General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1250 Views
  • 0 replies
  • 0 Likes

Resolved! OSPF in a Active/Passive Firewall setup

Hi,


I have a lab with a active/passive Palo Alto firewall setup. I have had a look at the Palo Guide for setting up OSPF at:

 

https://knowledgebase.paloaltonetworks.com/servlet/fileField?entityId=ka10g000000D8HwAAK&field=Attachment_1__Body__s

 

From this

...

vvadia by L1 Bithead
  • 7905 Views
  • 2 replies
  • 0 Likes

URL Identification

Hi

 

i have a question about URL Identification.

 

i use url object in security policy and no use ssl decryption

 

if no SNI is present and there is no CN enrty,

 

how can identify URL?

 

thanks.

hbshin by L2 Linker
  • 5563 Views
  • 3 replies
  • 0 Likes

What is "cdt_token" process?

Hi there,

 

Quick question. I'm currently troubleshooting a PA 3020 in version 8.0.12 for one of my customer. Its PA has huge DP CPU usage (arround 80%). I try to figure out the reason of this usage.

I've isolated the "ctd_token" process which is a big

...

epavis by L1 Bithead
  • 6373 Views
  • 6 replies
  • 0 Likes

DNS license and PAN OS 9.0

 

During Ignite we were told that DNS is coming as license service in PAN OS9.0.

Need to know is this service different from dns sinkhole?

 

IF it is how it is ?

MP18 by Cyber Elite
  • 3231 Views
  • 3 replies
  • 0 Likes

Traffic dropped due to old discarded session

 

We have traffic rule to allow the traffic but seems traffic is dropped by the PA when i did pcap.

then from cli i did show session all filter source  there i see old session from april in discarded state.

i ran the command few times and this session w

...

MP18 by Cyber Elite
  • 2788 Views
  • 2 replies
  • 0 Likes

Panorama pulling in vmware objects

I'm just wondering if there is a way for panorama to talk to vmware to pull in the virtual systems and tags for quicker deployments much like it can do with AWS. I have been looking around but I haven't seen anything specific and help would be great.

murphyj by L2 Linker
  • 2442 Views
  • 1 replies
  • 0 Likes

deny telnet command but permit JDBC protocol

We have an internal discussion about whether it is possible to block the 3 way hanshake TCP but allow the JDBC application protocol.
In other words we would like to block the test of the port with the command "telent address port" but we would like th

...

cata86 by L0 Member
  • 4550 Views
  • 2 replies
  • 0 Likes

SSL Certificates from enterprise CA

I will admit, certificates are one of my bigest hates.. I just can't get on with them

 

Firstly we have a microsoft EnterPrise CA. Which I am not overly familiar with anyway ( But I have managed to get the web interface workig on it...)

 

Idealy what I w

...

RMA'd Panorama m-100, how to migrate?

We had to RMA our m-100 Panorama and now I want to replace the failing one with the new one but for the life of me can't seem to figure out the steps to do that.  The link from this page: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id

...

drewdown by L4 Transporter
  • 3858 Views
  • 2 replies
  • 0 Likes

Refresh EDL from webserver

Hello community,

 

We are using EDL for manually blacklist and whitelist some domains. We configured all our firewalls to refresh the EDLs every 5 minutes, but EDLs don't refresh until a couple hours. The solution that we found is use the "import now"

...

Resolved! Any way to export pan_packet_diag.log?

Hi,

 

When generating a flow basic log - is there any way to export just the pan_packet_diag.log using scp? According to https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpFCAS the file wiil be included when exporting a TSF, b

...

Resolved! Using regex in defining a group address object

I'm defining a new group address object which should include addresses of several different tags (e.g. "Tag_1", "Tag_2", etc.).

When trying to define the match field I cannot find a way to actually do that. I'm not sure it's even supported. Whatever p

...

Resolved! Commit process

From Panorama during commit process , just typing "commit" and press enter will do commit to all device group/template ?

deepak12 by L3 Networker
  • 4326 Views
  • 2 replies
  • 0 Likes
  • 24175 Posts
  • 117 Subscriptions
Top Solution Authors
Top Liked Authors
Labels