General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4118 Views
  • 0 replies
  • 0 Likes

IPsec VPN with AH generates core files

Hi team, I have two VM-50 v9.01, one in SiteA and another in SiteB. I set up an IPsec tunnel between them with: IKE-v1 : phase1 (aggressive mode) and phase2 (quick mode) with ESP. it works fine and I'am able to ping from a vlan in SiteA to another vlan in SiteB . I wanted to test AH instead of ESP. However everytime I want to send a ping from...

Resolved! cfg export + master key hash

Dear Community, I have found this side note in an article regarding the master key on the firewall. "Without the Master Key, when a configuration is exported from a firewall, the password is hashed and can be copied." Basically its the exact answer of the question I originally had. I am facing a situation where a firewall crashed. I have receive...

Rboehme by L2 Linker
  • 4099 Views
  • 1 replies
  • 0 Likes

Unable to access the GUI of WF 500

Hi Team In WF 500, we are unable to access via GUI but we have access via CLI (Putty). WF 500 os version is 8.0.6. Please refer the attached error snapshot. Kindly help us to resolve the issue. Thanks & RegardsMohammed Ashik

PAN Wildifre 1 GUI Error.jpg

Resolved! Intel MDS Attack

Can anyone help to provide more information if below CVE are impacted in Palo Alto product line?Intel Microarchitectural Data Sampling Vulnerabilities (Fallout, RIDL, Zombieload) (CVE-2018-12126 , CVE-2018-12127, CVE-2018-12130, CVE-2019-11091)

Collect syslog information

Hi, We are going to add a new syslog server in PA config. So we would like to do a bit audit about PA supporting syslog sessions.What si the best way to know:-Volume of traffic per day for syslog-Top10 destination syslogs-..... thanks.

BigPalo by L4 Transporter
  • 3654 Views
  • 3 replies
  • 0 Likes

Overlap-Zone difference Vsys

HI Expert , I would like to know that it can be possible about overlap zone name but difference Vsys such as I would to defind name Zone "Trust" on vsys1 and would to zone name "Trust" on vsys2 as well Please suggest to me Thank you

Resolved! Alert When Accessing Application

Good morning! I'm trying to figure out if it's possible to throw an "alert" log entry when a specific application is accessed. I know it can be done with categories, but I'd like to do the same with specific applications. I can always filter my Traffic Monitor for that application, but sometimes it's much more convenient to set the "alert" statu...

GCSS-RT by L2 Linker
  • 4129 Views
  • 4 replies
  • 0 Likes

Resolved! cloud based proxy via IPSEC vpn and the way DPD is implemented on palo alto

Hello.so I've got a curious little problem and wanted to get some opinions before possibly creating a feature request at PA. we have a customer using a palo alto as his main firewall.and a certain cloud based proxy as their proxy.connecting to this proxy is done via IPSEC vpn tunnel.our customer noted that sometimes they lose connectivity to the...

Do you need Windows Server 2019 support for User-ID?

If you think you will need Windows Server 2019 support for User-ID, ask your PA rep to vote for feature request ID# 11012! We just upgraded all of our domain controllers organization-wide to Server 2019 only to find out that User-ID does not work with Server 2019 DCs. Now we must replace all of the DCs yet again with Server 2016 DCs in order to ...

GabeC by L1 Bithead
  • 10942 Views
  • 10 replies
  • 1 Likes

Best Practice: Allowing a known application together with a custom service.

Let's say we have 2 zones seperated by our PA firewall, Zone A and Zone B. Traffic between Zone A and Zone B is only allowed for some applications/services from dedicated devices in Zone A to dedicated devices in Zone B. We have a custom Service which uses TCP port 7777 named CustomService1. Device 1 in Zone A needs to access Device 2 in Zone B ...

Import LDAP Groups

All, I am trying to import my LDAP groups, but don't want all of them. I have too many groups to put them in the Include list. I also have a large number of local.admin and Folder Access security groups. SInce I can't filter by OU, how can I filter using negate and wildcards for the security groups I don't want? I am trying to use something l...

Zone protection - Show hops between source & dst.

Hello, I want to see the hops between the source and destination when I do tracert from my PC to an IP.The tracert is shown as completed. I followed the following kb but didn't work: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClfsCAC I disable Zone protection from the Zone initiating the conection(Trust) a few mi...

2019-05-16 16_31_47-C__Windows_system32_cmd.exe.png
upatino by L1 Bithead
  • 3040 Views
  • 1 replies
  • 0 Likes

Traffic is not getting Natted DIPP

We have Single Outbound PAT configured for internet traffic for all internal users.So all users traffic use the same Outbound PAt while going to internet but one traffic is not getting natted with this NAT policy There is no PBF configured, its simple NAT (Outbound PAT DIPP), Security Policy (From trust to untrust).PAN-OS 8.1.6 h2Request to fine...

  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels