General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 309 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3651 Views
  • 2 replies
  • 14 Likes

IPSec Tunnels BGP Fluctuation Frequently

Hi All, 

 

We have 04 IPSec VPN tunnels created on our PA FW with Public Cloud configured with BGP. (All these 04 Tunnels are created over single Internet link). All 04 peering IP of public cloud belongs to same region.

 

Pl note that these tunnels are i

...

Jimmy20 by L2 Linker
  • 1784 Views
  • 1 replies
  • 0 Likes

iOS Global Protect Always-On VPN ?

We have:

 

MDM: Filewave

iOS: 12+

GP: 5+

 

When an iPad is rebooted, GP doesn't auto reconnect & must manually be opened/connected again.  Any ideas how to get it to actually always auto reconnect?  We really only care about the user identification being a

...

Resolved! User identification in security policy

Hello,

 

I have a problem with configuration of user identification in security policy. What is the target: for some users who login to VPN via GlobalProtect I would like to limit them to some specific subnet. Users login to VPN using their Active Dire

...

Resolved! Need to Disable TLS 1.0 & 1.1 for port TCP-3978

Can someone suggest on how can we disable TLS 1.0 & 1.1 for port TCP-3978

 

Description: The remote service accepts connections encrypted using TLS 1.0. TLS 1.0 has a number of cryptographic design flaws. Modern impleme
ntations of TLS 1.0 mitigate thes

...

A statement about using Pinterest in a URL category.

Hello! somewhat new to the community, I used to have a login but didn't login forever...

Just something that you might want to know if you are ever forced to add pinterest to a custom URL category, you will also need *.pinimg.com in the category to ma

...

Burnsy30 by L0 Member
  • 2273 Views
  • 1 replies
  • 1 Likes

MFA Authentication

I need to configure MFA for administrator login, we would prefer second authentication through e-mail  or any mobile APP token.I am unable to find exact document to configure , could you please help us to configure MFA in our Paloalto device.

Resolved! Panorama - deleting part of a template?

When i import my HA pair of firewalls into Panorama (9.1.3), the resulting template includes values for HA config. I would like to leave HA config up to the gateways themselves and not include it as part of the template.  How would i delete that part

...

Troubleshoot/debug scep

Our pki team has setup a scep/ndes server for us to use for new firewall we setup. The error i get in the gui is not saying anything. If I would like to start a debug on the firewall cli for scep. Where do i do that?

hbalzac by L3 Networker
  • 2389 Views
  • 1 replies
  • 0 Likes

Panorama version 9.1.4

Since i can see the stable version mentioned for panorama is 9.1.4,but when i go to support portal under panorama base images to download 9.1.4 i cannot the file...i am looking to install it on vm/esxi.

 

Let me know the stable version from 9.1.x and 9

...

Swetang by L1 Bithead
  • 1653 Views
  • 1 replies
  • 0 Likes

Resolved! Global Protect Client Preferred Release?

 

We are currently looking at updating our global protect client and would like to get some guidance on what version we should be updating to, ideally a client that may support MacOS Big Sur when it is formally released. With the global protect client

...

why the config logs is not capture?

Hi,


We have observed that “activating” a GP client version is not captured under configuration logs.

 

  1.        Is this because no commit is required for such an action?
  2.        Is this expected behaviour?
  3.        How can we check on the history of such a con
...

PA 200 Connected to 4G Router

Hi Folks,

We currently have a primary direct internet from the ISP to the Palo Alto PA-200 configured with LSVPN .

As we plan to have a secondary Internet, we want to connect the Palo Alto PA-200 with 4G Router using LSVPN as well. 

The problem is the p

...

4G-PA200.jpg
Adam42 by L1 Bithead
  • 5071 Views
  • 6 replies
  • 0 Likes

OSPF: more detailed logs?

We're still experiencing the occasional OSPF adjacency drop, although it's much improved since our changes over the summer.

 

However, the log entries in the System log is anything but useful:

 

OSPF adjacency with neighbor has gone down. interface ae2.2...

fjwcash by L4 Transporter
  • 11082 Views
  • 5 replies
  • 0 Likes
  • 24185 Posts
  • 100 Subscriptions
Top Liked Authors
Labels