General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

EDU-330 and EDU-214 (looking for study material)

Hello everyone! I have been looking (without success) the study material of EDU-214 and EDU-330, I can not find anywhere, I checked the beacon portal and nothing.If anyone had this material or knows where to get it, I would greatly appreciate it. Thanks!

Resolved! Global Protect: Split DNS - NSLOOKUP & DIG expected behaviour

What is the expected NSLOOKUP / DIG behaviour when using Split DNS and attempting to resolve an excluded domain? We are seeing the following:nslookup excludeddomain.comServer: dc.domain.localAddress: 10.0.0.10*** dc.domain.local can't find excludeddomain.com: Non-existent domain Is this expected (obviously it resolves if I tell it to use an exte...

cg7201 by • L0 Member
  • 7063 Views
  • 2 replies
  • 0 Likes

GlobalProtect not connecting on Mac

I'm trying to use GlobalProtect on a Mac, but it won't connect. I don't know much about Mac in general which definitely won't help me, I'm doing this for someone else and this is my first time using GlobalProtect on one. When I start the app and type the username, password and portal it just says connecting in the status tab. So far I've tried r...

K.Arne by • L1 Bithead
  • 42054 Views
  • 14 replies
  • 1 Likes

Resolved! Policy, using App ID ssl, is bypassed in favor of service based policy

Hi All, I'm new to Palo so hope you guys can help me understand something. We have two almost identical security policies that allow traffic via ports tcp/443 and 80. The first policy uses App IDs, ssl and web-browsing. The second policy uses services tcp/443, 80. My expectation is that the second policy should never be hit since ports 443 and 8...

Inelse by • L1 Bithead
  • 7396 Views
  • 5 replies
  • 0 Likes

Resolved! Panorama Management Server Upgrade Suggested Path

Greetings,We are looking for suggestions/thoughts for our next upgrade to our PAN management server - we are running PAN 8.1.13 on a Model M-600. We are looking to go to 9.x - not sure whether 9.0 or 9.1 at this point. Probably will be decided based on the feedback we get from this post. So bottom line: - Which version would you recommend? Sho...

terryc by • L1 Bithead
  • 3758 Views
  • 2 replies
  • 0 Likes

Panorama Report Date Picker

Hi All, Is there a setting that I am missing in Panorama for the retention of the reports created in the reports tab under monitor ?On Panorama for any default or scheduled report I only have the ability to go back 7 days:This goes for any scheduled custom report or the pre-defined reports.Panorama:However on the firewall its self I have months ...

Marc_T_0-1617781192581.png
Marc_T_1-1617781268651.png
Marc_T by • L2 Linker
  • 3641 Views
  • 3 replies
  • 0 Likes

PA-820 Time Reverts to 2000

I have PA 820s deployed at remote sites with IPSec tunnels configured on them. When a power outage happens, either through a requested shutdown or not, the time resets back to Jan 1, 2000 on some of them and the initial commit fails. This causes the device to only be accessible via the mgmt interface. When looking at the logs, the reason the com...

Security Policies in Firewall

How to troubleshoot when we get sessions end reasons: Tcp-rst-ServerTcp-rst- client Tcp-fin n/aAged out I know what all these but I don't know how to troubleshoot the issue and don't know where to start troubleshoot Can someone help on this.

Using Rest API to delete an AWS Monitoring Definition in Panorama

I am trying to automate the addition/deletion of AWS Monitoring Definitions for the AWS Plug in for Panorama. I am able to add Monitoring Definitions using the following in Postman: https://{{panorama}}/api?key={{key}}&type=config&action=set&xpath=/config/devices/entry[@name='localhost.localdomain']/plugins/aws/monitoring-definiti...

SSL Decryption - Forward Trust Certificate option not available

Hello I try to configure the ssl decryption on my cluster of PA-220. I have an internal PKI based on Microsoft solution. On the first node, I'm able to generate the request, the csr has been validated by the PKI server and I'm able to export from the PKI the certificate (base-64 encoded). I'm able to import the certificat in my PA-220 device wi...

GP Authentication issues with Symantec VIP

Hi,We are running Palo Alto Global Protect with Symantec VIP MFA. We have run this for quite some time now and it has been stable until recently.We are seeing random errors appearing on one of the validation servers. It seems Palo is sending the request but Symantec is dropping it. A restart of the validation service on VIP EG fix the issue temp...

Firewall requests.png

Resolved! GlobalProtect Client Startup Windows 10

GlobalProtect Version 4.1.0-98PAN OS 8.0.10Login mode: on-demand Hi there, we've roll-out the GP-Software on everyone's PCs. Everytime a Windows (10) Client is rebooting the "GlobalProtect" pop-up Gui is showing up. Is there a way to stop loading the "GlobalProtect" pop-up Gui after rebooting Windows? Thank you.

Hodor by • L1 Bithead
  • 71006 Views
  • 14 replies
  • 0 Likes

Newbie Question

Guys, I want to apologize in advance. I just haven't been able to find any information on this topic. I have our first brand new PAN firewall and I'm configuring it for use in a remote datacenter where we rent space and we will connect via site-to-site VPN. I got into the FW via the management port and I like the interface. I'm setting up th...

  • 24463 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels