General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4246 Views
  • 0 replies
  • 0 Likes

TLS 1.3 Encrypted SNI No-Decrypt URL Categories

In non decrypted tls 1.3 traffic, how is the firewall in 10.0 seeing the URL that a user requests and how is it enforcing that category? I've read that tls1.3 encrypts the SNI field, which from my understanding, is the primary way the palo firewalls read and implement URL categories on non-decrypted traffic. If we don't decrypt on certain tr...

Sec101 by L4 Transporter
  • 9241 Views
  • 2 replies
  • 0 Likes

Panorama VM running on ESXi 6.7?

Dear community, I had a Panorama VM running Pan-OS 8.1 without any issue on top of VMware ESXi 6.7, after upgrading to 9.0.4 the host is rebooting the VM from time to time with the following error log:"..........reset by vSphere HA. Reason: VMware Tools heartbeat failure. A screenshot is saved at......" The screen-shot taken when the VM crashes ...

Carracido by L4 Transporter
  • 4429 Views
  • 2 replies
  • 0 Likes

Overriding existing User-ID mappings with Captive Portal to elevate privileges

Override the learned credentials through User-ID agent or captive portal for troubleshooting or additional access without involvement of a firewall administrator. (Without clearing from CLI). For example, IT admin is at users place and need to override current internet privileges to access Youtube for troubleshooting an issue. This can be achie...

How to migrate logs from M-100 to another M-100 in mixed mode by moving the logging disks

the customer have an M-100 do RMANow they need to replace the hard disk with the new M-100.I refer to this articleHow to migrate logs from M-100 to another M-100 in mixed mode by moving the logging disks.nine thousand three hundred and sevenCreated On 09/27/19 23:00 PM - Last Updated 05/19/20 20:46 PM I have some questions.Question 1: I don't k...

Felixcao by L3 Networker
  • 2187 Views
  • 1 replies
  • 0 Likes

User-ID Based Overide

Hello Everyone, We are looking a solution in a case wherein PAN-OS firewall are deployed with only USER-ID based policies for different group of orgranizations. Now everyhintg is working as expected but IT Engineers are getting trouble in Installing/Downloading softwares/pacthes from their windoes login. In that case they logged out from user a...

Global Protect with Client Certificate Authentication

Hi all,can somebody tell me if there is a manual or howto,which describes in detail how to confígure this.I read the "Quick Start Guide GP" and this threadhttps://live.paloaltonetworks.com/message/7126But I'm not getting it t work. When I connect to the portal sitewith a browser I'm getting the message "Valid Client Certificate Required".But I i...

indevis by L2 Linker
  • 4231 Views
  • 2 replies
  • 0 Likes

Configure Tacacs+ server on linux

Hello, i am configuring tacacs+ on VM-300, but there is no configure option "Device - Access Domain", so i think the VSA should be added into tacacs+ server config. These VSA are mention here, https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/authentication/authentication-types/tacacs.html#ida74c523c-3a49-47c1-a7eb-717efaf41eea I am not ...

Golbal pormat

Pelase help me I New members from Afghanistan I don't have information about Live ccommunity Please help me I want global primate username and paswward

Doubt about a counter: pkt_inconsist

Hello, i am seeing this counter increasing and I am not sure if i should be worried: > show counter global filter delta yes Global counters:Elapsed time since last sampling: 0.15 secondsname value rate severity category aspect description --------------------------------------------------------------------------------pkt_recv 289 19266 info p...

BigPalo by L4 Transporter
  • 2876 Views
  • 1 replies
  • 0 Likes

Questions about Ignite 2020?

We hope that you are enjoying Ignite 2020 so far! A lot of amazing sessions took place yesterday on day 1. We know you may have some questions or want to learn more about how you can engage with the LIVEcommunity. Please reach out to us down below! We can't wait to hear from you!

jennaqualls by Community Team Member
  • 3976 Views
  • 1 replies
  • 2 Likes

Custom URL Limit?

Hello~I am looking around for custom URL Limit in support siteI got information each box entries is differentRefer to InformationMax number of custom URL categories (PAN OS 4.1):PA-5060 PA-5050 PA-5020 PA-4060 PA-4050 PA-4020 PA-2050 PA-2020 PA-500 PA-20050 50 50 50 50 50 50 50 50 50Max total entries - allow/block list and custom categories (PAN...

virtual wire default-vwire is missing one or more interfaces

Hello, I'm new to Palo Alto firewalls but I need to know it for work purposes. I am currently working on a Palo Alto PA-220 Firewall. I'm at the very beginning stages of this configuration. I keep getting an error message everytime I try to configure my first internal LAN port (ethernet1/2). This happens after I click the "commit" button. Pleas...

Commit Error.JPG
finsfree by L0 Member
  • 35305 Views
  • 6 replies
  • 0 Likes
  • 24359 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels