General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4112 Views
  • 0 replies
  • 0 Likes

False Positive (virus/win32.wgeneric.vnujo)

Dear Support, Our customers have been reporting that palo alto is identifying our software as malware. application ms-ds-smbv3virus/win32.wgeneric.vnujoID 219797367 How can we proceed to whitelist our software permanently? Thank you

prsi0203 by L1 Bithead
  • 7761 Views
  • 4 replies
  • 0 Likes

Resolved! How do you deal with Service Route and MGT port redundancy?

We had an outage that took out a switch, and the PA management port is connected to that switch. I was unable to access the UI or CLI, and VPN was unable to authenticate via LDAP. I found the issue was that all the Service Routes were set to default using the MGT port. After looking through the settings, I see that I can assign a Management Prof...

Maxstr by L3 Networker
  • 6503 Views
  • 4 replies
  • 0 Likes

How to resolve invalid NAT rules in Expedition

I've downloaded and run the latest Expedition VM, and have imported my Cisco ASA config file, but Expedition says all my NAT rules are invalid. Not clear what that means, and the instructions (link below) say nothing about how to resolve them. https://live.paloaltonetworks.com/t5/Expedition-Articles/Expedition-Documentation/ta-p/215619?attachme...

Seeking Guidance on What Content Should Be Included In a Panorama Maintenance Guide

Tasked with creating a "Panorama Maintenance Guide," but finding little detail regarding what should be included. I have search for something similar from Panorama, but I have been unable to locate anything.There are a few functions I want to include, but I do no have those technical details for performing the task. Details to include if possibl...

TLHaga by L0 Member
  • 2737 Views
  • 2 replies
  • 0 Likes

Resolved! Checking for CloudWatch

Hi all, Relatively new with Prisma and playing with the RQL. Would anyone be able to tell me if there's a query i can run that tells me if cloudwatch is enabled within an AWS environment? Report wise, I tried running something against CIS compliance and it's really just telling me that cloud trail is not integrated with cloud watch which doesn't...

Resolved! HIP logs review

Hi, Need your insight !!We have few VPN portals to meet HIP checks ( laptop - Domain and anti virus ) I could see the HIP logs in the HIP Match ( that means host passed the HIP match ?)Or those logs that shows HIP match passed or failed ? Any keyword or check mark to verify host cleared the HIP matches ? ThanksKM

GlobalProtect reports Machine Certificate (null) but it isn't...

Hey all,Recently upgraded to PAN-OS v9.0.3 and GlobalProtect is no longer working for some. Error messages in the system logs are showing GlobalProtect portal client configuration failed... Machine Certificate CN: (null) for those that fail but also Machine Certificate CN: (just a blank here) for those that are successful. This is intermitten...

cafowler by L2 Linker
  • 6372 Views
  • 1 replies
  • 0 Likes

Resolved! Panorama Error

Getting below error in Panoram's system logs : Panorama has lost connection to its peer, no log will be forwarded Though from Panorama all devices looks connected .Verifed the device status from panorma. Anyone facing similar issue ?

deepak12 by L3 Networker
  • 10832 Views
  • 4 replies
  • 0 Likes

TCP issues when moving an application through a Palo Alto FW

Hi, Following scenario: we have a 2-level Firewall Filtering / Security Setup active in our infrastructure, with a Cisco ASA currently acting as the Internet Firewall (updated to the latest Cisco ASA OS version) and an internal Firewall (Checkpoint appliance, also updated to GAIA OS R80.20). Among others (like Web Servers, DNS, Email, and so on)...

NAT PPTP VPN

Hello, im trying to set up a NAT rule for a PPTP VPN tunnel.I have set it up like this:Source: untrustDest. zone: untrustSource address: AnyDest. address: lets say 20.20.20.20/32Service: anySource Translation: NoneDest-Translation:20.20.20.20/32 Security RuleZone:untrustSource address: Geo Location:NO,EUDestionation:20.20.20.20/32Application: PP...

holten by L1 Bithead
  • 3966 Views
  • 1 replies
  • 0 Likes

TLS 1.3 support

Hi everybody,any news regarding change of decryption from passive to proxy mode to support TLS 1.3 decryption?Thank you,Jan

Palo Alto lab devices

Hi guys,I was assigned to work on a project with involves working with Palo Alto appliances a lot. I have never touched such a firewall before, so I am planning to get two (or more) devices for my home lab and experimental use. Do you think the PA-2050 model would be suitable to get me started and possibly help me get certified? Thanks a lot.Reg...

Problems with panorama and paloalto ACC No data display

Hello good afternoon I have a problem with my panorama and a Palo Alto HA, in the panorama the complete traffic is not visualized and in the ACC no data display. Already apply these commands > request log-fwd-ctrl device <serial number> action stop> request log-fwd-ctrl device <serial number> action start But the same thing is ...

Question about Global protect Pre-Logon Issue

Hi, I configured GP pre-logon method, But it’s only working in administrator mode even though the user is part of administrator group, it’ not working for normal users. I followed below KB article,https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEYCA0 In global protect client installed laptops, we are able to connect g...

GlobalProtect.jpeg
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels