General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4224 Views
  • 0 replies
  • 0 Likes

Resolved! Polling JSON Format for AKAMAI

I am trying to create a prototype for a Miner that pulls IP's from a JSON formatted file. I have looked at the documentation for setting up a JSON miner (https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-MineMeld-to-extract-indicators-from-a-g...) and this topic similar to my issue (https://live.paloaltonetworks.com/t5/minemeld-discus...

Resolved! How to enforce GlobalProtect Connection for Network Access on iPhone with GP 5.0 App

Hey Guys, i'm currently testing the GlobalProtect App 5 with iOS Deviecs and Airwatch MDM. Everything works great, but it seems like that it isn't important which setting i've selected in the Portal > Agent > App (Settings). I've tried to enforce GlobalProtect for Network Access on iPhone but i can still deselect "connect on demand", so it...

Resolved! Migration without Expedition

HelloIf I wanted to migrate from Checkpoint to Palo with Panorama, but not use Expedition, what would be the general steps? Thank you for your time.

Configure HA1/HA2 command line

Need to configure the following in CLI:Control Link (HA1)Port ha1-a Control Link (HA1 Backup)Port ha1-b Data Link (HA2)Port ethernet1/1 Data Link (HA2 Backup)Port ethernet1/2 Any insight would be appreciated.

PA-5250 Power Supply Question

Do the power supplies within the PA-5250 load share? This is probably a real simple question but I have not found an answer within the documentation yet? Thanks!

B_Turner by L0 Member
  • 3018 Views
  • 1 replies
  • 0 Likes

Resolved! import device state order

Hi,I've done this successfully in the past, but cannot remember the proper order. I have a PA-200 that I want to replace with a PA-220. The PA-220 is in Panorama, its a device group + template. Should I1) configure the PA-220 with basic ip connectivity to Panorama, add the serial add it to the device group, template, push the config and then ...

ce1028 by L4 Transporter
  • 20090 Views
  • 12 replies
  • 0 Likes

PAN-DB URL Version Remains 0000.00.00.000

The firewall is running 9.1.4 (5250). The mgmt interface does not have general internet access so service routes have been configured for the following to use the external interface (internet connected): DNSEDLNTPPalo Alto Networks ServicesURL Updates Policy is created to allow outbound traffic to the internet sourced from the external IP (NAT ...

jlieberman_0-1600970729070.png

Resolved! Palo Alto LACP to Nexus

Hi all, I have an upcoming deployment and I need your inputs here. I will be replacing a fire that is configured in HA Pair with a PA-3220 non HA pair. The core switch of the client is configured as a active-passive (NX-OS). My concern is, can I enable LACP on Palo Alto side and make it a routed interface and assign IP to it and on the nexus s...

Portal not found. Please re-enter or contact an administrator for help

This is a confusing issue because it's NOT happening on other machines within the same network (same ISP, etc). I go as even as far as testing on a virtual on the same machine that is having the issue within the host operating system. I'm not getting this error within the Virtual, but getting it on the host OP that is the same machine. I was ...

difference between nego-fail and lacp-up event

Multiple logs are generated for LACP on passive firewall , but not sure whether this event generated due to layer 1 issue or config issue at switch end. We never faced this king of issue , this log are generated all of a sudden on passive firewall. Looking for exact meaning for below events . PFA image1. Link-down2. nego-fail3. lacp-up there is ...

Deepak_K_0-1601271762681.png
Deepak_K_1-1601271790244.png
Deepak_K by L3 Networker
  • 6040 Views
  • 1 replies
  • 0 Likes

Expressway-E and C and NAT

I am putting in a Jabber system using Expressway-E and C. My Expressway-E server is NAT'd through the PA-3020 and I have a security rule set up to allow the required ports in on the Public address. If I make a call IN from an external Jabber client it goes through fine. If I try to make a call OUT from a phone to a jabber client, the call does n...

Resolved! Firmware Updation A-P

Hi Guys, We have to upgrade firmware of our PA FWs in Active-passive Cluster (It's first time). Referred some online available documents to get familiar with upgradation process but all of them have difference at certain steps (I mean they are not unique). requesting if anyone can share the easy and effective straight forward steps (preferably ...

Jimmy20 by L2 Linker
  • 6440 Views
  • 7 replies
  • 0 Likes

Resolved! Access Denied to Learning Articles

Hi, How do I get access to below link?https://live.paloaltonetworks.com/t5/learning-articles/packet-flow-sequence-in-pan-os/ta-p/56081 I usually get below message when I try to access learning articles on PA. I'm registered as a customer. Any ideas please? You do not have sufficient privileges for this resource or its parent to perform this acti...

Active-Passive Cluster Link & Path Monitoring

Hi All, Referring my prior discussion Subject - "Firmware Updation A-P" , We have below configuration enabled on Link & path monitoring configuration at this moment, have a look on screen shot. Will this be sufficient to trigger auto failover to Passive , if in case we can disconnect / disabled any of the directly connected interface from A...

Link and Path Monitoring Screen Shot.jpg
Jimmy20 by L2 Linker
  • 3372 Views
  • 2 replies
  • 0 Likes

How to allow NTP ONLY to pool.ntp.org

I have a requirement to allow the internal NTP servers to sync with ONLY US.pool.ntp.org. I have tried creating the rule 2 different ways.Create a address object using FQDN for us.pool.ntp.org and use that in the rule destination.This doesn't work as there are like 500+ ips behind that poolCreate a custom URL category for us.pool.ntp.org and us...

  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels