General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.


Enable palo alto preempt or not?


I was just wondering what most of you people do regarding preempt option for A/P clusters. 

(and perhaps also some pointers regarding the different timers you can set, etc )


Main reasonis that the discussion to use preempt or not to use preempt co


Error Message for AE1 Aggregate Group



We are getting below messages on and off for our HA pair.

eth 1/5 and 1/6 are part of the ae1 aggregate group


nego-fail,ethernet1/6,0,0,general,critical,"LACP interface ethernet1/6 moved out of AE-group ae1. Selection state Selected",450025,0x0


How to Create a Report on Template settings?

I have some templates and template stacks that I've inherited. I would like to review the settings to understand them better, what's getting set where. Is there a way to export a report on those settings rather than clicking each of the tabs on each


Resolved! GlobalProtect license in HA

We have got the 220's and i installed the licenses before i configured them in HA. License that we got says GlobalProtect subscription for device in an HA pair. But the GP license doesn' show up in the passive device. I have yet to do any further con


raji_toor by L4 Transporter
  • 1 replies

GoToMeeting audio(Microphone) not working

Hello Community,


I have some questions regarding GoToMeeting and Security Policies. The System is a PA-3020, which is running on the software version 8.1.2.


For GoToMeeting to work properly, the application stun has to be allowed. I have created a se


Julian_V by L0 Member
  • 3 replies

Resolved! When was "firebase-cloud-messaging" added?

I found that the google-base join time is displayed here and here. In the list, the firebase cloud message is not included.

Recently, the rule setting only uses google-base, which causes FCM to not work properly, so I would like to ask "firebase-cloud


螢幕快照 2019-07-04 下午4.46.29.png
螢幕快照 2019-07-04 上午11.59.02.png
螢幕快照 2019-07-04 上午11.59.38.png

Slow accessing file shares using Global Protect VPN client

Has anyone experienced an issue where accessing file shares from a Windows 2008 R2 is really slow, often showing the hour glass taking up several minutes or cancel and retry opening file shares multiple times again before it opens up, after establish


hcao by L1 Bithead
  • 12 replies

Dynamic Routing offsite

I have been using small(ish) static routing tables until now.  I have 2 PA-3020 in HA mode that control the internet and new offsite datacenter.  At a second location 15 miles away, I will have a backup link to that datacenter.  A third 3020 is in pl



asymmetric routing

Hi , 
If there is asymmetric routing how the  firewall process the packet if it is in routed mode . 
How it process the packet if it is in vwire mode  and there is asymmetric routing ? 

simsim by L4 Transporter
  • 3 replies

Global Protect Pre-Log on set up issues

Hi all,

We are attempting to test global protect with pre-log on in our network and have a number of issues and I was wondering if we might be setting it up incorrectly.

The type of set up we require is with windows machines that log on to global prote


Source User in Monitoring tab same time not viewed

This my issue !!!


During the snapshot same time the source user is not capture by PA


and for this issue the internet for specific user is disconnected


after 5 min the connection start again and the source user is showing 


any idea about this problem


MFayez by L2 Linker
  • 1 replies


We have a rule based on LDAP . However after enabling SLDAP on server end, Palos don't identify it as LDAP rather they identify it as SSL based traffic . what is the ideal way of defining the rule for it now 

1. To define a rule above with Application


  • 24034 Posts
  • 102 Subscriptions
Top Liked Authors