General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 239 Views
  • 0 replies
  • 0 Likes

MAC-in-MAC on esxi - ha_aa_pktfwd_err_decap

I've been trying to track this issue down for a month or so now and haven't had a lot of luck with any of the permutations in my vmware environment. 

I am running two 11.0.4-h2 PA-VMs in Active/Active mode. I'm using floating gateways and all is runn

...

Resolved! Replace SFP Process

Hi we have a PA-850. Port 5 has a RJ45 SFP adapter, internet connection. We are upgrading our Internet connection (bandwidth increase only, no IP changes) and the new handoff from the ISP is single mode fiber, so I purchased a PAN-SFP-PLUS-LR to supp

...

Resolved! Migration of HA Pair to Panorama!

Hello Folks,

 

I'm planning to Migration of HA Pair (active-passive) to Panorama, can someone help to understand whether ther will be a service interruption during this phase?

 

HA Pair -> 8.1

Panorama -> 8.1

 

Best Regards,

Pradeepkumar 

TLS 1.3 has General Protocol Error

Hi all,

Fairly new to PAN OS and have just enabled decryption on my 10.2.3-h4 VM-300 firewall.  In my decryption logs, all entries for TLS 1.3 are having a 'General Protocol Error'.  When running a v11.0.1 firewall (that I had to downgrade due to dat

...

Certificate Expiry

Hi All,

I am trying to import the Azure SAML certificate to use it in the Identity Provider Certificate as it is expiring this Thursday. But i am getting the attached error. Does it mean do i need to delete the existing one and then import it? I have

...

Resolved! RTP traffic not matching App-ID Rule

I have a strange issue where I have a configured rule to allow the "rtp" and "rtcp" App-IDs with application-default service from any-to-any. Below that rule I have a generic permit-any rule with application service any. Screenshots below. The behavi

...

IanGraham_0-1704745546729.png
IanGraham_3-1704745826139.png
IanGraham_2-1704745786416.png

Global Protect application blank screen

Hello Members,

 

Can anyone help me to solve the global protect blank screen issue on my PC, as for others it normally works fine.

 

I am using Windows 11 and I have already removed and re-installed the GP App but still it shows a blank screen and I

...

SamiPTfA by L1 Bithead
  • 8006 Views
  • 7 replies
  • 0 Likes

VPN tunnel is getting dropped

we are seeing tunnel drop with below error message.

IKE phase-1 SA is deleted SA: 1.1.1.1[500]-2.2.2.2[500] cookie:191098e4ef6db35d:eba9ee89ff200b07

transition from trial to purchased license

Hi All,

 

We are in a scenario where we are running firewalls on trial licenses. 

 

We have purchased the licenses. Can you help me with following queries :
1. When firewall transition from trial -> purchased license, will firewall drop the network tr

...

BRI-IT by L0 Member
  • 393 Views
  • 1 replies
  • 0 Likes

Resolved! 2 Tunnel With 2 IP Public. Secondary one is filtered ?

I have two IPSec tunnels with 2 ISPs:
ISP 1 is Primary
ISP 2 is Secondary
with a Failover scheme.

 

But when I set the metric for ISP 1 to 10 and ISP 2 to 200, it seems that the public IP of the second ISP cannot ping the second tunnel's peer gateway, w

...

ariiero by L1 Bithead
  • 799 Views
  • 2 replies
  • 0 Likes
  • 23624 Posts
  • 107 Subscriptions
Labels