General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Panorama Dynamic updates

HelloI use Panorama to manage my firewalls, I configured Panorama for Dynamic updates (antivirus, Application & Threats) but, when I go to "Device Deployment / Dynamic updates", all versions are in middle of December 2019. When I "check now", I have no issue about an connection error but the new version of antivirus, App & Threats are no...

Resolved! Minemeld O365 doesn't have latest IPs

Seeing an issue using minemeld and O365 IPs and not having the same IPs that Microsoft is advertising that need to be allowed. Is there any easy way to confirm what is there and and what isn't via minemeld? I've been using for awhile but only now did I notice that some of the CIDRs aren't coming across via minemeld.

drewdown by • L4 Transporter
  • 13014 Views
  • 10 replies
  • 0 Likes

Resolved! 64-bit User-ID Agent Software

Hi,The Installation instructions for the User-ID Agent software remind you to ensure you've downloaded the correct version of the software (32 or 64-bit).However I can't find the 64 bit version of 8.1.10 anywhere, only of the Credential Agent. Anyone know where it is?? I've tried installing the 32-bit version to Windows Server 2016 instead but t...

Anyone else notice these "Load Config Partial" syntax changes in PAN-OS 9.0?

Doing my first migration to PAN-OS 9.0. We've migrated the config using expedition, but when I try to use the load config partial commands I keep getting a "Invalid syntax." error Example on how it used to work- load config partial from MT-fixed.xml from-xpath /config/devices/entry/vsys/entry/tag to-xpath /config/devices/entry/vsys/entry/tag m...

VPN

Hi. who can help me this topic?Person A must configure vpn with person B. Person A must configure two vpn connection and all data flow to vpn 1 node but if vpn node1 goes down, aoutomatic all traffic must flow through with node 2.

URAN_725 by • L1 Bithead
  • 2562 Views
  • 1 replies
  • 0 Likes

Free space in /dev/md2 partition

HelloWe have a Firewall PaloAlto with free space 509MB in partition /dev/md2, and 609MB in partition dev/md5, actually we need to upgrade the PanOS since 7.1.18 to 8.1.12, and there are 5 PANOS to upgrade, so the information is keep in /dev/md5 but before the installation We would like to know if the /dev/md2 root partition has little free space...

How to block Internet Explorer

I am trying to block Internet Explorer traffic going out to the internet from my internal users. I have decryption in place and followed this article: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEdCAKI am seeing some websites being blocked but some of them are not despite decryption. Has anyone tried blocking IE?P...

Resolved! Block External Email

Hello -Basically I would like to start blocking external email access from the internal network such as Yahoo Mail. I don't want to block access to Yahoo itself, just inbound email from Yahoo and other sites like that. Is there any documentation on how to best accomplish this? Thanks in advance!

Resolved! Global Protect Certificate based authentication or Ldap Authentication

Planning to implement a certificate-based authentication method in Global protect VPN in some of the iPad. All other clients should be able to log in just using with LDAP(username/password). The customer doesn’t have GP Portal license. Can we achieve this on 8.1.x PAN-OS with two client authentication profile? Anyone did this one 8.1.X OS?

CyberEye by • L3 Networker
  • 5737 Views
  • 4 replies
  • 0 Likes

Global Protect HIP check issues

Have had an open case with support since August 2019 with HIP checks setup for Global Protect. There are options to allow HIP checks for a large number of different AV vendors and their products. The issue we have come across is that we have defined specific AV vendors that can be used and all others are denied. The vendors we have allowed we...

mattwech by • L0 Member
  • 4422 Views
  • 2 replies
  • 0 Likes

VPN between Palo Alto and Check Point firewall

Hello,I am trying to establish a successful VPN connection between my Palo Alto firewall and a Check Point firewall. The VPN tunnel on the Palo Alto side shows all green for phase 1 and 2, however on the Check Point side I keep getting a failure per the log "IKE failure no response from peer".In the "Monitor" > "System" log of the Palo Alto t...

HA clarification with a single ISP

Hi Gang, Excuse me for my ignorance. We had firewalls Palo literally thrown at us, and instantaneously put into production (not great!). I have a pair of Palo's in HA Active/Passive with preemptive enabled on active/primary. These are in turn, patched to an INET switch (internet handed off via a single ethernet patch cable to this switch). We ...

Bootstrap debugs / logs

Hi, I was wondering when I went through the bootstrap documentation, it mentions that it should display logs of the bootstrap even if successful but in either case, nothing appears on the console, not even a single word about bootstrap... where should this be displayed or how can i check these logs?

CLIq by • L3 Networker
  • 6838 Views
  • 5 replies
  • 0 Likes
  • 24455 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels