General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4107 Views
  • 0 replies
  • 0 Likes

9.0.9-h1 for Panorama?

I am looking to upgrade our VM Panorama devices from 9.0.6 to 9.0.9-h1 but whilst I can 9.0.9h1 via Panorama>Device Deployment>Software I cannot see it available under Panorama>Software. Does that mean that it is not available for my device?

StuartS by L1 Bithead
  • 3089 Views
  • 1 replies
  • 0 Likes

GlobalProtect Pre-Logon setup uses multiple IP addresses

I have setup GlobalProtect with Pre-Logon configuration, but between the "pre-logon" status and "post-logon" status of the same computer I am getting 2 different IP addresses. For example, during pre-logon I get 172.16.4.201, but as soon as a user logs into Windows I get 172.16.4.200. Is there any way to keep the IP address the same between th...

CTW1983 by L2 Linker
  • 7333 Views
  • 6 replies
  • 1 Likes

Timeout when connecting to Azure

I seem to be having an issue where the microsoft_graph_secapi output nodes aren't succesfully connecting to Azure. I don't know what I could have possibly configured wrongly to cause this.

IsaacKuf_0-1594283370776.png
IsaacKuf by L0 Member
  • 3547 Views
  • 2 replies
  • 0 Likes

PA-VM deployed in Bluvalt cloud (openstack)

Dears,I'm new in paloalto firewall. We deployed PA-VM in our provider Bluvalt cloud (openstack) and we need to use vpn site to site tunnel with another provider. I will be grateful if anyone can help us to make the settings from the beginning.

UserID 8.02 and Windows 2016 server problem

Hello I know that on this forum few peoples reported that this configuration working (but still isn't supported). I moved config from my old userid server to new one (everything typed from keyboard) but when I try to start UserID I got error: 05/30/17 14:05:00:193[ Info 1213]: New connection 127.0.0.1 : 55295. 05/30/17 14:05:00:209[ Info 1286]...

_slv_ by L4 Transporter
  • 2810 Views
  • 1 replies
  • 0 Likes

Virus/Win32.WGeneric.akrgog

Hello,I'm getting a Threat Detection - Virus/malware identified by the name "Virus/Win32.WGeneric.akrgog" when a user tries to open a particular PDF file. When looking at the Threat log I can see the PDF file being blocked and identified as a 'Virus.' In the same session, I can also see additional files with the extension .aspx being allowed. I ...

GlobalProtect Internal not getting User-ID

I have internal globalprotect setup on a system, but i don't see any user-ID associated with that system IP. It is configured to save credentials. User-id is configured on zone and interface management profile as well.

raji_toor by L4 Transporter
  • 18935 Views
  • 9 replies
  • 0 Likes

How to create policy between vsys.

Hello Team,New to palo alto..and need one help. Below is my topology.I want 10.1.1.0/24(vsys1) to communicate to 10.2.2.0/24(vsys2) and the route is via L3 device.What should be my policy here? Shall i create below policySource Zone-Zone ASource IP-10.1.1.0/24destination Zone- InsideDestination IP-10.2.2.0/24Service -AnyAllow And one more fromSo...

topology.png

User grouping firewall policies for all firewalls

Hi all,I like to ask if it is possible, and and hot to build a scalable solution for AD grouping info to all firewalls managed by panaroma so that they can create firewall rules based on user id and grouping. Current environment I am testing:1 panorama1 VM firewall configured as standalone master device in a device group. It queries AD, look in...

Resolved! Deny Facebook Posting

I've been playing around with trying to block Facebook posting but allow all other access to Facebook. I setup a deny rule for the 'facebook-posting' app and then setup a rule below it allowing 'facebook' but, this doesn't seem to stop posting. The logs don't show any traffic for 'facebook-posting' so wondered whether this will only work with SS...

Ash2k by L2 Linker
  • 7137 Views
  • 3 replies
  • 0 Likes

Resolved! Access is denied. EDU-110 why?

Hi, I am new to Paloalto network. I really like EDU-110 training which give a great opportunities for people to learn about Paloalto firewall.I don't understand why I got a "403 - Forbidden: Access is denied." when I tried to access EDU-110. I was 70% there .. some day work and some day don't ? Any idea? Thank you

External/Untrust IP's showing up as Internal/Trust

I am at a complete loss as to what I am seeing. I have PA-3250's running 9.1.2 code in L3 mode. The interfaces are split up into 2 aggregated ethernet interfaces, each using subinterfaces (ae1.706, ae1.707, ae2.699, ae2.698, etc.) When looking at traffic logs I see my interfaces assigned to ae1.706 and ae1.707 sourcing traffic from my trust zone...

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels