General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

PanOS 11.1.5 (and others with the fix for CVE-2024-2550) still not preferred?

Might anyone know why 11.1.5 and 10.2.10-h10 (or anything newer) are still not marked as preferred 3 months after release? We're on 10.2.x now and likely would upgrade to 11.1.x, but I figured waiting for the patch for CVE-2024-2550 makes sense. CVE-2024-2550 PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway Using a Specially...

ccvega by L1 Bithead
  • 1295 Views
  • 1 replies
  • 0 Likes

Resolved! Device Certificate fetch failure

Version : 10.1.6-h3 Issue/ Error log : Failed to fetch device certificate. Failed to send request to CSP server. Error: No OCSP response received(dest => 35.222.13.89) Tshoot : Generated OTP over support portal but no option for me to key in the OTP KB unable to resolve : https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0...

VLim by L2 Linker
  • 55374 Views
  • 14 replies
  • 0 Likes

Two separate PA one the same ISP on both location

Hi, we have two PA fws around 1km in bettwen. They are connected with dark fiber so users on both side can see each other.One the same ISP on both side, and public IP address range of /28 addresses. We are using that public IP address for several services (each service has its own public IP) and want to configure both PA so when PA on primary ...

Resolved! Renewal of license

Dear team, I have four firewall devices whose licenses are expired. I am unable to get the vendor we bought the devices from. Could you please guide me to purchase new licenses directly from Palo alto. Regards, Lamin.

lnicol by L0 Member
  • 1705 Views
  • 2 replies
  • 0 Likes

Demo Lab Environments - No Longer Available

I was going to review some Panorama setting options in the demo environment and the demo environment is no longer available. Did Palo Alto decommission these labs and was there any communication about it? If so, can anyone provide the communication? Here are the labs sites I have tried to reach and they just timeout. https://us1.demo.paloaltonet...

Resolved! Clear SSL Certificate cache

Hi,We have a PA-500 and I can view the SSL certificates with: "debug dataplane show ssl-cert-cn"I was told that this is the list of SSL certificates that are stored in the cache.However I'd like to know how to clear this cacheThanks

List of domains to allow for in-flight WiFi

Hi all, I've been working with a number of customers lately who have been trying to gather a list of in-flight wifi domains that they need to allow as GlobalProtect Enforcer exceptions and I thought I'd share them here. I'd also ask that you please post any additional domains or use-cases that are missing and I'll be sure to update my list. No...

chmotley by L2 Linker
  • 54434 Views
  • 15 replies
  • 7 Likes

Resolved! SIP traffic being dropped in drop.pcap without log on PAN OS ver 10.2.4-h10

Hi Team, I'm getting SIP traffic drops on drop.pacp without any logs on traffic monitor or in the global filter. i have SIP-ALG disabled and i have a policy to allow the expectect communication. My PA-460 is dorping some SIP packets, not all for the same comunicattion, just te request Message packets seems to be droped. Can you help me t...

Evaluation ESXi shutdowned

I testing Evaluation for ESXi PA-VM-ESX-10.2.5.vm_eval.ovaSuccessfuly,installed.But, after PA-VM login: indicated, I cannot login in entering default admin / admin.and,a few minutes later,PaloAlto-VM is shutdowned. Even I tried several times,it occured it everytime.Please help to address this issue.

Static default route setup for DHCP client WAN interface

Hello All I would be much appreciated if you can help with setting up my static default route which I believe is the culprit why I'm not able to route data traffic to internet. eth1/1: WAN interface, the interface is set as L3 untagged, configured DHCP-client for IPv4. ISP assigns a new IP every 10-12 hours and the bridge-mode cable modem...

static route setup.png
routing table and metric.png
Screenshot 2023-08-19 at 23.49.57.png
SNAT rule.png

Limited CLI Rights

Howdy All! We are in need of finding a way to give a help desk individual limited access to the CLI to run a Python script to clear addresses from the DoS Blocked-Table. The 2 commands it is running is the debug dataplane show dos block-table debug dataplane reset dos zone <zone> block-table source <ip address> What I have foun...

double nat

hello, my palo alto pa440 wan is connected to another firewall who is connected to the isp with a public ip natted to my firewall.i have to setup an ipsec tunnel i don't understand if i have to use the public ip or the vlan ip as local peer ip address thanks

Gruppoes by L0 Member
  • 1181 Views
  • 2 replies
  • 0 Likes
  • 24443 Posts
  • 125 Subscriptions
Top Solution Authors
Labels