General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4228 Views
  • 0 replies
  • 0 Likes

DNS packets in drop stage, but i can see the same packet in transmit stage and DNS server response as well.

Hi Community I am seeing a strange behavior with DNS traffic. I tried to resolve some FQDns which work fine (those are public fqdns). But when I do the packet capture, I can see the same packets in transmit and drop stage. By comparing the tcp port and dns transaction id, i can see those packets sent only once by end machine and the same in both...

PAN-DB API for URL Re-categorization

I apologize if this has been asked before, but I could only find some posts from 2014. Is there an API for PAN-DB that allows for automated submissions for URL re-categorization? Thanks in advance!

Gergen by L1 Bithead
  • 8865 Views
  • 6 replies
  • 0 Likes

Microsoft Failover Cluster node not sending out Gratuitous ARP requests after a failover

This was a particularly odd issue which I had never experienced before so I thought it’s worth blogging about it.During a normal MS Failover Cluster failover operation, the node calming the cluster roles sends out a GARP request to notify the networking infrastructure of the MAC address change. The Layer 3 switch / router then updates the MAC ad...

Resolved! SSL Decryption internet throughput issues

Hello everyone, We have been testing SSL Decryption on a single PC, when decryption policy is applied, internet connection speed is highly affected - Speedtest shows less than 1mb/s When decryption policy is disabled, the speed is around 200mb/sPalo Alto 3220, version 9.1.0We are using a certificate from our domain CA, SSL decryption works fine,...

Transfer finished course from personal Beacon account to partner Beacon account

Hi, Does anyone know if its possible to transfer the courses you have completed in your personal Beacon account to your Partner Beacon account? I finished a bunch or courses before starting my new role as Network support engineer and would like to move the certifications from my personal account to my partner accounts. Thanks

Ben-Price by L4 Transporter
  • 2115 Views
  • 1 replies
  • 0 Likes

Resolved! Global Protect Always On When Coming Into the Office

I finally got certificate based always on GP VPN working when my laptop is at home. It occurred to me that when people go into the office, they'd be on the internal LAN.How is that normally handled? Since I currently have an egress separate from the GP PAN the traffic would hit the same portal as when they're home and noonewould be the wiser. Bu...

Resolved! Why ip address are different at gui and cli

Hello, ip address was changed to below ip address via gui, please see the below first picture. but why cli shows different ip address at the same interface? and the the PA cannot ping itself. Anyone can help to explain it? Thank you

PAFrank_0-1621221800133.png
PAFrank_1-1621221875576.png
PAFrank by L2 Linker
  • 5470 Views
  • 3 replies
  • 0 Likes

ISP failure after 2-3 packet drops

We are using one VOIP application over internet which is disconnecting after drop in 2-3 packet. For seamless connectivity we are looking for ISP failure if 2-3 packets are dropping.We can configure path monitoring ( By default ping interval is 3sec and count is 5) . We want to know this path-monitoring will fail after 15 consecutive pings or ho...

Deepak_K by L3 Networker
  • 3234 Views
  • 2 replies
  • 0 Likes

Resolved! Globalprotect check operational system on the portal/gateway without collecting HIP data and using HIP profiles/HIP objects?

I found out that you can use the operational system without a HIP object/profile to do things on the Gateway/Portal even if the collection of HIP data is stopped on the Portal. Portal config: Gateway Config: Can someone tell me why when I try to check if the operational system is Linux in a HIP object/profile and I attach it to secu...

NikolayDimitrov_1-1621011523428.png
NikolayDimitrov_0-1621011296270.png

Global Load Balancer (DNS) for GlobalProtect Portal

Looking to set up multiple data center redundancy for GlobalProtect and I'm unsure if Palo Alto would support a global load balancer (GLB) for the solution. We have global load balancer DNS servers that detect the status of our DC internet connections and will remove the IP's from the DNS entry if an ISP is down. The TTL on the DNS entries is ...

yostie by L0 Member
  • 8381 Views
  • 1 replies
  • 2 Likes
  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels