General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4254 Views
  • 0 replies
  • 0 Likes

User grouping firewall policies for all firewalls

Hi all,I like to ask if it is possible, and and hot to build a scalable solution for AD grouping info to all firewalls managed by panaroma so that they can create firewall rules based on user id and grouping. Current environment I am testing:1 panorama1 VM firewall configured as standalone master device in a device group. It queries AD, look in...

Resolved! Deny Facebook Posting

I've been playing around with trying to block Facebook posting but allow all other access to Facebook. I setup a deny rule for the 'facebook-posting' app and then setup a rule below it allowing 'facebook' but, this doesn't seem to stop posting. The logs don't show any traffic for 'facebook-posting' so wondered whether this will only work with SS...

Ash2k by L2 Linker
  • 7204 Views
  • 3 replies
  • 0 Likes

Resolved! Access is denied. EDU-110 why?

Hi, I am new to Paloalto network. I really like EDU-110 training which give a great opportunities for people to learn about Paloalto firewall.I don't understand why I got a "403 - Forbidden: Access is denied." when I tried to access EDU-110. I was 70% there .. some day work and some day don't ? Any idea? Thank you

External/Untrust IP's showing up as Internal/Trust

I am at a complete loss as to what I am seeing. I have PA-3250's running 9.1.2 code in L3 mode. The interfaces are split up into 2 aggregated ethernet interfaces, each using subinterfaces (ae1.706, ae1.707, ae2.699, ae2.698, etc.) When looking at traffic logs I see my interfaces assigned to ae1.706 and ae1.707 sourcing traffic from my trust zone...

lost access to the GUI after installed a certificate

I have installed a certificate that was working fine with my firewall, but suddenly I lost access to the GUI of the firewall.I tried what is mentioned here in the link below with no luck.https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cli0CAC

Resolved! wildcard certificate for log forwarding app

Hi All, We are doing a POC for prisma access, customer wants to test log forwarding app and since they have wildcard certificate they want to use it.Can we use wildcard certificate for log forwarding app and is there any limitation/caveats in using wildcard certificates.

HA1 showing down

HA1 is showing down, but HA1 Backup and HA2 are showing up. FWs recently configured by contractor who has left. Configuration appears correct. Any suggestions?

Resolved! How do I add disk space to Panorama?

We have had Panorama running but we want to add disk space to it. We have added the disk space to the VM but how do I actually get Panorama to recognize it? version 4.1.6

JeffTQT by L2 Linker
  • 5672 Views
  • 3 replies
  • 0 Likes

suspend both firewall

What would happen if you suspended both of your firewall in an active/passive HA configuration? Starting with suspending the passive firewall first and then the primary firewall.

jdprovine by L4 Transporter
  • 10120 Views
  • 9 replies
  • 0 Likes

PR_END-OF_FILE_ERROR in firefox

I am having trouble with https://support.microsoft.com in firefox and getting this message. It works fine in chrome though, After i disable decryption for it, it works fine in firefox as well. Why it is breaking in one browser with decryption enabled. Maybe there are other sites as well that i yet don't know are breaking as well for same reason.

image.png
raji_toor by L4 Transporter
  • 4602 Views
  • 2 replies
  • 0 Likes

GlobalProtect Pre-Logon NULL issue

Trying to setup new config for pre-logon, seems to be not working. I am getting machine certificate null error. First i was using internal PKI but then i found this KB and i was hitting the same issue.https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClR8CAKI then tried to setup with self generated certs, while i have ask...

image.png
image.png
image.png
image.png
raji_toor by L4 Transporter
  • 13198 Views
  • 12 replies
  • 0 Likes

Resolved! Site to site tunnel routing issue

I have 2 ISP. My site to site VPN is configured at on 1/10 (ISP A).I want to move my all vpn to other isp1/9(ISPB). Once i change is interface from ike gateway and add the virtual route toward (ISP B) tunnel is up but traffic is not passing through tunnel.when i ping from my PC toward destination ip traffic is still passing via (ISP A). When i ...

How to Collect HTTPS on PA-3020?

Hi.It's a question about my client's request.The customer is using PaloAlto Pa-3020 (PAN-OS 7.1.23), and wants to collect https information (log) through the firewall. The customer told me, "I (customer) know that you need to install a private certificate on each PC to collect HTTPS."I looked up related information in Tech Docs, but I couldn't f...

Resolved! Two ISP connections - one primary / one guest network

Hello,Today we have one interface designated as a WAN interface that manages our IPsec tunnels, GP Portal/Gateway, NAT for Websites, and business web browsing and needs. We have a second internet connection that we use for a guest network that goes through a really old Sonicwall (Different IP range/provider from our main WAN (untrust) link). I...

cmateam by L3 Networker
  • 12145 Views
  • 8 replies
  • 0 Likes

SIP Trunks failing

Hi All, Im a Telephone system installer and have installed a system with SIP trunks which authenticate with the public IP (not register user name/password)The SIP trunks remain working at all times for outgoing fails after a time normally about a day. the firewall is a palo alto PA220 the SIP provider tells me they are trying to communicate on a...

palo alto.png
  • 24362 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels