Resolved! GP Always-On disconnect with comment logs
Am I just blind or where do the GP disconnect comments get logged to?
Am I just blind or where do the GP disconnect comments get logged to?
We are currently experiencing a situation in which we are receiving requests to our public segment pool. According to a syslog that Palo Alto sends to our SIEM, many of these IP addresses are part of a botnet. However, when we checked Palo Alto, we did not see this information in the traffic log. The SIEM/Sentinel is enriching logs received ...
When adding ztp firewalls to the Panorama we see the following error in the Panorama´s ztp plugin logs: 403 - Forbidden: Access is denied.You do not have permission to view this directory or page using the credentials that you supplied. Any idea what the problem can be?
Hi AllWe are currently trying to monitor Layer 3 sub-interface bandwidth via SNMP. I've been checking the enterprise MIBs for palo alto, and there doesnt seem to be any such OID. Does anyone have an idea what OID to use, if even possible, to monitor a subinterface, for example, ethernet1/12.12?Many Thanks All!RegardsDavid Vassallo
Hi, Im having an issue with Macbooks. We have a captive portal that uses SAML authentication. If we open Chrome, the captive portal appears and the authentication completes successfully, but no other applications work besides Chrome. Additionally, if we use any other browser, such as Safari, the captive portal does not appear at all. Any ide...
Hi, Here's a polished rewrite: Just wondering if anyone has come across an IBM Container Registry authentication issue where the registry traffic is routed through PaloAlto Akamai geo-location edge servers (for example, cp.icr.io). I experienced intermittent authentication failures where the login process would hang and never complete. After s...
Hi everyone, present, i have VPN global protec Authentication two factor with certificate and radius, by interface management The current setup is as follows: The Palo Alto firewall acts as both the gateway and the OCSP responder. The OCSP responder is configured to use the management IP address, and the OCSP Override URL also points to the ma...
From the system log, i find a log severity is Critical. The message is "License for feature lcaas will expire on 2024/10/30" what is lcaas ? how can i deal with this message ?
We changed the password complexity and history settings on our firewall a couple of days ago.After committing the changes the local users are not able to login on the firewall.So we tried to boot into maintenance mode by connecting through a console cable in order to roll back to a older running config.This did not do anything though, because th...
Some people complain of the captive portal redirecting them when they are in the middle of filling out a form, or doing work on a online portal, is it possible for the captive portal to appear in a different tab like a pop-up instead of a redirect?
In closed environment, the firewall and panorama cannot connect to internet. panorama ( v10.2.5 ) and firewall ( v10.2.5 ) Panorama fail to do the job "refresh license deployment" Please Help !
Hi Team I got a question : During a previous session with end user, it was determined that, following the migration from PEAP to TEAP on the metropolitan area’s wireless network, 802.1X authentications fail to complete correctly when traversing the site-to-site VPN between a branch and the corporate headquarters.From a technical standpoint, t...
Hi, I have captive portal for auth users with SAML. Users are being prompted to reauthenticate after 20 minutes more or less. Where can the timeout be increased, or how can the requirement to reauthenticate every X amount of time be removed?
Dear Community Members, I want to ask couple of things: Is the PAN OS 11.1.4-h33 vulnerable based on CVE-2026-0273 PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI and should be upgraded to PAN OS version 11.1.4-h34 and above? For PA-14020 it came with a base of 11.1.0, can this support to move to other based P...
Dear all We got a question assigned about the PaloAlto EDL for MS Intune, the EDL "MSIntune All URL" (accessible via https://saasedl.paloaltonetworks.com/feeds/msintune/all/url). By 30th of April 2026, Microsoft added the URL "lgmsapeswiss.blob.core.windows.net" to her list, which can be reviewed here: Network endpoints for Microsoft Intune - ...
| User | Likes Count |
|---|---|
| 8 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |

