General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4231 Views
  • 0 replies
  • 0 Likes

Resolved! Configuring QoS

Hi, I'm still a little new to Palo Alto (but familiar with QoS concepts), and right now I'm trying to understand how QoS is configured on a PA3020 in production (configured by someone else before I was with the company). I can see a QoS profile called 'default', which is applied to two interfaces. However, there is no QoS policy at all.If I unde...

Luke_R by L2 Linker
  • 4841 Views
  • 4 replies
  • 0 Likes

Resolved! Multi-domain/child domain group mappings

We are in the process of moving two old domains into a new domain with child domains and have been having some issues with UserID and group mapping applying the wrong domain to users, which in turn makes it so the correct security policies don't apply. The general setup is this: Old1 and Old2 are the old domains (neither has child domains); Roo...

Resolved! OSPF question

I have a stub area - my office.But I have 2 paths into it from area 0.0.0.0Is it still a stub as its has 2 paths in and out. so area 0.0.0.0 via rtr A to area 10.172.0.0 or area 0.0.0.0 via rtr b to area 10.172.0.0 What I want it just the DGW sent it from both rtrA and rtrB

Resolved! Warning in panorama "app not found"

We are having a warning when we push in panorama: We have check the apps&threats version and everything is OK. Panorama version is 9.0.4. It could be a cosmetic issue?

appweb.jpg
BigPalo by L4 Transporter
  • 13090 Views
  • 13 replies
  • 1 Likes

HA link monitoring

Hi All, I apologize for the basic question and have to ask since I do not have a spare firewall pair to test with. Wanted to understand the link group configuration behavior when there are no interfaces specified under it. Palo Alto does accept the configuration so does that mean that all interfaces are being monitored or none of the interfaces ...

rahulbri by L1 Bithead
  • 7984 Views
  • 5 replies
  • 0 Likes

Access from dynamic Office 365 URLs to internal ressources

Hello,Im using minemeld to get the dynamic address (URLs, IPs) from office 365. If there are IP addresses, this works without problems via the EDL. In this case the EDL replace the source object.What about addresses that have a wildcard in the URL? These EDLs cannot be selected from the source object and must be saved using the URL pattern filte...

Wildcard domain + destination question

Hi..I want to be able to allow a specific set of apps to *.github.com. To do this would I simply specify a custom URL with *.github.com and destination of ANY? That would then only allow those apps to *.github.com? I ask just because I am wary of having the destination as ANY and not clear on which takes precedence. Currently I have it lock...

Annotation 2020-01-21 093816.png
drewdown by L4 Transporter
  • 3385 Views
  • 3 replies
  • 0 Likes

Mgmt interface stop working

Hi. I have a PA-500 and after a storm, the management interface stopped work. When I connect a network cable the leds doesn't work.I made a configuration to access the Firewall and to use some services throught another interface, but the "Log Scheduled Export" doesn't have this option.How can I solv this problem?

Resolved! GP external gateway - Connection method Pre logon Always on

We are using SAML in Azure for GP external gateway connection.When connection method is on demand we get mobile push notification and user gets connected to the GP. Testing with Connection method Pre logon Always on, i am not getting mobile push notification.Need to confirm is this by design? or is there any config i can do so that Connection me...

MP18 by Cyber Elite
  • 7034 Views
  • 9 replies
  • 0 Likes

Resolved! how to download global protect agents?

Dear Techs, How can I download a specific version of global protect agent? Note: Due to audit points, the PA portal login page is currently disabled. Generally, I log in to PA portal and download the activated versions from there. Is it possible to download from the support portal like we download the OSS versions? Thanks in advance.@reaper

Resolved! Error installing license key. Please check if it is a valid key

Techs, I am building a OSS device in parallel to the production one. While uploading the Apps and Threat DB manually I was getting a license error. Hence I tried to install the Apps and Threat license I am getting the error "Error installing license key. Please check if it is a valid key ". I have downloaded the key from paloalto portal itself, ...

PA-820 Decryption Causing Slow Internet at 5000 sessions

We have been having a issue at our corporate office where users are complaining about slow access to the internet when I have decryption enabled and sessions reach 5000. Around 3000-4000 access is completely fine. I have been monitoring this from the CLI using the command "show session all filter ssl-decrypt yes count yes". Since the 820 is spec...

  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels