General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4111 Views
  • 0 replies
  • 0 Likes

migrating configuration from physical appliance to Azure VM

Hi community, I´d like to check with you if there´s a way to migrate/adapt the configuration from a physical firewall to be imported into an Azure´s VM? Could it be possible importing into the Migration tool both configuration files...1. snapshot from physical appliance2. the sample configuration file from Github repositoryhttps://docs.paloalton...

Carracido by L4 Transporter
  • 4664 Views
  • 1 replies
  • 0 Likes

URL Filtering Issue

Hello Community, I want to block one specific https URL (without applying decryption rule) but the traffic is being allowed by the lower policy. I have applied many combinations with the wildcards but none of them works.Can someone please help me with this.

JAIDEEP by L0 Member
  • 2449 Views
  • 1 replies
  • 0 Likes

Asymmetric Routing and TCP Syn Check

Hello All, I have a scenario where I will be having two ISP's (ISP-A and ISP-B) connected to the PA Firewalls via eth1/1 and eth1/2 interfaces. Both these Interfaces will be in the same untrust-zone. ISP-A will be the primary one and ISP-B the backup with some prepends and local preference for incoming and outgoing traffic.However, ISP-B has con...

Anjush by L0 Member
  • 5597 Views
  • 2 replies
  • 0 Likes

Global Protect and google play traffic from mobile

Hi all , I am running PAN OS 8.0.19 and GP 4.1.12 and users cannot access google play store while they are connected to the VPN from androids . I have tried with spli tunneling including 63 subnets from google and I have tried full tunnel defining in the ACLs IP any any just for tshoot but it seems I am getting in but cannot download any app . ...

Resolved! SSL Exclude Option Missing in 8.1

Hi Community, I noticed, that in 8.1.x (7,8,9, 9h4) the "SSL Exclude Option" in Device > Certificate Management > Certificates is missing.The PAN-OS 8.1 guide mentions this option on page 198, and you can see it in a screenshot in this KB point 7:https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClUjCAK Does anyone...

Chacko42 by L4 Transporter
  • 5198 Views
  • 2 replies
  • 0 Likes

Resolved! LSVPN Satellite Deny specific subnet to Publish to gateway

In LSVPN VPN setup how can we deny specific subnet to not advertise to gateway. I have selected Publish all static and connected routes and I want to deny some of static routes of them , how can we do that ? I know we can disable public option manually and add each subnet apart from that with enabling publish option is there a way we can deny it...

Multicast with Chromecasts confusion

Background: I have a trust zone on ethernet1/2 192..168.1.0/24 and an iot zone on ehternet1/4 10.10.10.0/24 and I want to be able to cast things from endpoints (mobile phones and laptops) to the chromecasts on the iot zone. It seems like multicast (aka mDNS) is the trick however I am not sure I am going the right direction or if this is even...

multicast1.jpg
multicast2.jpg
secpol.jpg
hshawn by L4 Transporter
  • 10219 Views
  • 2 replies
  • 0 Likes

Resolved! Ubuntu

Hello, can anyone tell me what version of Ubuntu I should use for MineMeld ?

Autofocus MineMeld - how to access output node that requires authorisation

I need to create O365 IP/URL EDLs but when I try to access the output nodes I get "Unauthorised" message unless I sign into AutoFocus in the browser. Needless to say I cannot do the same on a firewall. How do I allow anonymous connections to a feed in Autofocus MineMeld or use authentication when configuring EDL on a firewall?

Config Files Backup

Hi.I have PA850. According to this link (https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm7yCAC) I configured backup with local Superuser account. Everything is OK. But then I created new Admin Role named backupadmin and new account palo. This account's profile is backupadmin. I attached screenshots. The aim is I don't...

1.JPG
2.JPG
3.JPG
4.JPG
Outlaw by L0 Member
  • 3112 Views
  • 1 replies
  • 0 Likes

High memory usage on Palo Alto

I have an issue with a Panorama VM indicating high memory usage.Using the following resources: top - 10:59:58 up 82 days, 1:07, 1 user, load average: 4.22, 3.89, 3.87Tasks: 156 total, 1 running, 152 sleeping, 0 stopped, 3 zombieCpu(s): 39.2%us, 1.8%sy, 0.0%ni, 58.0%id, 0.9%wa, 0.0%hi, 0.1%si, 0.0%stMem: 16447708k total, 16354760k used, 92948k fr...

Resolved! Data Center Firewall - Monolithic vs Virtualized

This is purely theoretical and does not represent a real network.You can think of this as on prem or public cloud:- MonolithicThis design utilizes 3 physical firewalls that are embedded in a data center fabric• Perimeter• B2B• DCThe main focus of my question is on the DC firewall, as you can see segmentation is derived by using traditional zones...

DC Firewall - monolithic.jpg
DC Firewall - virtualization.jpg
DC Firewall - virtualization.jpg
mcronin by L0 Member
  • 3046 Views
  • 1 replies
  • 0 Likes
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels