General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4244 Views
  • 0 replies
  • 0 Likes

Resolved! New Install Checklist

Hello -Has anyone seen or created, that they'd like to share, just a general checklist of information to collect and steps to do a new install?

Resolved! Problem URL-Filter onedrive urls

Hello everybody, I use url-list from urlhaus. If I test some entries, I got a problem with onedrive-urls like this: onedrive.live.com/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fiThis url should be blocked by urlfilter on the firewall. But it was not blocked. I can download the file. Also I can not se...

IKEv2 keepalive tuning

IKEv2 on PA has built in keepalive mechanism, but it can only act if the communication is lost for more than 5 minutes: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClgcCACAfter testing it out, about 7-8 minutes passed until Palo Alto detected lost peer and did reset of the tunnel.That's happening due to built in alg...

nikoo by L3 Networker
  • 6902 Views
  • 1 replies
  • 0 Likes

Configd Crashing every 50-60 Minutes; Panorama M-500, PAN-OS 8.1.15

Morning All-I wanted to go ahead and try dropping a post here in hopes that someone else has experienced either an identical or very similar issue. There is a lot info that could be provided but I'll start with the basics: -Configured in HA pair with another M-500.-Both Panorama appliances also configured as log collectors.-Both appliances are ...

Screen Shot 2020-08-04 at 11.21.49 AM.png

Resolved! What happens to active sessions in Dual ISP Scenario

We have 2 ISP's, primary is down right now. Both ISP's connect to different interfaces. When Primary comes up, the interface will be different for outgoing/incoming traffic. Will the active rdp/web sessions/GlobalProtect/IPSEC tunnels drop when primary link becomes active again. Or will it be seamless.

raji_toor by L4 Transporter
  • 3766 Views
  • 2 replies
  • 0 Likes

DataPlane Restarted unexpectedly

As we have seen that in system log the dataplane is Restarted. When i run this command show system resource follow i can see that cpu utilization goes 100%. Please suggest as i run 8.1.7 PAN-OS version.

Joshan_Lakhani_1-1596621967579.png

DHCP client identifier 61 return VLAN id

I am using my pa-850 as a DHCP server on a small office LAN. I need to assign a VLAN to the phones and another VLAN to the computers. The phones are sending Option 61 Client identifier as part of DHCP Discover. How do I configure DHCP custom options to use the Option 61 value and return a specified VLAN ID?

Video problems

hi, im having problem with videoconference LIFESIZE, the calls work but we cannot see the video. We have a rule any any permit and we dont know whats happening. I read about disable statefull packet inspection in our firewall. how can i do this in PA??

Customer Support Portal 2FA Disable

In trying to improve the security of our access to CSP, I enabled 2FA at an account level. In testing, it was not as configurable as I wanted, so I disabled it for the account. In attempting to disable it for my own account (as required after enable/disable for the account), my profile change is not saved. I will get the "changes saved" messa...

cdwing by L1 Bithead
  • 3124 Views
  • 1 replies
  • 0 Likes

Resolved! How to clear global protect previous users

I configure global protect users in address about 1000 for future plan.but users is only about 200.when gp users connect, it cannot get old IP address. Get new IP address.How can I clear previous users and IP address.

zayyar by L0 Member
  • 6932 Views
  • 2 replies
  • 0 Likes

Minemeld Gridmeld Cisco ISE integration

Hi, recently we configured Minemeld with Gridmeld to fetch SGT-IP bindings from Cisco ISE over RestAPI (PxGrid). Minemeld is pushing the SGT-IP Bindings correctly into the dynamic object groups. However, we noticed the IP to tag bindings are sometimes missing from the Palo Alto (checked with "show object registered-IP all") and 1 minute later ad...

Isssue with EDL updates

We have already configured the EDL feature in Palo Alto but the following behavior of Palo Alto has been observed while accessing the digital App and digital.com from the internet using 03 different blacklisted public IPs by Spamhaus (which is also used by Palo Alto). Two of them are allowed while one IP is blocked, while the Palo Alto Spamhaus ...

IP 1.JPG
IP 2.JPG
IP 3.JPG

panwdbl request

I have few Public IP which is blacklisted by there respective publishers, but it's not listed to panwdbl.appspot.com list. How I can send a request for updating the those IPs

PAN-ENT-PLAT-ESA-TT-1YR

Hello Dear All, Can you provide me with specification documents for these part numbers:PAN-ENT-PLAT-ESA-TT-1YR, PAN-ENT-PLAT-ESA-TT-3YR, PAN-ENT-PLAT-ESA-TT-5YR?Appreciate your fast responseThanksAhmed Sabry

AAhmed by L1 Bithead
  • 5714 Views
  • 6 replies
  • 0 Likes

Resolved! strange problem only with a full tunnel on one gateway

I have two gateways where users are predominantly using split-tunnels. When I connect to Gateway A with a full tunnel, I can load public webpages and intranet sites. When I connect to Gateway B with a full tunnel, I cannot load public webpages like cnn.com, traffic logs show application incomplete to untrust zone, and traffic to the trust zone ...

  • 24359 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels