General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4117 Views
  • 0 replies
  • 0 Likes

Resolved! GP external gateway - Connection method Pre logon Always on

We are using SAML in Azure for GP external gateway connection.When connection method is on demand we get mobile push notification and user gets connected to the GP. Testing with Connection method Pre logon Always on, i am not getting mobile push notification.Need to confirm is this by design? or is there any config i can do so that Connection me...

MP18 by Cyber Elite
  • 6945 Views
  • 9 replies
  • 0 Likes

Resolved! how to download global protect agents?

Dear Techs, How can I download a specific version of global protect agent? Note: Due to audit points, the PA portal login page is currently disabled. Generally, I log in to PA portal and download the activated versions from there. Is it possible to download from the support portal like we download the OSS versions? Thanks in advance.@reaper

Resolved! Error installing license key. Please check if it is a valid key

Techs, I am building a OSS device in parallel to the production one. While uploading the Apps and Threat DB manually I was getting a license error. Hence I tried to install the Apps and Threat license I am getting the error "Error installing license key. Please check if it is a valid key ". I have downloaded the key from paloalto portal itself, ...

PA-820 Decryption Causing Slow Internet at 5000 sessions

We have been having a issue at our corporate office where users are complaining about slow access to the internet when I have decryption enabled and sessions reach 5000. Around 3000-4000 access is completely fine. I have been monitoring this from the CLI using the command "show session all filter ssl-decrypt yes count yes". Since the 820 is spec...

unable to create a global protect VPN connection while carrier using Dual stack lite

We are receiving many reports about extremely slow and unstable GlobalProtect connections with some internet providers in Marburg .The providers don’t provide native IPv4 addresses in consumer tariffs, IPv4 packets are tunneled via carrier-grade NAT (Dual Stack lite). This causes packet fragmentation. End user are unable to connect to VPN or if ...

Remove feed entries from old (deleted) feed

I was receiving feed information from the Zeus tracker miners which was discontinued earlier this year. I removed the miners and deleted them from the aggregators, but the data is still in the feeds. How do I remove/expire the data? Attached a screen shot of one of the data entries in the feed. Thanks! Mike

deanm by L2 Linker
  • 4780 Views
  • 1 replies
  • 2 Likes

Log Parsing

Hi team, i am sending the firewall logs to a kibana for log analytic purpose and i ran into a minor issue i can not find a good working grok parsing for the logs that will actually work. any chances any one here done that and can help me with it ? Bets Regards,Alex.

TAP in environments with asynchronous routing

We have a situation where we can't get all the mirrored traffic to the same interface. But as it's asynchronour souting nevironment a packet can be mirrored to one interface and the reply to the other. So we need to connect 2 PA TAP interfaces to capture whole sessions. The question is will PA match the packets into same session if we put both i...

santonic by L6 Presenter
  • 3984 Views
  • 2 replies
  • 0 Likes

Reverse Proxy and X-forwarded-for

We use a load balancer to terminate SSL connections coming into our publicly accessible web servers from the Internet. The same load balancers are used as a reverse proxy. Because this produces a blind-spot for us, we have configured the load balancer to insert the real Internet IP into the XFF entry of the resulting inbound HTTP packet (we do...

Deleted rule still matching traffic

Hi team, We have experiencing something strange behaviour on one of our Palo Alto. Palo Alto is managed via Panorama, our costumer add a security rule directly to device (not using Panorama). We delete the rule on the device, so doesn't appears anymore on Palo Alto device, but traffic still match the rule... (You can saw it in Monitor, we dele...

nanukanu by L2 Linker
  • 3199 Views
  • 2 replies
  • 0 Likes
  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels