General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4116 Views
  • 0 replies
  • 0 Likes

Resolved! SSO Activation

I am writing to request assistance in activating Single Sign-On (SSO) for my Paloalto account. I need access to log support cases with Palo Alto Networks. It is showing error as shown below: Best RegardsJames

JZhaoJunyuan_0-1734332073754.png

Bulletproof External Dynamic Lists only has 4 entries

Hi, These are the only entries in the default "Palo Alto Networks - Bulletproof IP addresses" EDL. Is this normal? 5.188.205.0 - 5.188.205.25580.85.155.0 - 80.85.155.25586.105.227.0 - 86.105.227.25591.237.249.0 - 91.237.249.255 Dynamic updates seem to be dynamically updating as expected. tia

Resolved! Predefined report show like ipv6

Dears, This report is generate by "Monitor → PDF Reports" every day. Today,I receive this file,but the ip address like ipv6. I don't modify any setting with report yesterday. How to modify to ipv4? And I want to send this report after modify "PDF Reports",but I can't find the function of send PDF Report manual. Thanks. Device:PA-820 PAN-O...

PA-820 Report.png
yasheng by L1 Bithead
  • 3577 Views
  • 7 replies
  • 0 Likes

Resolved! Panorama - unable to use log disk

New Panorama 9.0.5 install. Panorama was successfully installed in a VM on a single disk. Needed space for a log volume so a second disk was created and attached to the VM. VM was rebooted, disk added using “request system disk add sdb”, disk is visible via “show system disk details", shows Admin Enabled state. When attempting to use this volume...

How can I get OVA image file

I am trying to do the PCNSA cert and need the OVA image file. My account does not have the software updates section. We do have a Palo Alto firewall at my work but it’s not registered under me. I am doing the pcnsa cbt nuggets with Keith Barker and need that file to run the FW as a VM. Please help on what I need to do to get my account going wit...

bjfoste1 by L1 Bithead
  • 3238 Views
  • 5 replies
  • 0 Likes

Resolved! No valid AceMlc2 config: SC 1 (AceMlc2): Config not valid

Hello all, I need some help troubleshooting these low severity logs that keep popping up. This is happening on a PA-3220 which is running 10.2.9. The output of show ctd-agent status security-client is: [snip] Security Client AceMlc2(1)Current cloud server: ace.hawkeye.services-edge.paloaltonetworks.com:443Cloud connection: disconnectedConfig...

paolopoz by L1 Bithead
  • 8666 Views
  • 4 replies
  • 0 Likes

"IP Tag" Log

Does anyone know what the "IP Tag" log is exactly used for? I know its related to dynamic address objects but what is the log used for?

2017-04-05_13-52-42.jpg

Resolved! Device Group name change query

Hi, I want to confirm if I change the device name of existing device group in Panorama, will it create any issue in the configurations or settings. Thanks

Resolved! Cisco ISE integration for UserID

Greetings all, I'm wondering if anyone else is using Cisco ISE for network access control and has experience integrating it to publish User ID to the Palo Alto firewalls? I saw a support article for it but the regex appears to be out of date. I found another guide somewhere else that suggested using field identifiers instead of regex which is w...

jsalmans by L4 Transporter
  • 31198 Views
  • 13 replies
  • 0 Likes

Wait time

What's up with the horrendous wait time to speak to a tech regarding a case? Been on hold for over two hours.

Getting Inbound connections from Malicious Palo Alto IP

Hello all,I've recently detected inbound traffic from an IP address 147.185.132.201 where the ISP is showing as Palo Alto Networks, Inc. The IP has a malicious reputation over VT, AbuseIPDB, and IPVoid. Can anyone with information about this IP address share their insights? Have you noticed any unusual activity associated with this IP? Are there...

Certificate Expired Warning in Deploy but all certificates are good

The Sub CA Certificate of our old internal PKI expired a few days ago. It didn't have any impact and wasn't a security risk, but today i cleaned everything up. Problem is, i still get a warning on one of our firewalls. Certificate %redacted% in shared expired on %redacted% I triple checked the configuration and the new certificate i configur...

Resolved! How to request a URL filtering change to High-Risk?

How does one submit a request to PA to recategorize a URL to the High-Risk category? The root domain associated with CVE-2023-6961 (WordPress XSS vulnerability) is categorized as High-Risk, but the subdomain actually serving the exploit is categorized as Insufficient-Content, Low-Risk. The Request Change function in the URL Filtering test does...

  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels