General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4119 Views
  • 0 replies
  • 0 Likes

Can we configure captive portal for windows machine in palo alto which are in domain?

Can we configure captive portal for windows machine in Palo alto which are in domain? Customer do not want SSO authentication on Palo alto for machine which are in domain, while going to internet.He want captive for traffic going to internet.He want windows machine login authentication via AD, but he want captive portal for Palo Alto for AD user...

Resolved! What is file file descriptor?

Hi.I have a problem with management serves, sometimes when I try to connect to firewall by SSH I can see message "Cannot connect to management server". Process restarts itselft and connection to mgmtsrvr return, mgmtsrvr return to normal resource utilization. I also had a problem with PBP, a lot of packets was blocked by PBP. The software versio...

PA-220 - 9.1.6 - DO NOT UPDATE

Hi guys, We have had 3 PA-220's recently that have all failed and needed to be factory reset when upgrading to 9.1.6. I have a case open to investigate further but this version is still the recommended version which is worrying. Luke

LukeRath by L1 Bithead
  • 6891 Views
  • 8 replies
  • 0 Likes

Site to Site IPSec VPN Configuration to extend Enterprise Network to a remote office

I have two PA800 NGFW running in Active-Standby HA mode and they are connected to a Perimeter Switch. Need an insight about a V-P-N Configuration on my PA that is about to connect to remote office. I am new to this and I brought this here because there is a little bit more/less about this configuration for me. My office and the remote office are...

iscofate by L0 Member
  • 4212 Views
  • 1 replies
  • 0 Likes

Panorama custom reports hang

Custom reports on my Panorama (9.1.6) were working fine until this week. Today, any report i run gets stuck in "please wait" indefinitely. Nothing has changed on the machine. Any ideas what i should look for?

Resolved! Local user Identification issue

As per the below mention snap-shot, we observed user id get changed with AD user and we have allowed the internet access to local user id which is configured in Palo Alto. Due to issue user facing internet issue. We have not configure this user in AD domain, then how user id gets change in the Palo Alto automatically ? While authenticating via ...

Capture Local user Identification issue.JPG

Resolved! Schedule cli command execute

Hi all, I need schedule some cli command which i execute manually from SSH console like below; Command line 1: test vpn ipsec-sa tunnel Xtunnelname:XtunnelProxyIdCommand line 2: test vpn ike-sa gateway Xtunnelname Is there any way schedule tasks in palo alto? Regards.

Lacrymae by L1 Bithead
  • 4663 Views
  • 2 replies
  • 1 Likes

Failed to Launch Help warning pops up randomly while connected to GloabalProtect(5.1.5)

Hello everyone, most lately have started seeing a warning messaged "Failed to Launch Help" pop up randomly while connected to GloabalProtect(5.1.5). Tried looking for KB Articles around it and could not find any. Was wondering if I could get some insight on what could be causing this and how to get rid of it? Thank you,VC

changing AD user passwords through globalprotect app

Hi Community, I have the following scenario:user_1/password_1 Active Directory credentials for login into windows system and domainuser_2/password_2 Active Directory credentials only for globalprotect authentication. I´d like to know if there is a way to change the password_2 for user_2 through the GP agent application? Thank you!

Carracido by L4 Transporter
  • 2176 Views
  • 1 replies
  • 0 Likes

Resolved! PAN 5050 DDNS

Hello Team, I moved up from Fortinet/Ubiquity, bought a used PAN 5050 and upgrade the OS to 8.1.18 for a Home Use. However, since i am new to PAN during the configuration i realized PAN 5050 does not support DDNS. In my case i am home user I don't have a Static IP. As you all know, having Dynamic IP is a pain for almost all firewalls and limited...

KurdTech by L1 Bithead
  • 3435 Views
  • 3 replies
  • 0 Likes

EDL URL List Format and Subpages

I understand that for an EDL of type URL, the format is either company.com*.company.com This will include any additional subdomains, whether at the beginning or the end of the URL. Regarding the forward slash, will a URL like the following be a valid entry that will be processed? company.com/subpage/QWERTY/ Additionally, does that mean only th...

Captive Portal for Corporate devices

We have recently upgraded our HA firewall cluster (PA-3020) from 7.1.22 to 9.1.6 following the suggested upgrade path by PA.We have captive portal in place, before the upgrade, all our corporate windows 10 laptops as soon as we power them on, they used to connect to our corporate Wi-Fi and allowed users to login as per normal.Since the time we h...

UHL by L0 Member
  • 3130 Views
  • 3 replies
  • 0 Likes

Minemeld MISP miner needs a revisit

Hi guys, I believe the MISP miner for Minemeld needs a re-visit. None of the tagged indicators are being pulled by Minemeld from our MISP instance. I think there are a lot of changes to the current API as compared to the ones used by the current miners. Also, a lot of new queries such as Decay Model and Timeline can be done through API. I don't ...

vedd3r by L2 Linker
  • 3131 Views
  • 1 replies
  • 1 Likes

Resolved! Logging for deny/drop policy

Hi Team, what is the recommended/ best practice logging option for policies with action set as deny/drop? is it "log at session end" or "log at session start"?

Query on file blocking profile.

Hi, Can we achieve the following points, 1.Required only our office domain user can able to access upload/download file2.Hotmail user can only access for downloading / uploading block3.Another domain user (Guest user) only downloading the file uploading block I know that we can block other domains but can we achieve this requirement downloading...

  • 24336 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels