General Topics
Showing results for 
Search instead for 
Did you mean: 
General Topics


Thank You for Filling Out the LIVEcommunity Experience Survey!

If you've visited LIVEcommunity anytime recently, you've probably seen a pop-up asking for your feedback. We've deployed this survey since April 2020 for new and returning visitors alike as a way to gather feedback from our users. 


In the past six


jforsythe by Community Team Member
  • 1 replies

Problem adding zone to tunnel

I'm trying to add a zone to a tunnel interface. I can create the tunnel and configure it via panorama defining virtual router, vsys and zone to be applied via template. But when I check the devices where it should be applyed  both zone and virtual ro


ibge by L1 Bithead
  • 1 replies

Resolved! moving policies and objects to another device group

Policies and objects are currently in the wrong device group. able to move everything successfully except for the address objects. i feel the move is pretty self-explanatory, but i have taken the time to read the user guide and still no luck. is ther


SFP Compatibility



I have got 3 firewalls. 5050 and (3020-1 & 3020 -2 HA pair). We are trying to replace the core 6500 switch with meraki 425. and we have got the MA-sfp-10gb-sr and we need to look for supported sfp in palo side. I found one good fit as PAN-SFP-PLU


Minemeld Installation on RHEL 7.4

Dear Team,


I have successfully installed minemeld on RHEL 7.4 and Am able to access the web console from Local Machine but am not able to access from Network.  


Please help if anyone faced the same issue.


Thanks and Regards,



Virtual IP address in HA- Active Passive Mode

Hi Experts,


I've query about High Availability Active-Passive. As we know, interface IP addresses are same on both the firewalls and when Active device goes down, secondary firewall will take over by sending gratuitous arp to switches. So switches ca


5250's failing to pass traffic after AV software update




We are on the version 8.1.2 and If I upgrade to the latest ‘Applications and Threats’ version,  currently 8044-4859, and then upgrade AV from 2678-3175 to 2683-3180 all rules fail, and traffic drops through the default deny.


I do not see any par


Bomi by L1 Bithead
  • 3 replies

Resolved! tcpdump - view whole packet in CLI



I know I can capture whole packets (snaplen 0) and select verbose (and verbose ++) output when viewing packet captures with tcpdump on mmt interface.

But can I see whole packet in CLI? Verbose output only seems to add some header fields, I can'


santonic by L5 Sessionator
  • 2 replies

Upgrade to PAN-OS 8.0.11 causes device restart loop

I performed an upgrade on a HA Pair of PAN-5220 firewalls from PAN-OS 8.0.7 to PAN-OS 8.0.11 and once the firewalls booted up they would run for about 5 minutes, alarm (red LED on device) and then reboot, over and over and over.  Even with only one f


PA-3260 High Availability

We are migrating our Active-Passive PA-500 enviroment to an Active-Passive PA-3260 enviroment.

In the PA-500 for the High Availability Control Link (HA1) was ethernet 1/7 and for the Data Link (HA2) it was ethernet 1/8.

For the PA-3260 I can use HA1-A


ZEBIT by L3 Networker
  • 1 replies
Top Solution Authors
Top Liked Authors