General Topics
Showing results for 
Search instead for 
Did you mean: 
General Topics


Join Us for a Tech Deep Dive Miniseries!


Stop Zero-Day Threats in Zero Time with Nebula PAN-OS 10.2.


Join us live for an in-depth look at the latest advancements in cybersecurity, best practices, tips and tricks, demos and
more to protect your business and defend against threats in real


jforsythe by Community Team Member
  • 3 replies

Is it secure ?

Hello all

We have configured GP REMOTE ACCESS VPN with OTP  authentication.

Ones we try to connect to Portal it failed to pass at the first time only second time.In Radius server we see that it tries to authenticate first the Ldap account then VPN acco


Radmin_85 by L4 Transporter
  • 3 replies

Resolved! ha syn failure - url filtering


on passive PA we are seeing 


( description contains 'No synching file to peer because local state is not Active (Passive).' )


is this normal?

MP18 by Cyber Elite
  • 2 replies

Cannot Sync Running Config in HA active/passive

Hi All,


I have a PA3020 with 7.0.5-h2 PAN-os version.

I have tried different times to sync manually the running config on passive member without success.


I can clearly see from the Active Member's "ha_agent.log" these errors:




Resolved! MineMeld and Office 365

I've used MineMeld in the past and I've been very happy with all of it's functions.  Recently, I've started a new job and I've recommended MineMeld as a solution to get O365 IP's into the firewall for writing policy.  Microsoft announced on April 2nd


Resolved! Changing Firewall Rule Names (Security Policies)

I need to rename a whole bunch of firewall rules (Security Policies).

Ive done a search here and looked in the manual; I think I know the answer.

I can change Firewall / NAT rule names as needed? There will be nothing else I have to change right? This


choff123 by L3 Networker
  • 3 replies

Resolved! 8.1.4 & TLS 1.3?

This link ( says that PAN-OS 8.1.4, PAN-OS 8.0.14, and PAN-OS 7.1.21 will fix a TLS issue.  I don't see any mention of this in the 8.1.4 addressed issues page though.  Do we know this is


Force URL filtering for AnyConnect Users?


Hello - I'm looking for some way to force AnyConnect VPN users to go through the PAN which is on the inside for URL Filtering.

A couple of caveats:

- Can't move to GlobalProtect because of ISE integration with AnyConnect.

- Want to use PAN for URL Fi


zac_hg by L1 Bithead
  • 0 replies

Resolved! Dual ISP VPN failover with static route path monitor

Now that we have newer features like static route path-monitoring, is there a new recommended configuration for Dual ISP with VPN failover?  I'm thinking SiteA (Dual ISP) to SiteB (Dual ISP) with IPsec VPN both using a single VR. 

I assume it will be


Palo Alto Mgmt Port Issue

Dear Friends,


We are facing a issue that currently we are unable to console to firewall device. But traffic is passing through active firewall. Status is HA1 backup= Down


Please advice 




Resolved! logs for Intelligence Sharing and telemetry

is there any way i can find from cli or from web gui that confirms my PA is sending all telemetry   data ?


any where in PA  cli i can find the logs or data send to Telemetry?


where it  send this data to?


is this function performed by the MP of the PA


MP18 by Cyber Elite
  • 2 replies

URL Filtering block websites?

I have a URL filter profile with a list of URLs set to block (under Objects  Security Profiles > URL Filtering), which is applied to security group profile. 

However none of the URLs are being blocked. 

Is there something I should check to confirm this


URL Filtering different with browser and application



We have a server, from where the user wants to go to, for example,

The certificate from the website has a CN *


We dont have decryption for URL Filtering. In the URL Filtering category, we have allowed

The u


global protect clientless NAT

We are configuring global protect.

The scenario is we use one armed global protect, because we have it connected behind our ASA firewall with functions as boundary.


As we have several scenario's we want to use the client and clientless version.


For th


Top Liked Authors