General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience.

General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.


Ensuring a Safe and Secure Community: How You Can Help


Dear LIVEcommunity Members,


Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun


jforsythe by Community Team Member
  • 0 replies

Recommended Version

Good Morning:


What is the recommended version for the Palo Alto 3050 series firewalls?  We are currently running 8.1.8


What are your thoughts on 9.0.2-h4?  Are there any problems with it, or should we more likely than not be good to go?

birkhojk by L2 Linker
  • 2 replies

Custom URL Category and SSL Decryption

Hello all,


We have a custom URL category created to exclude sites from SSL decyption. We have the category set to no decrypt on the firewall but recently we encountered an issue where URLs that we add to the custom object were not getting categorized


BGP sessions not exporting

Hi folks/


I'm trying to use BGP to synchronise routing across two ISPec tunnels to a Palo Alto HA cluster.


I have BGP connectivity established - the remote end is exporting the routes I want, and they're being seen (and managed correctly) by the Palo


darren_g by L4 Transporter
  • 11 replies

Force BGP Peering over a certain interface/path

I have many paths through my network and my palo altos are choosing to peer iBGP with each other over the Northbound paths to the next level of of switches. I want them to use the links south bound to my datacenter core to peer BGP. They are peering


PAN DB URL filtering issue.

Dear all,


One of my customer PAN DB License expired and we try to block all Youtube videos excluding some the vidoes links in Youtube. 


My query here is, whether if the device without a valid PAN DB Licence we will be able to acheive the above requir


Resolved! Policy details

Hi ,


Is there way to pull the details of all policies using same address/address group  in Panorama via cli .


I can check from gui , but it will need lot of manul work .


Example:  address group  -" Test" is part of policy for 10 firewall managed by P


deepak12 by L3 Networker
  • 3 replies

Resolved! Office 365 Security Policy Question

In referencing the link below (FAQ - Office 365 Access Control), I'm concerned with a destination in the Security Policy for Office 365. What is everyone else doing for destination? The list of IP addresses for Office 365 Business products is long an


Resolved! API-Call for QOS results in 'interface has unexpected text'



when I try to use an api call to query the qos statistics of an interface i get this errormessage:


<response status="error" code="17">
<![CDATA[ show -> qos -> interface has unexpected text. ]]>
<![CDATA[ show -> qos -> inte

ABux by L1 Bithead
  • 4 replies

Vulnerability in PA?



We just received info about this vulneraability:

So we would like to know if PA appliances are impacted?



BigPalo by L4 Transporter
  • 16 replies

Resolved! Changing IP Addresses

Throwing this out here to see if I maybe creating any issues.


I have a machine that is setup in my firewall with an address object.  Let's say it's its Machine1 and it's IP is   This machine will be decommissioned soon and I have setup ano


Panorama Local Log Collector.

Hey, I have a HA pair of firewalls in SiteA and a HA pair of firewalls in SiteB. SiteA and SiteB seperated by a 1Gb WAN. I have Panorama deployed in HA, one VM in SiteA and one VM in SiteB. I want the firewall in SiteA to send logs "only" to the Pano


  • 23709 Posts
  • 110 Subscriptions
Top Liked Authors