General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4229 Views
  • 0 replies
  • 0 Likes

Resolved! Are there signature release for following vulnerabilities?

Hi,I'm Tomoyuki Nakamura. Are there any plans to release signature for the vulnerabilities below?.These were not listed in THREAT VAULT or Security Advisory. CVE-2024-11639CVE-2024-11772CVE-2024-11773CVE-2024-37377CVE-2024-9844CVE-2024-37401CVE-2024-11633CVE-2024-11634CVE-2024-47578CVE-2024-47590CVE-2024-54198CVE-2024-47586CVE-2024-54197 B...

Resolved! using Subinterfaces in different Vsys inder same phy interfa

Hello Team, We are implementing a physical interface under vsys Data-center , with subinterface (Eth1/200 --> Data-center) and other subinterface (Eth1/300--DeptA) is assigned to other vsys called DeptA. knowing that the physical interface is without zone . How does the communication will be authorized in the security policies and with the ...

Support wait times and SLAs

I am in the call queue since 3 hours. Called in yesterday and left a call back number, but never received a call back. Does anybody have a similar experience lately?

uvolk707 by L1 Bithead
  • 1769 Views
  • 4 replies
  • 0 Likes

Resolved! Pipe a command and using match regular expressions

Dear experts!I'm trying to compile a match which matches the following regexp: (debug|monitor).(global|level|pcap|detail\.enable) but it seems like it does not support capturing groups. I've searched for a manual for the match command but struck out. The end game here is to use it to filter show system state to capture lines containing:debug.gl...

epacke by L0 Member
  • 16456 Views
  • 4 replies
  • 0 Likes

Equipment: PA1410 (PAN-OS 11.1.4-h1) Threat Logs is not monitored every time

Equipment: PA1410 (PAN-OS 11.1.4-h1)Issue: Some threat logs are not seen in output.Details:・The vulnerability protection alert test was performed 4 times on PA1410 with reference to the following page.https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpPCAS-1st time (2024/12/14 15:29:58): A threat log was seen as output ...

Resolved! PA-440: Bottom Face Screw Mounting Footprint

I am looking to add the PA-440 to the Elevator Model I am working on, but because of limited real-estate, we do not have room for standard 1U server rack, and have to create a custom enclosure to house the firewall. I am looking to mount the PA-440 to the enlcosure, but cannot determine what is the bottom facer screw mounting footprint as seen...

Resolved! Importing list of Blocked IP's and URL's into EDL

Hi, I want to be able to quickly blacklist a bunch of URL's and IP's from internal uers going out to the internet. What is the best way to achieve this? Would I just place them all in a file text file, and just import them to a custom External Dynamic List? Thanks for the help in advanced.

Resolved! Panorama Disk

We have Panorama VM with 1tb data disk. I am not able to add 2tb disk. Gives me an error due to this 1tb disks. What can i do?

chens by L3 Networker
  • 1824 Views
  • 3 replies
  • 0 Likes

Resolved! OSPF route suppression

Hello, I have a question about suppressing OSPF routes. We have a PA-3410 with software version 11.1.4-h7 and we have configured OSPF neighbourship with the Huawei switches. All OK, in OSPF we advertise static and connected routes, but we want to suppress the announcement of WAN networks with public IP. I found this topic https://knowledgebase.p...

snmpd.log error Solarwinds monitoring PA1410

I am investigating an issue with Solarwinds monitoring a PA1410 , in the snmpd.log i see the following : 2024-07-18 09:39:45.403 +0100 Error: pan_snmputil_sysd_fetch_modified_obj(pan_snmputils.c:1528): Unable to fetch sw.cmd.*.dp*.counter={'interface':'ethernet1/16'}: NO_MATCHES2024-07-18 09:39:45.403 +0100 Error: pan_interfacedata_build_sys...

Ridwaan by L1 Bithead
  • 1228 Views
  • 1 replies
  • 0 Likes

Resolved! Importing root certificate in Panorama 10.2.15 not working/ EDL hosting service.

Hi, I have a strange issue i am trying to import the globalsign root certificate into panorama device template. I am following this article (also doubt the global sign is needed because when i browse manualy to the EDL the url is singed by Google) Configure the Firewall to Access an External Dynamic List from the EDL Hosting Service (paloaltonet...

zGomez by L3 Networker
  • 9111 Views
  • 6 replies
  • 1 Likes

Converting SonicWALL DNAT configuration to Palo Alto DNAT Configuration

Hi to all the expert, I am new to Palo Alto firewall. I need a guidance from the expert to guide how to converting SonicWALL DNAT rule to the Palo Alto DNAT rule. SonicWALL DNAT Config: Original Source: Any Translated Source: Original Original Destination: x8:V292-IP (10.204.44.33/27) Translate Destination: Original Original Server: Ping Tran...

GWong4 by L2 Linker
  • 907 Views
  • 1 replies
  • 0 Likes

Long commit times when changing DNS settings

On an HA pair of PA-460, the commit time is usually around 60 seconds, when changing the DNS settings to something that is not reachable, the commit time changes to 10 minutes+. I've tried replacing the primary but the issue is the same. When I looked at the device server logs there was a continual message with the number incrementing: debug: ...

s0lselcia by L4 Transporter
  • 1717 Views
  • 3 replies
  • 0 Likes

Unable to discovered ICMP and SNMP from solarwinds. Discovered in Solarwinds as ICMP Only.

dc1-fld-sdw-1adc1-fld-sdw-1bUnable to discovered ICMP and SNMP from solarwinds.Discovered in Solarwinds as ICMP Only.we have checked there is no firewall block and verifed SNMP2 configurationsits looks good but unable to discover ICMP and SNMPSerial Number 026601-000614-9922 Product ION 9200 OS Release CGX 6.1.9

  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels