General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4115 Views
  • 0 replies
  • 0 Likes

Add backup GlobalProtect portal to GlobalProtect client

On our PA-1410 under Network - GlobalProtect - Portals - each of our portals (one on each interface for each ISP) - Agent - Agent Config - External Gateway I added gp2.domain.com to go along with gp.domain.com. I was thinking (hoping) that would update the GlobalProtect client to add the gp2.domain.com to the GlobalProtect client as a failover ...

VPN tunnel flapping after the 11.1.4-h7 upgrade

We have upgraded our FW to 11.1.4-h7. After the upgrade the IPSEC tunnels were working fine. But from the past 2 days we are observing that tunnels are flapping and one of the tunnel is down due to phase-1 negotiation failure due to timeout. Does anyone else facing the same issue? or faced the issue earlier like this?

PAN-OS 10.2 preferred release Vs. vulnerabilities

Hello everyone, maybe this is a silly question, but as far as I can see the current PAN-OS 10.2 preferred release dates back in november and does not include fixes for recently discovered vulnerabilities (CVE-2025-0108, for example). I usually put a vulnerability protection profile in front of my management networks, but this vulnerability i...

grenzi by L3 Networker
  • 1923 Views
  • 4 replies
  • 0 Likes

GlobalProtect requires token twice - Possible RSA inconvenience

Hi Community. I have an issue on GP: it makes requests for token twice to get through VPN to my network. I discovered the RSAs feature "Next Token Code Mode", but believe PA (5050 - PAN-OS 7.1.10) has nothing to do when a NTC is requested, so I recommended my customer to open a case with RSA. Instead, my customer told me RSA answered this: https...

gastong by L0 Member
  • 16728 Views
  • 7 replies
  • 1 Likes

Lab license for Palo Alto

How hard is it to get a lab license from a Vendor such as CDW. Last week I went to their website and purchased 'PAN-PA-410-USG-BND-LAB'. Today I looked and saw it as canceled. Still trying to find out why it was canceled. The cost of $104 which I put on my credit card

Resolved! Anyone experiencing slow websites with PANOS patched for CVE-2024-0012/CVE-2024-9474?

Is anyone else experiencing intermittent slow website access with the recent hot patches for CVEs? Currently running 10.2.9-h16 and having intermittent issues with some websites, some users, while others have no issues. I can't find anything in the PaloAlto logs that indicate any problems (no threat, AV, reset connections, decryption failures, e...

Resolved! CVE-2025-0110

"Can anyone confirm whether CVE-2025-0110 affects Cloud NGFW firewall? Any relevant details would be appreciated." Cloud NGFW for AWS Cloud NGFW for Azure https://security.paloaltonetworks.com/CVE-2025-0110

Suraj639 by L0 Member
  • 1190 Views
  • 1 replies
  • 0 Likes

Upgrade path question

We have a second Palo Alto that we want to upgrade and then use as a High Availability device to work with our current operational firewall. It had been used before, but is currently offline. I was following the upgrade path from 9.0.13 to 10.2.13-h4 (latest version I could find for the 10.2.* family). I was experimenting to see what worked du...

transfering license without a CSP account

Hello,I hope someone can help me.I tried to find myself the answer but looks like I'm getting a chicken-and-egg problem.To accelerate the learning curve, I've bought a PA-440 on ebay.To transfer the device, I need a CSP account but since I don't have yet a device, I cannot create an account. How can I create an account in these conditions?We int...

Antivirus mismatch without license

We have a cluster of firewalls with an antivirus mismatch alert. The thing is that there is no antivirus license.This issue happpened after one of the nodes went down and we had to perform a factory reset. We are seeing this by cli: av-version: 0 av-release-date: threat-version: 0 threat-release-date: 2025/02/10 19:10:10 CET I know it does not a...

Secondary IPSec tunnel with Prisma Access always down.

Dear community! I have a dual S2S VPN configuration with Prisma Access with static route path-monitoring as well as tunnel monitoring. The secondary tunnel is always down, only comes up when primary goes down. Do you know if this is expected behavior? Thanks in advance!!

Carracido by L4 Transporter
  • 3318 Views
  • 3 replies
  • 0 Likes

Feature Request: ECMP Path Monitoring

We are currently using ECMP to load balance to our two ISPs. Which works great. However since there is no path monitoring(Unless you set static routes). If something happens upstream and your peer doesn't go down the PANs will happily keep sending data out that interface without batting an eye. Causing half your customers to be very unhappy. If ...

  • 24335 Posts
  • 124 Subscriptions
Top Solution Authors
Labels