General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 244 Views
  • 0 replies
  • 0 Likes

Credential Theft Protection and SSL Errors

I am currenlty doing a proof-of-concept test for the Credential Theft Protection feature. SSL decryption is configured and working. I can get the system to re-direct to the Anti Phishing Continue Page. However, that page uses the SSL cert associated

...

Resolved! Device Certificate OTP stuck in progress

Hi,

so i have a panorama vm on 10.1.10-h2 managing 4 NGFWs on VMs in azure.

need to install device certs.

in CSP i did the OTP and install for the panorama first and this went to plan. cert installed and happy.

then I did the OTP process for the mana

...

PA_nts by L3 Networker
  • 1532 Views
  • 2 replies
  • 0 Likes

Throughput means through show system statics session.

Hello all,

I checked the throughput information of CLI > show system statistics session as part of a way to check real-time traffic volume in Paloalto during migration work.

There was an inquiry from the customer about exactly what the throughput figu

...

Resolved! PAN-OS Certificate Expirations Clarification

With all the recent certificate update requests over the past couple months, the documents have become a bit confusing. Previously the below article stated version 10.1.11-h4 was a fix but now the article (updated 2/22/24) says version 10.1.11-h5 is

...

Prove the firewall innocent?

Hello,

We have communication from load balancer to 2 servers called S1 and S2.

Both S1 and S2 have same Windows Server version and have exact same patch level.

Both serve a web-service hosted on their IIS.

On Palo firewall, we have App-ID based rule

...

allowing MS product activation and denying web access

I have a network that I want to allow MS product activation to work but web browsing and other internet activity to be denied.

I have two main security policies that apply just to this network although DNS and ntp is also allowed:

The first one is an a

...

kjh by Not applicable
  • 9999 Views
  • 3 replies
  • 0 Likes

Resolved! QoS Policing on one of interface.

I want to establish a 600Mb egress rate limit on a specific interface. Is this the correct procedure to implement and enforce the policy? Since I'm new to setting up QoS on Palo Alto devices, I would appreciate some guidance. Additionally, I'm curiou

...

JasonKu_0-1708801333211.png
JasonKu_1-1708801379846.png
Jason.Ku by L0 Member
  • 719 Views
  • 1 replies
  • 0 Likes

Resolved! VPN Global Protect Portal - two VR and one VR environments

VPN Global Protect Portal - two VR and one VR environments

 

Hello, good afternoon.

As always, thanks for the help, the support, your time and collaboration always.

 

I tell you I have the following case, which has me very restless, since I always tr

...

Metgatz by L4 Transporter
  • 3882 Views
  • 2 replies
  • 0 Likes

Layer 2 subinterfaces w/ Vlan interface for routing.....

Say I want to connect this port to a switch downstream (trunk), with clients hanging off of switch on access ports and use vlan interfaces for routing. Switch is set to trunk allowing relevant vlans, the firewall interface is subinterfaced (layer2) w

...

VK9H13 by L2 Linker
  • 829 Views
  • 1 replies
  • 1 Likes

Resolved! SSL decryption Certificate expired

Hi Team,
We have PA self signed certificate in the firewall being used for SSL Decryption, the certificate is about to expire
From GUI we can able to renew for another one year but our concern
  • Will it automatically replace the existing certificate in en
...

VishnuPS by L3 Networker
  • 4412 Views
  • 3 replies
  • 0 Likes

QUIC decryption? A TCP replacement

It seems like QUIC is going to become main stream, Its not just this linked video, I am seeing QUIC related stuff increasingly now. As per docs I see even for 10.2 its advised to block udp 80/443 and block QUIC. I would guess Palo Alto bringing QUIC

...

raji_toor by L4 Transporter
  • 5782 Views
  • 3 replies
  • 1 Likes

GlobalProtect Version

Hi Team,

We are currently running 6.0.5 GP client version, now we are planning to upgrade the version in Prisma. May i know which version is the best version as we faced few issues in 6.2.0 for different customer not sure which is the better version

...

  • 23627 Posts
  • 107 Subscriptions
Top Liked Authors
Labels