General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4132 Views
  • 0 replies
  • 0 Likes

Syslog listener to python script possible??????

Does anybody know how, or can offer some clues, as to how I could get the platform to call a python script to use an external API as a result of a syslog message. I know the syslog daemon passes the messages to Minemeld in JSON format, but what would be required to get minemeld to make an outbound call - ideally via script. The use case is s...

Resolved! Reason why the GlobalProtect session is disconnected

Hi Guys, Some of our users experience disconnects from our GP VPN. When it happens it always impacts a partial set of the clients not everyone. I would like to know a method in which I can determine the reason of the disconnection. In the Monitor-Logs-GlobalProtect tab I can only see the fact if a user is logged-out or logged in and authenticati...

olloczky by L1 Bithead
  • 17791 Views
  • 7 replies
  • 0 Likes

Resolved! PBF and ipsec

HQ Network and Remote Network location are always through MPLSPBF is configured with path monitoring for forwarding via MPLS and if mpls failstraffic will be through ipsec_1 tunnel according to pbf created in palo alto.How to configure in palo alto if both ipsec1 and mpls down so that traffic should pass through ipsec_2@jdelio @Remo @BPry

bit_byte by L2 Linker
  • 3960 Views
  • 3 replies
  • 0 Likes

Resolved! PA-3320 Session's Setup Alerts for session limits reached

Today we had a networking issue that was random and hard to track down. Turns out to be DDOS attack to our Citrix. Since the Dashboard on the GUI doesn't show the BIG RED OMG Light when your maxed we missed it for sometime.does anyone know how to setup Email alerts for sessions over a certain load. 20%.. 30%... 40%... AND 99%

PAlmart_0-1610051721540.png
PAlmart by L1 Bithead
  • 3517 Views
  • 1 replies
  • 0 Likes

Cortex XDR mismatch between version of agent and cloud console

Dear community, For some of the XDR agents there´s a version mismatch between the software installed on the endpoint and the one displayed on the console in the cloud. Example: I installed 7.1 and the agent´s window is showing the right version but in the console in the cloud the agent version for this endpoint is showing 7.2. Does anyone else h...

Carracido by L4 Transporter
  • 2287 Views
  • 1 replies
  • 0 Likes

delete ikemgr.log without impacting existing VPN tunnels

This file is getting too big for me and it takes forever to search for things in that file. I would like to purge/delete this file WITHOUT impacting existing VPN tunnels. I want to be able to debug VPN tunnels later on as well. 1- delete debug-log mp-log file ikemgr.log2- debug software restart process ikemgr Is this going to impact EXISTING V...

dtran by L4 Transporter
  • 5241 Views
  • 4 replies
  • 0 Likes

Resolved! Routing problem

I am configuring a new AP-850. MGT port works fine and I can access the Internet. Now, I configure ethernet1/1 to access the Internet. I also configure the routing. But can't ping 8.8.8.8. Do I miss something or how do I troubleshoot it?

pa-5.JPG
pa-6.JPG
boblin by L2 Linker
  • 6751 Views
  • 7 replies
  • 0 Likes

Resolved! Add production firewall to panorama

Hi All,We are using PAN Firewalls on 9.1.5We have 2 HA pairs both in production with around 100 policies on each and Global Protect on 1 pair. We have purchased Panorama VM and want to add the firewalls to Panorama. Now I did find some previous articles on this but not sure whether there is a tried and tested way. And would that work for firewal...

VPN Problem - Ping from Loss

Good afternoon; Currently I have a PA-820 device which is updated to the latest version 9.1.1 of PanOS. Every time I am connecting to the VPN, the ping is lost after a few minutes. I'm checking and the VPN is still connected, even if I connect to a remote desktop before it goes down I keep the connection even after. But if I want to connect to a...

04-01--2021_17-01-57.png
04-01--2021_16-57-55.png
04-01--2021_17-06-09.png

Resolved! Change management ip of cluster nodes.

Hello, We have 3200 series HA cluster . The requirement is to change the ip addrrss of management interface of both the nodes.( Note we are not changing the ip address of panorama ) All the required rules and routes are in place .Can we change the ip address remotely while still logging through the management interface ( old ip). Via the command...

Problem accessing internet when install globalprotect Mac

Hi.I've updated my macbook to MacOS Big Sur. After that, I had internet issues. So, I uninstalled the globalprotect and the internet returned normally.Now, I installed globalprotect again and my internet is not working again. This problem occurred when I allow "System software from Palo Alto Networks was blocked from loading" in security and pri...

Condina by L0 Member
  • 2680 Views
  • 1 replies
  • 0 Likes

Migrating from 5060 to 5220

Hi, We are planning to migrate from 5060 to 5220 both should be in PAN-OS 8.0.7 releases.As per article at https://live.paloaltonetworks.com/t5/Management-Articles/Hardware-Migration-from-PA2000-to-PA3000-or-PA5000/tac-p/156354#M4307 taking device state from older platform and importing to the new one should work.Has any one done it and experie...

IKEv2 - Unexpected ipsec key delete event

Hi All, I'm a medior network engineer who just got into a new position where I deal with PA FWs. I face the following issue now: There is an IPSEC site-to-site VPN between my PA-850 (ver. 9.1.3) and a remote FW (I'm not sure about the remote device type). I see strange behaviours. Yesterday 3 pm the rekey happened. It finished with ikev2-nego-ch...

olloczky by L1 Bithead
  • 7283 Views
  • 2 replies
  • 0 Likes

I'm looking for a device concurrent connection number adjustment function through session management

HelloI'm using PA-5050 now. I am looking for ways to prevent multiple users from accessing the equipment at the same time through session management.I thought I could do it on the Device-session tab of the WebUI, but I don't think there are any related functions.If you haven't found it, I'd appreciate it if you let me know which menu you can tak...

Resolved! Don't see HA1 and HA2 ports

I am following this article "How to Configure High Availability on PAN-OS" to configure HA on our new PA-850. I don't see HA1 and HA2 ports. Or where I can configure HA interface?

ha1.jpg
boblin by L2 Linker
  • 7768 Views
  • 6 replies
  • 0 Likes
  • 24337 Posts
  • 124 Subscriptions
Labels