General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4433 Views
  • 0 replies
  • 0 Likes

Custom Logs / Path Monitor Alert

Hello! I may be trying to do something impossible, but it seems like the configuration elements are all there. We have a static default route to our ISP that is set with path monitoring so that we failover to a backup route when the gateway is unreachable. We are trying to figure out a way to be emailed when the path monitor fails. I have ...

ECMP breaks secure email access.

Hi all, while using ECMP for the last 2 years without any issues using 3 ISP's with different weight and enabling Symmetric Return and Strict Source Path, I found that some sites with authentication access and Proofpoint secure emails access are being timed out because of their sensitivity of the source ISP change during the session. In most of...

SShnap by L3 Networker
  • 2278 Views
  • 5 replies
  • 0 Likes

The PA-220 is unable to boot into the system.

As stated in the subject, I encountered an error during boot-up. The details are as follows:SPI ID: ef:40:18:00:00header found at offset 0x1d80Image 1.2: address: 0xffffffff81000000, header length: 192, data length: 8160Validating data...Starting next bootloader at 0xffffffff81000000SPI stage 1.5 bootloaderSPI ID: ef:40:18:00:00Header 1 found at...

Custom URL Issue

Hi all, I had an issue where a client created a Custom URL category with multiple of URLs and added it in a Security Rule, all of the URLs specified in that custom category is matching except one URL with wild card such as *.sometechnologies.com. I'm using the command >test custom-url url <MyURL> to check the match but for only one url ...

Creating tunnel monitoring profile between PA-3220 to Meraki SDWAN Cisco

Hi Friends, Our end customer wants to set up tunnel monitoring profile between a PA-3220 firewall and a Cisco Meraki SD-WAN device. Although an IPsec tunnel has already been established between the Palo Alto and the Meraki SD-WAN, we need to determine whether failover will occur automatically if one tunnel goes down, or if tunnel monitoring ne...

GlobalProtect 6.3.3

Our vulnerability scanner for the last couple weeks has been reporting vulnerabilities for GlobalProtect that are remediated with an upgrade to 6.3.3, but other than the vulnerability acknowledgement from PA mentioning it I do not see any evidence of 6.3.3 being released. The latest version I see in the "Software Updates" section of the customer...

C.Osborn by L0 Member
  • 8970 Views
  • 6 replies
  • 2 Likes

Other Administrators are holding device wide commit locks

Hi Guys, i have actually the problem that i cant do any commit, there are two pending commits and if i try to commit the following message appearing: "Error Other Administrators are holding device wide commit locks". Even when im logged in as the administrator who did the commit the same message appears. The Administratoraccounts are supperusers.

External Web Proxy

Hi. Have someone working with next hop fwd proxy ? I need post firewall solution for additional files types blocks (like Trellix)

chens by L3 Networker
  • 1219 Views
  • 2 replies
  • 0 Likes

Resolved! GlobalProtect SAML Authentication Complete

We recently upgraded firewalls from 10.1 to 11.1. We've stayed on globalprotect 6.2.5 and 6.2.8 the entire time. Before the upgrade, GP would logon automatically after user logon. GP would use SAML authentication and complete without fanfare. After updating to 11.1, GP starts up, SAML auth to the portal opens a browser which completes SAML...

What is the Checkov softwate ECCN number

Hi Team, We would like to consider using checkov software ( https://checkov.io) for our projects. As part of the security compliance, we would like to know the ECCN number for the checkov software. Could you please help share the same or let us know the contact details so we can reach offline. Thank you in advance!!

amar2237 by L0 Member
  • 1279 Views
  • 2 replies
  • 0 Likes

Social Media not blocked

We had created a security policy to block all social media and it was working fine, then since two weeks we found that Social Media is working and when i check the security policy everything shows fine and I checked the logs it shows as deny but even then Youtube Facebook is working fine. Regards, Mohammed Ibrahim Ahmed.

  • 24374 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels