General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

HA-Palo Alto with 2-Diffrent ISP

Dear Community i have 2-PA configured as HA and need to be redundant for ISP,so i have interface from ISP-A and another one from ISP-B, and from internal service i have VM server that needs only one IP statically work with NAT and 2-Vsys,and using static route for routing, my question is how I can make some change so I can make redundant for th...

CVE in the “Vulnerability protection” profiles

Hi We have a doubt about the inclusion of CVEs in the “Vulnerability Protection” profiles. Currently [CVE-2025-0282][CVE-2025-0283] are not included in the list of signatures. Is it possible to request Palo Alto to include them and is there a procedure? Regards

Alpalo by • L4 Transporter
  • 1166 Views
  • 1 replies
  • 0 Likes

Panorama Error: Number of address group(x) exceeds platform capacity(x)

Hi All, We onboarded the 1 pair of Palo Alto firewalls into panorama. It is successfully onboard. New Template stack pushed successfully to firewall. But the device group was failed with “Error: Number of address group(x) exceeds platform capacity(xx)”. Based on Palo Alto solution is to disable "Share Unused Address and Service Objects with De...

Resolved! FTP Transfer BIOC

Hello Palo Alto LiveCommunity, I’m currently working on a task where I need to create a custom BIOC (Behavioral Indicator of Compromise) and add it to a restriction profile to block FTP command lines. Specifically, I want to prevent FTP-related commands from being executed by monitoring and restricting certain patterns. I also need help with...

Can't find PAN-OS for VM

Hello, In my customer support portal, I can't find the VM version for PAN-OS. Is this related to my license, or did Palo Alto remove it? Thank you! Best regards,Murillo Castiho

murilocastillo_0-1736866502498.png

speedtest is not correctly identified with and without decryption 10.2.4 latest app-id

hi guys, I searched through and it looks like it's an know issue that speedtest.net is not correctly identified by app-id I use app -default setting on the policy The policy cannot really see speedtest.net's traffic and identifies the traffic as ssl, speedtest uses customer port tcp 8080 which is obviously not part of ssl app id defined...

nevolex by • L3 Networker
  • 4600 Views
  • 3 replies
  • 0 Likes

Resolved! after 11.1.5-h1 update, 11.1.5-h1 missing from software list

I recently updated to 11.1.5-h1 on one of my firewalls and the software area updated to show the base versions and previous preferred versions we were running but I am not able to see that I am actually on the 11.1.5-h1 version. I assume it isn't listed since it isn't preferred but then how do I know for sure what version I am running? Do I need...

Setting Up a Remote VPN using Connect Before Logon

Looking for some assistance as I am building out a remote vpn using Connect before logon for my Palo Alto. Does anyone know a simple, easy way to set this up with LDAP. Some article are outdated and some are inconsistent in their approach verse other documents. Appreciate the help.

Unable to commit changes

Hello team, i have been facing the below error when trying to commit changes in palo alto firewall pa-1420 invalid local dhcp setting for monitor destination 8.8.8.8 (module routed client routed phase 1 failure please help.

GlobalProtect fails to connect to backup gateway when portal is down

Hello, PAN-OS 8.1.4; GP 4.1.6I am using only the one VR with dual gateways and ECMP routing enabled with WRR (Weigthed 1/4 (WAN1=50, WAN2=200).I have one portal configured for WAN2. I have two (2) gateways; one on WAN2 and one on WAN1. When WAN2 is up, I can acces the portal and the gateway on that interface.When the portal is down (WAN2), and ...

Hardening Guide for PAN NGFW and Global Protect

For compliance reasons, specifically StateRAMP (and likely FedRAMP in the distant future), I'm looking for any hardening guides or STIG for the PAN NG-FW and Global Protect or even general best practices. I feel odd asking for "security hardening" for a security solution, but I'm just making sure all bases are covered. I've found a couple t...

malmgren by • L0 Member
  • 3088 Views
  • 1 replies
  • 0 Likes

Introducing the LIVEcommunity Support FAQ: Your Valuable Customer Resource

LIVEcommunity is thrilled to introduce its new Support FAQ section, designed to help Palo Alto Networks customers quickly resolve their common queries. You'll find this new area under the Articles section of the main menu: Our goal is simple: provide clear, comprehensive resources that address your most frequent issues. Using data-driven ...

kiwi_0-1719493645523.png
kiwi by • Community Team Member
  • 3247 Views
  • 2 replies
  • 1 Likes
  • 24458 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels