General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4246 Views
  • 0 replies
  • 0 Likes

Resolved! Panorama

Just need to know is there a max size for a Panorama log file and if so what is that size, currently we are at 1.6TB and want to make sure we are not over the limit and into possible file corruption scenario

dttech by L1 Bithead
  • 2988 Views
  • 2 replies
  • 0 Likes

Hyper-V Compatibility issues

Hey,I'm running a 3 Node S2D on Server 2019.Currently migrating from VMware Hypervisors which has the Palo Alto running on it, instead of doing a Migration\Conversion i want to build a new server. I'm trying to setup a Palo Alto VM-300 Series Virtual machine which comes as the VHDx File.I'm using SCVMM and select use an Existing Virtual Machin...

System alerts

Hello Team,I am getting system alerts in my firewall below is the error:-PAN OS - 9.0.6Disabled applications in vsys1: cip-ethernet-ip-disable-io cip-ethernet-ip-disable-sfc cip-ethernet-ip-enable-io cip-ethernet-ip-enable-sfc cip-ethernet-ip-read-mod-write cip-ethernet-ip-read-tag cip-ethernet-ip-read-tag-frag cip-ethernet-ip-run cip-ethernet-i...

Resolved! Global protect static IP

Hello Team, Is there any way to configure static IP for VPN(Global Protect) users. Example:-I have an IP pool - 192.168.1.0/24User A, UserB, User CAuthentication profile is (Active directory)When user A will connect through the external gateway for this user IP address should be assigned - 192.168.1.10When user B will connect through the externa...

Resolved! PA-5020 to 5220

we are planning to upgrade ur existing PA-5020 to bigger boxes. our current 5020s are struggling to handle the ssl decryption and it sometimes give ''Dataplane CPU under severe load'' logs on busy days. I heard 5200 series are specfically designed for decryption . However I have 2 questions here:1.What can be my best options? PA-5050,506,5220 or...

Inbound SSL decryption - Digicert

If inbound SSL inspection when using Digicert certificate is not supported, what is the alternative. We have many web-servers using same wildcard cert used for GlobalProtect and wanted use this same certificate but it doesn't work. Is there any other mechanism to implement inbound SSL inspection.

raji_toor by L4 Transporter
  • 12695 Views
  • 15 replies
  • 0 Likes

Resolved! 40031 Threat Exception

What I am wanting to know is if I can add a range of IP addresses to a vulnerability exception.This would be the entire 1-254 range, rather than 1 IP address at a time. I have already checked the links below and they talk about adding IP addresses one at a time as an exemption.Rather than allowing the vulnerability for the entire site, I would l...

New setup PA-VM Active/Active external routing not working on standby

I have a pair of VM 300s in active/active mode and everything is running OSPF. PA1 is primary and PA2 is standby. I noticed I was missing a bunch of traffic for anything going to the standby router. I can ping every interface on the standby sourced from the loopbacks on each router but I cannot route through the standby.The OSPF table shows both...

Capture1234.PNG

Email Link Analysis - does it look at all emails?

I am curious to know if the organization I work at gets a blast email to 500 employee's from an external B2B marketer does the wildfire analysis get performed on all 500 identical emails or does it simply do it once knowing the email and links are identical.

joecbrown by L1 Bithead
  • 10587 Views
  • 12 replies
  • 0 Likes

Resolved! Palo Alto lab in VMware Workstation

Hi guys,I need some help with configuring network in VMware Workstation and Palo Alto. I tried to build VMware lab using both Udemy and CBT Nuggets video courses:The problem is that I can't have my Palo Alto to have an access to the Internet. It doesn't matter what type of network adapter I use NAT or BRIDGE. Below are my network settings:Networ...

4kusnik by L1 Bithead
  • 24067 Views
  • 14 replies
  • 0 Likes

Panorama: cannot use in templates objects from DG

Dear Community, I have a Panorama with several firewalls in a device group under the share one.I have several templates and I cannot select any shared object from DG into any part of template configuration, for example adding an address object as an interface´s address or into the user ID´s include list. I´m using super admin account to attempt ...

Carracido by L4 Transporter
  • 2704 Views
  • 1 replies
  • 0 Likes

Pre-logon for specific user only

My requirement is that some user should use Pre-logon and other should use User-logon. Currently all users are using only user-logon mode. Is it possible to use both mode in global protect, because we have to call client certificate profile on globally for pre-logon user?If yes can you please guide me how can i archive this and Is there any dow...

gp1.png

Allow only MS Intune and Windows Update - block all internet access

HI, I am after permitting only MS Intune and Windows Update - block all internet access.I have followed the custom URL filtering as mentioned in the link below:https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRfCAK&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetailCreated the custom url filte...

kams19_0-1597318380297.png
kams19_1-1597318419497.png
kams19_3-1597318525650.png
kams19_4-1597318560001.png
kams19 by L1 Bithead
  • 14076 Views
  • 8 replies
  • 0 Likes

Resolved! disable qos

Hi, I have the below configuration for qos , and there are policies also configured . If I want to disable for sometime , Just unchecking the checkbox under Enabled will help ? Or even after un checking the traffic will fall under class 4 ? Or do I need to remove or disable all the policy ? Thanks

Capture.JPG
simsim by L4 Transporter
  • 4571 Views
  • 1 replies
  • 0 Likes
  • 24359 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels