General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4133 Views
  • 0 replies
  • 0 Likes

Onboarding to Passive HA to Panorama

Hi Everyone, I need advice on how to onboard the passive HA to Panorama. The Primary is already on Panorama but upon checking, it doesn't belong to a device group yet. I have read some documentation on how to onboard a local firewall to panorama, but I haven't seen how to onboard the Passive Ha on Panorama. Could someone point me to documentatio...

N.MANTUA by L1 Bithead
  • 1063 Views
  • 2 replies
  • 0 Likes

Resolved! Replicating vSwitch NIC status to a NGFW VM (ESXi)

Greetings all, I wanted to see if anyone has successfully replicated the status of a host NIC attached to a vSwitch to a Palo Alto NGFW VM in ESXi 8? Right now, all ports always remain up because the virtual switch they are attached to remain up. It seems like this should be a trivial configuration, but I can't figure it out for the life of me.

Resolved! Deep Packet Inspection and SSL Certificate

Hello, newbie here. One of our clients asked me: "We have an exchange server which is on site. We need to renew the ssl certificate, I was told that if the Palo Alto firewall performs deep packet inspection, we need to supply the ssl certificate to the firewall. if it is so, we need to coordinate with my local admin to install the ssl certif...

N.MANTUA by L1 Bithead
  • 5912 Views
  • 4 replies
  • 0 Likes

Resolved! Failed to check content upgrade info due to Peer certificate cannot be authenticated with given CA certificates started 10/12/2021

Hi, It looks like the cert on us-static.updates.paloaltonetworks.com applied on IPv6 address is expired.2600:1901:0:669:0:0:0:0. go to www.ssllabs.com and check it..option 1. Device > setup > Services > change the update server to the default.option 2 Device > setup > Services > uncheck verify update server identity.commit...

Capture.PNG
Capture2.PNG

Resolved! How to install a Cortex XDR agent communicating through the Palo Alto Networks Broker VM?

1. I installed Cortex XDR Agents before setting up the Broker VM. I want all the agents to route traffic through the Broker VM as a proxy. The Broker VM is activated and connected. Should I uninstall the existing agents and reinstall them using the following command? msiexec /i c:\install\cortexxdr.msi proxy_list="My.Network.Name:808,BrokerIP:80...

AAlsaadi by L1 Bithead
  • 3827 Views
  • 3 replies
  • 0 Likes

unable to open a case

I have a new support account, but there appears to be a problem. URL is https://support.paloaltonetworks.com/Error/Error. I need to open a case for a critical issue.

A very weird Behavior on SIP traffic traffic reversing back to the same egress interface

Hello everyone , im seeing a very strange behaviour in my pa-445 version 11.1.4-h7 firewall , where i have an interface on the firewall which is a gateway to my voip devices , the same firewall connects to the voice server through an ipsec tunnel interface , so the traffic flow is like this , voice subnet to firewall and then from firewall to vo...

How to create ACLs for access to AWS workspaces (EDLs don't cover all IPs)

I need to create ACLs for outbound access to AWS workspaces using the destination IPs / subnets / FQDNs shown on AWS publication https://docs.aws.amazon.com/workspaces/latest/adminguide/workspaces-port-requirements.html#ip-address-regions. PAN publishes an EDL for AWS workspace, but it only contains a handful of IPs. Some of the IPs listed ...

PaloAlto Passive Firewall Monitoring in HA Setup

Hi everyone,Greetings! I’m currently using OpManager to monitor a Palo Alto firewall in an HA Active/Passive setup, and the Link State of the interfaces on the passive device is set to auto. While OpManager is able to correctly pull interface details from the active firewall, I am experiencing issues with the interface status of the passive fire...

USER111 by L0 Member
  • 1359 Views
  • 1 replies
  • 0 Likes

Resolved! PA-1420 QinQ

Does the PA-1420 support QinQ tagging terminating at the Firewall? We have a L2 connection with an ISP to Azure and they require QinQ tagging. We do not have an ISR or other router to do it for us at this time. Thanks, Steve

smzr34 by L0 Member
  • 1846 Views
  • 1 replies
  • 0 Likes

Resolved! OS Upgrade path to 10.2.10-h9

Hello.I am currently using PAN-820. The OS is 10.1.9-h3. What is the correct way to upgrade? (I will upgrade to 10.2.10-h9.) 1. Upgrade to 10.1.14-h6, then upload 10.2.0, then upgrade to 10.2.10-h92. Upload 10.1.14-h6 and 10.2.0, then upgrade to 10.2.10-h93. Upload 10.2.0, then upgrade to 10.2.10-h9 What is the correct way? I cannot receive ...

danudan by L0 Member
  • 1856 Views
  • 1 replies
  • 0 Likes
  • 24337 Posts
  • 124 Subscriptions
Labels