General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4116 Views
  • 0 replies
  • 0 Likes

Does PANOS is impacted by DNS Flag day ?

Hello community, Do you know if PANOS is impacted by DNS flag day ? I know CheckPoint and Juniper SRX are impacted by this change DNS config. But I do not see any info provided by Palo alto about that. Best RegardsAndres P.

Suggestion for Panorama update

Within Panorama, while managing client firewalls, routinely the customer wants some variation of the built-in URL category restrictions. While it is great to have so many categories and for the most part they are well apportioned. However, to get around the one off requests for sites to be opened that are in a category that is blocked, it is our...

kprewitt by L1 Bithead
  • 2988 Views
  • 3 replies
  • 0 Likes

Panorama Dynamic Updates SSL Connect Error

After upgrading some of our firewall and Panorama to PAN OS 8.x, we cannot push out dynamic updates from Panorama anymore. We are still able to push out dynamic updates to firewalls running anything below PAN OS 8.x, but nothing within the PAN OS 8.x range. We verified and are not blocking port 28443 anywhere, but are getting an error when tryi...

Dynamic Updates Palo Alto.jpg

User-ID: Require some guidance on best architecture for UserID deployment

Hi everyone.We currently have a small rollout of UserID across 2 of our firewalls across 2 sites. I think there are some gaps in performance and redundancy and I'd like people's opinions about the best way to deploy UserID. Bit of background about our environment. We have approx 40 domain controllers spread across 2 domains over 10-15 sitesUser ...

URL Filteting question

We received an alert about the behavior of the virus. The malicious loader is downloaded from the URL of compromised legitimate sites, where it is disguised as an image.The URL by which the malicious loader is hosted, all addresses end with the string abc.jpg. The string in the URLs where the encryptor is hosted is:hxxp://[anything]/abc.jpg I re...

aaobuhov by L2 Linker
  • 6849 Views
  • 7 replies
  • 0 Likes

Passive Node not showing recent config

Hello, We have a cluster of two palo alto 850, the passive node is not syncing config with the active node despite dashboard claiming they are in sync. Pushing the config from panorama is successful however the passive node does not show the most recent config.How do we fix this issue? Thanks in advance!

User-ID & Fast User Switching?

Is there a best practice for making the Palo able to realize who is currently actually logged onto the machine, or are we forced to disable Fast User Switching for this? (Windows 10) I know currently that if user A logs in, it knows it's A. If we switch user and B logs in, it then knows it's B. However if we switch user back to A, the logs ca...

Resolved! Admin Roles restrict commit from Panorama

We have Panorama managing the firewalls.certain admin role name we do not want them to do commit on the panorama and firewall. so we want if user log into panorama and from there if he go to firewall context or he directly log into firewall thencommit should be disabled. I logged in to the panorma and under panorama admin roles i disabled the...

MP18 by Cyber Elite
  • 3550 Views
  • 2 replies
  • 0 Likes

How to install self signed certificate to Android phones

hello allafter upgrade to new GP 4.1.8 there is some kind of problemThe phones try to connect to portal and gateway and after it we get security warning but we continue and get connectedBut then when we try to connect ones more the GP says it is failed. We must re-enter the login and password againIs it some way to stay connected on GP even if y...

Radmin_85 by L4 Transporter
  • 6045 Views
  • 1 replies
  • 0 Likes

EDL for Free Email services?

I'm looking for an EDL that would have all the free email services (@gmail.com, @yahoo.com, @hotmail.com, etc..) Is anyone aware of anything like this, that is maintained, or would we need to build something?

Resolved! QoS

Hi Community, I am having some queries about PA qos.My requirment is for example, i need to control upload in following scenarioI have a 50 mbps link from ispi have clear and tunnel traffic,My tunnel traffic should not go beyond 25 mbps in any scenario (even if other traffic is not there).Clear traffic shoul always preffered. ie if i have 45mbps...

Packet drops in LAN interface,..

Hi All,For a 5 minutes we are unable to access internet ( even not able to ping next hop router), We observed that there is a packet drops in PaloAlto LAN interface, below snap shows the same. Can any body give the reason for this packet drops?Please help me to identify the root cause,.Thank you,Guru

Gururaj by L4 Transporter
  • 14989 Views
  • 10 replies
  • 0 Likes

Need some suggestion about the routing between 2 internet outgoing interfaces

I recently submitted a case to PA support about 1 of the internet facing interface cannot contact outside nor contact from outside. Use ping to diagnostic and found that the ping (request) and ping (reply) use 2 different route ). This is because the 2 interfaces has its own zone and for different purpose:1. Staff use the 1st data line, and use ...

jeremylo by L3 Networker
  • 2502 Views
  • 2 replies
  • 0 Likes
  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels