General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4229 Views
  • 0 replies
  • 0 Likes

PANORAMA UPGRADE from 8.0.19 to 8.1.X template Query

I am in process of upgarding our Panorama (M-100) from 8.0.19 to 8.1.X code.I have gone through below URL for upgrade consideration and procedure to upgrade PAN.One thing i feel is critical to my enviroment is Template. We use regular template however 8.1.x code support template stack.As per online documention , conversion from template to templ...

Nischal by L2 Linker
  • 5222 Views
  • 3 replies
  • 0 Likes

URL Filter For One Specific URL

We have a VMWare Horizons install with a URL of:https://horizons.domain.com We need this available to the Internet. It is 2FA protected and works fine. This URL:https://horizons.domain.com/admin is not 2FA protected and is exposed to the Internet. Is it possible to block only the /admin url but not affect access to the upper link on a PA firewal...

IPv6 duplicate issue

Hello,is there anyone had an issue of duplicate IPv6? i coundn't able to ping next hop ipv6 ip. i worked with PAN TAC even they don't have answers just suggested to change different ipv6 subnets, tried by changinging different ipv6 subnet couldn't fix the issue. Our network envirnoment has same architucture for ipv4 and ipv6 but ipv4 working p...

Resolved! Password problem

HI All, I last logged into our VM-300 on friday 23rd August to make a SSL Decryption config change and attempted to login again yesterday. However all of a sudden my admin password doesn't work. I'm the only one who knows the password anyway, so no one else has access to it. There are two admin accounts and neither password works now. The only a...

Resolved! Maximum number of OSPF routes supported

what is the maximum number of OSPF routes supported on PA3020 and PA3220.I have checked the maximum number of routes using the command show system state | match cfg.general.max-route.Is there any specific limit for OSPF routes in the routing table ?@reaper, @gwesson, @BPry Your inputs are much appreciated. Regards,Syed Mohamed Ishaq

APPLICATION INCOMPLETE

Good day All i had read all the possible solution to this issue, but still presenting the same symphtom, i have applied all solutions mentioned on all posts. does anyone had or did something different? thanks in advance.kind regards.

Capture.PNG

Direct web traffic to internal proxy

For some reason oun of our MS GPO's is failign to apply ( or rather is wiping ) proxy server settings for our users. The users shoudl be hitting the proxy before going through the PA, but it's broken.USER-Website:80:443 --> PROXY:8080 --80:443--> --PALO --> WORLD I am trying to fatom how to get teh PA to transparently pass traffic to ...

fw1.jpg

Caveats for changing interface netmask?

I've got a client that wants to expand the network range on one of their interfaces for additional DHCP scope space, moving from a /24 to a /23. I wanted to check if there are any caveats to this on the PAN side? Will the update take effect as soon as the change is commited?I'm currently scoping out the rest of the network to confirm if anythi...

migrating configuration from physical appliance to Azure VM

Hi community, I´d like to check with you if there´s a way to migrate/adapt the configuration from a physical firewall to be imported into an Azure´s VM? Could it be possible importing into the Migration tool both configuration files...1. snapshot from physical appliance2. the sample configuration file from Github repositoryhttps://docs.paloalton...

Carracido by L4 Transporter
  • 4703 Views
  • 1 replies
  • 0 Likes

URL Filtering Issue

Hello Community, I want to block one specific https URL (without applying decryption rule) but the traffic is being allowed by the lower policy. I have applied many combinations with the wildcards but none of them works.Can someone please help me with this.

JAIDEEP by L0 Member
  • 2476 Views
  • 1 replies
  • 0 Likes

Asymmetric Routing and TCP Syn Check

Hello All, I have a scenario where I will be having two ISP's (ISP-A and ISP-B) connected to the PA Firewalls via eth1/1 and eth1/2 interfaces. Both these Interfaces will be in the same untrust-zone. ISP-A will be the primary one and ISP-B the backup with some prepends and local preference for incoming and outgoing traffic.However, ISP-B has con...

Anjush by L0 Member
  • 5735 Views
  • 2 replies
  • 0 Likes
  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels