General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1700 Views
  • 0 replies
  • 0 Likes

Retro-fitting standard SD-WAN into existing firewalls

I want to deploy hub-spoke SD-WAN into my existing routers, but it says you must do it through Panorama.  It then wants me to create a template, add the router, interface, etc. and basically define everything to do with SD-WAN in Panorama.  The probl

...

Advertising default route in OSPF Totally Stubby Area

Hello,

 

I've setup an OSPF Stub area with the below options on the ABR:

 

- Accept Summary [ unchecked ]

- Advertise Default Route [ checked ]

 

However if I look at other neighbors in the area they are not received a default route pointing to the ABR. Is

...

NobleNOC by L0 Member
  • 3247 Views
  • 1 replies
  • 0 Likes

Device groups out of sync for multiple firewalls

After importing a new firewall into Panorama all of the other firewalls are now showing out of sync. I believe it's because the box was checked that says "import devices shared objects into panoramas shared object context". When I tried to push to de

...

Slade34 by L0 Member
  • 2288 Views
  • 1 replies
  • 0 Likes

Tunnel interface show "Red"

Hi,

As iam facing the issue with  Passive firewall as interface status show "Red"

 

Moreover Tunnel monitoring is already disable still it's show red. As on the active firewall the it's show green,

Can you please advise.

 

Joshan_Lakhani_0-1616928688768.png

User-id redistribution not working

I have user-id successfully configured on a fw, and i am trying to redistribute these mappings to panorama 

 

We are using the integrated Panos agent, 

 

i have created the the user-id collector name/pre-shared key on redistribution tab of the User-id Ag

...

Resolved! API call to panorama how to register DAG?

When registering IP's to Tags on panorama, do you have to specify a target or device-group or serial number in your call?  How does that match/registration actually occur?  Do you have to specify a "location   device-group"  in the call?

 

<uid-message

...

Sec101 by L4 Transporter
  • 4957 Views
  • 5 replies
  • 0 Likes

What is "'service':Off" in chassis.leds on PAN-OS 9.1?

Hi,

I found out a new item in 'chassis.leds' on PAN-OS 9.1.
There is not shown on PAN-OS 8.1.
Anyone know what does it mean 'service':Off ?

- v8.1
>show system state filter chassis.leds
Chassis.leds:{'alarm':Off, 'fans':Off, 'ha':Off, 'log':Off, 'status':G

...

Mt_103 by L2 Linker
  • 2079 Views
  • 1 replies
  • 0 Likes

NAT issue for accessing ICMC service from google

We have 4 production servers are accessing ICMC service which is hosted in following URL “pubsub.googleapis.com”,

 

If all 4 servers in common NAT rule then there is a time-out error observed which caused ICMC service failure.

 

We have tried change the

...

gasin1 by L1 Bithead
  • 2746 Views
  • 4 replies
  • 0 Likes

Global Protect Users Experiencing Telnet Disconnects

I wanted to see if I can get some help with some session termination problems that I am experiencing for Global Protect users. Our remote users connect to an on-prem ERP systems through telnet, tcp/23.  I recognize that this protocol has inherited pe

...

CCullhaj by L1 Bithead
  • 3872 Views
  • 3 replies
  • 0 Likes

Resolved! Convert VSD Juniper(Screen OS) configuration to Palo Alto

Hi team,

We have a Juniper firewall configuration with 4 VSD(virtual security device) and we want to migrate that kind of configuration on Palo Alto.

We have tried to migrate that configuration but we didn't find this capability on palo alto firewall.

D

...

Fjrubiab by L0 Member
  • 3664 Views
  • 3 replies
  • 0 Likes

Resolved! VPN Best Practices

I'm looking to make some modifications to Site-to-Site VPN IKE-Gateway/IPSec profiles and GlobalProtect IPSec Crypto Profile.

 

For GlobalProtect IPSec,  I'd like to switch from aes-128-cbc to GCM.  I know GCM is more secure and has better performance

...

ce1028 by L4 Transporter
  • 5610 Views
  • 5 replies
  • 0 Likes

BGP configuration

I am looking to see the commands to check bgp configuration on palo alto 5050 Software version 8.1.14

 

We have that PA in our organization but i am new and trying to check why i am not able to learn a route 10.104.55.0/24 in BGP in PA 5050

 

I am learni

...

  • 24217 Posts
  • 117 Subscriptions
Top Liked Authors
Labels