General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4126 Views
  • 0 replies
  • 0 Likes

GP Split Tunnel with Microsoft O365/Microsoft Teams & GP License

Hello All, It appears that the large list of IPs and domains to completely enable split-tunneling with GP for O365 & Microsoft Teams requires the GP license to facilitate defining domain names in addition to IP networks (which I understand works without a license). Are you able to split tunnel O365 and/or Microsoft teams without a license? ...

jhwarren by L1 Bithead
  • 3733 Views
  • 1 replies
  • 0 Likes

Resolved! User-ID: Is possible to retrieve groups without sever monitoring?

Hello community, I´m sharing with you this doubt you maybe can help me with: I´m only interested in having the group-user mappings and not ip-user mappings. Is this possible? Furthermore, is it possible to retrieve group-user mappings without having to configure the server monitoring? The idea is to configure the LDAP server profile and then the...

Carracido by L4 Transporter
  • 3574 Views
  • 2 replies
  • 0 Likes

Can't connect firewall to network

I'm trying to setup a PA-220 for the first time. I'm able to access the fw via the web interface when I directly connect my laptop to the mgmt port. I'm stuck on Step 11 (https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/getting-started/integrate-the-firewall-into-your-management-network/perform-initial-configuration). I am not able to ...

c_n0te by L0 Member
  • 2761 Views
  • 1 replies
  • 0 Likes

Unable to disconnect Global Protect in Linux machine

Hi Team, I have configured GP using "On demand" method when I tried to disconnect GP by ran the command (user@linuxhost:~$globalprotect disconnect ) getting below error, sweekrit@sweekrit-HP-240-G6-Notebook-PC:~$ globalprotect show --errorUnable to establish a new GlobalProtect connection as a GlobalProtect connection is already established from...

GP disconnect error.PNG
GP odemand method.PNG

Resolved! Names instead for IP address on routing table

Hi there, We have a PA with two Virtual Routers, Internal VR and DMZ-Internet VR. When I type show routing fib virtual-router "Internal VR" for example the forwarding table shows a name for next hop and interface, see the output below: show routing fib virtual-router "Internal VR"id destination nexthop flags interface mtu------------------------...

which answer is right?

A company needs to preconfigure firewalls to be sent to remote sites with the least amountof reconfiguration. Once deployed, each firewall must establish secure tunnels back to multiple regional data centers to include the future regional data centers.Which VPN configuration would adapt to changes when deployed to the future site? A. Preconfigur...

Radmin_85 by L4 Transporter
  • 4212 Views
  • 4 replies
  • 0 Likes

authentication sequence with LDAP and SAML

Hi Community, I have a requirement to have client authentication in globalprotect portal/gateway to have with LDAP first then another profile wich is SAML based. the requirement is to authenticate with SAML profile if LDAP auth fails. But as SAML profile cannot be added in authentication sequence, i cannot take advantage of authentication sequen...

Normalize UIA mappings 8.1.12

Hello, I've searched and found a few posts but I can't seem to find the solution; prior to 8.1 UIA, all users shows up in UIA as domain\username. Since installation of UIA 8.1.12, it's a mix of domain\username and username@domain. It seems that in the firewalls themselves, I've only seeing domain\username so the proper rules seem like they ar...

COlson by L2 Linker
  • 3235 Views
  • 3 replies
  • 0 Likes

creating a trusted certificate for remote vpn

atm my palo-alto 8.0.7 have a remote vpn "Global Protect" that is working fine but with a self signed certificate that gives a warning , can someone please tell me how do i create a certificate for GP and sign it with a trusted party DIGIcert ? what are the steps?

chuckles by L2 Linker
  • 3475 Views
  • 1 replies
  • 0 Likes

Resolved! Query on Panorama mode

We are currently running a Panorama virtual appliance in PANORAMA mode running on the ESXi host. Based on the predictable logs per second (LPS) estimation, we have allocated 16 CPUs and 32GB memory while the virtual appliance initially built up. At the moment, we only have one managed firewall connecting to Panorama and sending logs to the Panor...

  • 24336 Posts
  • 124 Subscriptions
Top Liked Authors
Labels