General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4468 Views
  • 0 replies
  • 0 Likes

Google-meet troubles

Good morning community,I have problems to configure an access policy from the internal user network to the google-meet video conferencing service, users report that they do not listen to or view the video. When leaving the policy to any destination I see a lot of traffic going through the policy which I am not sure corresponds to google-meet.Cur...

google-meet.png

FQDN exclusion Global Protect enforce connection

Is it possible to FQDN exclude your local domain *.localdomain when enforcing network Global Protect connection? Could this be used as a workaround for not having pre-logon configured? How/why is there not a enforce global protect connection only while "outside" of the network?

Sec101 by L4 Transporter
  • 5949 Views
  • 8 replies
  • 0 Likes

Microsoft Exchange Server 0-Day vulnerabilities - Share your thoughts

Hi all, if you haven't lived under a rock for the past week, I'm sure you've heard about the 0-day MSExchange vulnerabilities. We want to let you know that Palo Alto Networks has you covered and wanted to make sure you have all the information you need. Check out the blog to get more information about these vulnerabilities and how PAN can prot...

kiwi by Community Team Member
  • 8508 Views
  • 4 replies
  • 1 Likes

Resolved! palo alto cli scripting mode limitation

Hi All, Is there any specific restriction to use commands or lines in scripting mode (set cli scripting-mode on)? The restriction, I means, how many set or delete lines/commands I can use. Not sure what's the buffer or bus size to handle if I paste 200 lines at the same time, would it crash? Device - PA 5250Os version - 9.0.9-h1 Thank you.

ChiragP by L2 Linker
  • 16371 Views
  • 3 replies
  • 0 Likes

DDNS over PPPOE

I would like to know some details about DDNS over pppoe. That feature was not available in 9.1.x series below is the document i chedked. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/dynamic-dns-overview.html However, when I check the same docs in 10.0.x series that is available. https://docs.paloaltonetworks.com/pan-os...

Jafar_Hussain_0-1615877557334.jpeg
Jafar_Hussain_1-1615877557336.jpeg

Jitter when making Phone calls

Hi ExpertsThe client is reporting Latency/Jitter when making the phone calls which is traversing through the PA firewalls 5220. We've QOS policy configured for the RTP/SIP applications (User/Zone is set to 'any') with Class 1(real-time) . Also, we've configured a Guaranteed Egress of 5000Mbps for this Class1 traffic under QOS profile which is ap...

Upgrade/Move from Panorama Legacy mode to Panorama mode

Hi,Currently Panorama is in Legacy mode, there 5 devices connected to it, 2 in 2 data centres, one at an office. Templates are configured and synced across devices including device specific templates (like configs and other device management configs). However due to the logging limitations we need to change to Panorama mode. The other temporary ...

M500 Disk Pair Raid status changes between active and clean

If I execute the command 'show system raid detail' on my m500 log servers I see the status of the disk pair toggling between active and clean. I am wondering why it would doe this. Is this normal? admin@LOG01> show system raid detailDisk Pair A AvailableStatus activeDisk id A1 Presentmodel : ST2000NX0253size : 1907729 MBstatus : active syncDi...

How are 'Bytes' counted in ACC and traffic logs?

Hi All,One of our customers has blocked the 'Music' category in URL Filtering but when we filter the 'Music' Category in ACC, it shows total bytes for the last 7 days as 5 GB. So what do bytes really represent? Why does it show 5 GB when the category is blocked? Please explain this in detail.Regards,Hiren

How to Renew Certificates for GlobalProtect Devices

Hi all, I want to renew the expiration date of the certificates for my globalprotect devices. The firewall is the CA that issued the certificates. My question is whether I have to export and import the certificates after renewing them by following the steps on this article: https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/cer...

Carracido by L4 Transporter
  • 29310 Views
  • 7 replies
  • 2 Likes

Palo Alto appliance SSL-VPN throughput

Hi all, I searched all the documents available for Palo 5220 (performance datasheet, PANOS admin guide etc) but i cannot seem to find anywhere specified the SSL-VPN throughput...only the maximum number of SSL-VPN tunnels. Is there anyway or maybe a document where I can find this parameter? I need this for writing a technical proposal to a client...

livliv by L0 Member
  • 3685 Views
  • 1 replies
  • 0 Likes

Resolved! Cannot install Machine Certificate for GP Pre-logon

I encountered a problem installing the machine certificate.I followed the article below:https://live.paloaltonetworks.com/t5/news/globalprotect-pre-logon-authentication/ta-p/322237 We are using a self-signed root ca that is in the cert profile for auth, then generated the server cert and machine cert and signed them with the same root. Then expo...

ERROR.png
CERT.jpg

Connect 2 Aruba Controllers to PA-220

We have two Aruba wireless controllers in a master / secondary configuration. Each one has a trunk port which contains about a dozen VLANs with our guest wireless traffic. The VLANs are arbitrarily assigned to the trunk ports by the controllers and can change depending on network conditions (from what I understand). The PA-220 is the gateway ...

  • 24379 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels