General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4110 Views
  • 0 replies
  • 0 Likes

Resolved! Clear Alarm LED?

Hey all, I have a PA-220 that has the Alarm LED lit. The cause was that someone tried to insert a power supply from a PA-200 into the PA-220. Thinking that what happened is that a brief short was created which triggered the alarm. All other LEDs are good. Anyone know a way to turn off the Alarm LED or clear it from the CLI or GUI? Thought m...

cafowler by L2 Linker
  • 13675 Views
  • 4 replies
  • 0 Likes

Virtual router to virtual router communication

Hi, We have a setup in which a switch is used for interconnecting several virtual systems to a perimeter router. The switch is going end of life and needs to be replaced. Is it possible to replace this switch with a "Virtual router" in Palo Alto?Below is the setup: 1. All virtual systems have their own virtual routers. 2. Default routes from th...

Inter vr-routing.jpg
MGRashmi by L2 Linker
  • 9035 Views
  • 3 replies
  • 0 Likes

Panorama Pan OS Automatic Update to Managed Firewall Devices

Hi, I currently manage a group of Palo Alto FW Devices (5220, 800, 3200 and 200 series) via a Panorama M-100 Series Appliance. I would like to know if Panorama pushes automatically PAN OS SW Update (at the PAN OS - level only - not AV, AppID or Wildfire signatures) to the managed devices (after having them downloaded from the internet, hence ass...

CarloMun by L0 Member
  • 2694 Views
  • 1 replies
  • 0 Likes

Resolved! Configuring Site-to-Site VPN between two PAs

We recently purchased a PA850 and PA220 to use at two different locations and want to set up a tunnel between the two devices. I am unable to successfully get connectivity between them. I am trying to follow this guide (Site-to-Site VPN with Static Routing ), but I'm not sure if the problem is in my configuration or the physical hardware connect...

CoreyS by L0 Member
  • 3936 Views
  • 2 replies
  • 0 Likes

Multiple copies of Content Update e-mail since 8145

Before I open a support ticket about this, I wanted to check if it was only happening to me or if others have been experiencing the same thing. Up until April 17, 2019 I would only receive a single copy of the daily "Palo Alto Networks Content Update" e-mail, the last of which was version 8144. Since the release of Content Update 8145 on April 2...

fjwcash by L4 Transporter
  • 2458 Views
  • 1 replies
  • 0 Likes

Resolved! PA 5050 Power supply failed and how to see env logs?

On PA5050 we have One of power uspply failed.I have opened RMA with PA. I was using this command to see env logs less mp-log ehmon.log ** Ehmon (v3.0)*2018-07-01 01:43:57.677 -0600 Start time.2018-07-01 01:43:59.679 -0600 Loading: libkernel_error.so... done2018-07-01 01:43:59.680 -0600 Loading: libraid.so... done This doe...

MP18 by Cyber Elite
  • 5178 Views
  • 2 replies
  • 0 Likes

DNS Proxy Configuration with VPN

Hi, I'm trying to route to some internal domain controllers for domain local DNS, and public DNS servers for everything else. This seems reasonably straight-forward except that when I specify the internal network IPs of the Domain DNS servers, they timeout all requests for domain DNS when looking up via the Palo DNS proxy. All other DNS resolves...

Envisian by L0 Member
  • 3603 Views
  • 1 replies
  • 0 Likes

Server Response Inspection for HTTPS/VPN/Encrypted Protocols

Hello, we are experiencing slow/failed downloads and slow/failed file transfers over protocols like HTTPS, SSL, VPN. like to hear some opinion regarding "Disable Server Response Inspection", does PAN actually inspect encrypted sessions even though there is no SSL Decryption configured? For DSRI, usual deployments are Inbound traffic toward Publi...

Resolved! high management CPU

Good day community.We are using PAN 820 and the management CPU isn't stable for the last 3-4 days.It's going from 10-15% to 70-100% and stays like this for some time and this happen several times a day.So, the GUI interface is freezing and also I noticed that connection to internet is freezing too. So, speedtest shows a normal speed, while brows...

1.jpg

QoS Methods, Design & Configuration

I have a site that only has 5 megs of upload speed and its constantly getting fully utilized. I know I should probably get more bandwidth from the ISP but thats simply not an option right now. Anyway here is my goal. I would like to make the firewall perform strict allocations of gaurenteed bandwidth for 3 different classes I have configured ...

QoS Statistics.PNG

Resolved! Deal Reg area single sign on error

Hello, so i've been trying to access the deal reg area on the "NextWave Partner Portal".The problem is that i'm always greeted by the following error: Is there some mailing address for these kinds of errors or generally speaking can i do something to fix this? Regards

Bildschirmfoto 2019-05-01 um 17.40.28.png
iweltag by L2 Linker
  • 5329 Views
  • 3 replies
  • 0 Likes

aggressive-cleaning enable but still got disk usage email alert?

i have configured the command below but still got email alert model: PA-5050sw-version: 8.0.9 -NGFW-1(active)> show system state | match aggressive-cleaning cfg.debug-sw-du.config: { 'aggressive-cleaning': True, }domain: 1receive_time: 2019/04/29 05:03:23serial: 002201001803seqno: 6880362actionflags: 0x8000000000000000type: SYSTEMsubtype...

MP18 by Cyber Elite
  • 7863 Views
  • 8 replies
  • 0 Likes

Resolved! IPSEC GUI shows green for both phase 1 and 2 - Need to restart the ipsec to ping across the ipsec

Gui shows both phase 1 and 2 up.Can not ping lan IP at vendor end. when i ping vendor lan ip i see below ( description contains 'IKE phase-2 negotiation failed when processing proxy ID. cannot find matching phase-2 tunnel for received proxy ID. received local id: 0.0.0.0/0 type IPv4_subnet protocol 0 port 0, received remote id: 192.168.46.32/28...

MP18 by Cyber Elite
  • 3453 Views
  • 2 replies
  • 0 Likes

Resolved! Route Monitoring. Possible FR?

Hi I ran into an interesting requirement which (I believe) is not possible with the current path monitoring features for static routes. Here is my scenario... First lets just remove dynamic routing from the equation. For this specific use case dyanamic routing isnt possible between R1, R2 and the PA. PA has a default route configured to R1. R1 i...

4D83FE9B-261E-45EA-9969-1C48BD460C9F 4.png
4D83FE9B-261E-45EA-9969-1C48BD460C9F 6.png
  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels