now is use PBF to always send some of my traffic out the secondary ISP. Everything I've read says this is possible and should be fairly straight-forward but I just can't seem to get it ...

NAT.jpg
PBF.jpg
Traffic.jpg
Cooper80 by L0 Member
  • 3671 Views
  • 2 replies
  • 1 Likes

unable to block google chrome updates

I blocked 'google-update' app in firewall rules but I still see some of the users' browsers getting updated. I can't find any helpful logs for those users. Please let me know a solid way I can blocked google updates on Palos. TIA.

Resolved! HA down PA-220

I've a pair of PA-220 configured as cluster. After power off - on HA is down. But I can connect to both firewalls via https & ssh.Active fw1 shows that HA ports 7 & 8 are down (red in GUI). On passive firewall fw2 all ports are grey.But the real strange thing is, when looking into running-config (CLI), on active fw1 all the HA config is ...

ChrisCon by L2 Linker
  • 5559 Views
  • 3 replies
  • 0 Likes

Resolved! Failed to delete Certificate due to references - but I don't want to delete those references

Hello, my current GlobalProtect portal/gateway certificate is expiring soon so I had our 3rd party CA create a new one with the same name. In Panorama under templates/device/certificates, I uploaded the new cert with a temporary name (ex. expiring cert name is foobar.net so I uploaded the new cert as new_foobar.net). Now I want to delete the e...

  • 24336 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels