General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4118 Views
  • 0 replies
  • 0 Likes

Resolved! By using LAN unable to connect VPN

Hi Experts, I have installed Global Protect VPN client. When I'm trying to connect VPN it is throwing an error "Server Certificate is invalid".When I connect mobile internet or internet dongle to my machine I can connect VPN. But when I connect through LAN it is giving the error. Can anyone please help me to overcome this issue? Thanks in advanc...

Prasuna by L1 Bithead
  • 4235 Views
  • 4 replies
  • 0 Likes

How to get IP public of GitHub

Hi All I am considering to use Minemeld in company with Palo Alto Firewall. I tested it and I saw it support to get IP of AWS, Google Cloud, Azure but I didn't see GitHub. So how I can create custome Miner to collect IP public of GitHub. Please help me to resolve it. Thanks, Giang Le

Resolved! Page not loading properly

Hello, We have a simple rule placed at the top allowing users to connect to Netflix. However, the page is not loading properly. No SSL Decryption in place. How to fix the issue?

Screenshot.png

Unauthorized Access

Hi All, we had an unauthorised access to our firewall, after the access all the logs in the firewall have been deleted and configurations have been changed and committed. we need to which credential are used to login the firewall. Now we found the ip address as well as what changes are they made. there is any other chance for restoring the del...

Admin Roles - Read Only

I am trying to create a admin role on the PA device and select things in the webUI to be read only. When I check these items I get enable and disable options but not the read only option icon option? Is there something I am missing here?

Resolved! Unable to access PA via Web GUI-0 ERROR: websrvr: Exited 4 times, waiting 360 seconds to retry

Unable to access PA via Webgui System log shows 2019-05-19 22:43:35.301 -0600 INFO: l3svc: exited, Core: False, Exit code: 12019-05-19 22:43:35.570 -0600 ERROR: l3svc: Exited 4 times, waiting 330 seconds to retry2019-05-19 22:43:35.787 -0600 INFO: websrvr: exited, Core: False, Exit code: 12019-05-19 22:43:36.060 -0600 ERROR: websrvr: Exited 4 ti...

MP18 by Cyber Elite
  • 10017 Views
  • 4 replies
  • 0 Likes

Resolved! Getting this from Vendor device eventid eq ike-recv-p1-delete

After Phase 1 success as Responder in PA I am getting below event id ( description contains 'IKE protocol notification message received: INITIAL-CONTACT (24578).' ) and ( eventid eq ipsec-key-expire ) eventid eq ike-recv-p1-deletedescription contains 'IKE protocol phase-1 SA delete message received from peer. cookie:5b34d3ab8d000c44:6d1b2079...

MP18 by Cyber Elite
  • 10825 Views
  • 7 replies
  • 0 Likes

Resolved! show vpn ike-sa gateway Corp

when i run above command it says Show IKEv1 IKE SA: Total 6 gateways found. 1 ike sa found. Show IKEv1 phase2 SA: Total 6 gateways found. 65 ike sa found. What does above number tell us ?

MP18 by Cyber Elite
  • 4360 Views
  • 4 replies
  • 0 Likes

Resolved! Every few mins in system logs eventid eq ike-nego-p2-succ

We have IPSEC tunnel to vendor every few mins in system logs i see eventid eq ike-nego-p2-succ and ( description contains 'IKE phase-2 negotiation is succeeded as initiator, quick mode. Established SA: 193.x.x.x.[500]-174.112.x.x[500] message id:0x8988FE61, SPI:0xB410457F/0x01E085CD.' )

MP18 by Cyber Elite
  • 5604 Views
  • 9 replies
  • 0 Likes

Resolved! Tunnel went down while PA was responder

Seems PA was responder and tunnel went down today at 9.29.22 MSTbelow are logs We were responder so we should know the reason for tunnel going down 72%2019-05-10 09:28:16.772 -0600 [PNTF]: { 14: }: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=62c9b46a9f36df3e 9df9f7aad21a9e9c (size=16).2019-05-10 09:28:17.334 -0600 [PNTF]: { 12: ...

MP18 by Cyber Elite
  • 6687 Views
  • 7 replies
  • 0 Likes

Resolved! Content / Database Versions Do Not Match

Every week I recieve these emails while the PAN firewalls do their weekly updates, is there a way to not recieve these e-mails, the time stamps are exactly the same from each device, as they are upgrading at the exact same time. Is there a setting in Panorama that can eliminate these needless messages?Thanks,Craig

Resolved! How to...(VPN globalprotect)

Hello guys, I'm trying to do something and i'm not really sure if it's possible. Let's get into... I have an url that is for example: "www.myweb.com". Our partner is hosting that web and with his firewall is just allowing us the access through our IP WAN. Everything works fine, we can access, but the problem comes when we tried to do it through ...

  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels