General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4118 Views
  • 0 replies
  • 0 Likes

Zone Protection drops traffic

We have below settings for our untrust zone protection. We don't see a high CPS rate but we still see packets getting dropped, and has now started effecting us. Any guidance would be helpful.PANO9.0.11/5250

image.png
image.png
image.png
raji_toor by L4 Transporter
  • 7683 Views
  • 9 replies
  • 0 Likes

Unexpect single port disconnection from PA-220

My client's PA 220 cannot reach to his gateway. However, after he has reboot his PA, the connection is back, but only for few hours long! No matter how I have add the MAC address and troubshoot the problem of the system. I have checked both port on therouter and the port on the PA. I have added the MAC address on the ethernet port. I have even ...

Resolved! Cannot view config difference in Panorama

Hello, When I do a 'show config diff' from CLI in Panorama, all I get is something like:- outfile /opt/pancfg/session/pan/user_tmp/6822880318474071/opresult.out.10687;+ outfile /opt/pancfg/session/pan/user_tmp/6822880318474071/opresult.out.10688; Using 9.0.7 No change was made and I can view the config difference from the firewall and also...

Minemeld miner that accepts email addresses.

Hello Guys,Am new to mine-meld and trying to add a node/miner that can collect email addresses.I was able to find the Prototype aggregator "stdlib.aggregatorEmailAddress" but not the prototype Type=miner and indicator=email-addr.Could someone please suggest/guide me set the miner?Thanks,Vamshi.

LIVEcommunity account lost (or stolen?)

Hi everybody! Today I logged into my LIVEcommunity account as usual, but my profile has gone. It seems that I got a brand new account, while the original one is not accessible. This is my original profile: https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/61214 Now my profile appears to be this: https://live.paloaltonetworks.com/...

grenzi by L0 Member
  • 4160 Views
  • 3 replies
  • 0 Likes

Resolved! User Group Count exceeds threshold - PANORAMA

Hi Folks, looking for advice on an alert which is bugging me. Our Panorama instance regularly (2 per hour) reports that:Panorama - SYSTEM ALERT : high : User Group count of 12080 exceeds threshold of 10000 Now this is correct - as it comes from two (soon to be four) firewalls plumbed into LDAP/AD:admin@Panorama> show user group list device-gr...

GN_ROS by L1 Bithead
  • 7735 Views
  • 8 replies
  • 0 Likes

Resolved! GP disconnect intermittely

Hi All, The users are able to connect and work for sometime and then traffic flow stops; although Global Protect Agent shows that VPN is connected.The user have to disconnect and reconnect again, then it will work for sometime and stops again. This intermittent issue can occur in 10 min, or 30 min or 1 hour or more, there is no definite time. In...

Global Protect portal Config selection criteria combination of User group/device check/custom check?

I'm guessing others are combining these together, but is it possible to specify these together mix/match? Specifically, We have configs without a custom check (custom checkmark box UNchecked-portal/agent/configs/config selection criteria custom checks), and that are only based on AD group. But when I turn on custom checks for a different agen...

Sec101 by L4 Transporter
  • 4005 Views
  • 2 replies
  • 0 Likes

Adding ?v=panosurl to MineMeld EDL brought down our entire network

Just wanted to share this with the community in hopes that it may prevent one from experiencing the hardship that we did. We use MineMeld with our URL filtering rules. We appended "?v=panosurl" to the end of the end of the URL for our General_Block_List with the assumption that it would just reformat the output essentially removing the "http:/...

Resolved! UserID Active Directory multiple VSYS

Hello people, I have a novice question so apologies if it is too obvious to some. I have created 5 vsys and I want to use the same Active Directory server in all 5 vsys (vsys A, B, C, D,E) for userid in policies. The Active Directory is only routable via one of the vsys (vsys A). Does this mean that I should create an interface in the other 4 v...

Jedi_D by L2 Linker
  • 3419 Views
  • 3 replies
  • 0 Likes

citrix web browser application dependency

I have 2 pa 850 . devices was not able to install antivirus update due to application dependencies on web browser. our citrix servers are not set up for web browing due to security concern. is their any other solution available. our pa configuration is bump in the wire. looking for suggestions?

kushalsh by L0 Member
  • 2161 Views
  • 1 replies
  • 0 Likes

Can we configure captive portal for windows machine in palo alto which are in domain?

Can we configure captive portal for windows machine in Palo alto which are in domain? Customer do not want SSO authentication on Palo alto for machine which are in domain, while going to internet.He want captive for traffic going to internet.He want windows machine login authentication via AD, but he want captive portal for Palo Alto for AD user...

Resolved! What is file file descriptor?

Hi.I have a problem with management serves, sometimes when I try to connect to firewall by SSH I can see message "Cannot connect to management server". Process restarts itselft and connection to mgmtsrvr return, mgmtsrvr return to normal resource utilization. I also had a problem with PBP, a lot of packets was blocked by PBP. The software versio...

  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels