General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4123 Views
  • 0 replies
  • 0 Likes

Resolved! ssl-decrypt exclude-cache ---SSL_CLIENT_CERT

when i run below command show system setting ssl-decrypt exclude-cache VSYS SERVER APP TIMEOUT REASON DECRYPTED_APP PROFILE EXCLUSION_LIST_MATCH13.71.172.130:443 ssl 42077 SSL_CLIENT_CERT undecided default No does this mean that PA can not decrypt the ssl traffic due to client cert? what can be actual reason behind this?

MP18 by Cyber Elite
  • 5135 Views
  • 2 replies
  • 0 Likes

Resolved! Decryption Profile ----No decryption

i am using default decryption profile. Under tab no decryption i see below block sessions with expired certs need to understand when does this setting is used when i am doing the ssl decryption or not doing ssl decryption? also does it only apply to ssl decryption policy ?

MP18 by Cyber Elite
  • 3752 Views
  • 4 replies
  • 0 Likes

show counter global | match proxy

Need to verify if below output looks good from ssl decrypt show counter global | match proxyctd_fwd_session_proxy_deny 384306 0 info ctd pktproc Content forward: action init denied for decrypted sessionsctd_switch_proxy 4 0 info ctd pktproc switch to proxyproxy_process 217482856 146 info proxy pktproc Number of flows go through proxyproxy_inval...

MP18 by Cyber Elite
  • 4289 Views
  • 3 replies
  • 0 Likes

Resolved! LDAP over IPsec?

Hello. I'm trying to configure UserID via our domain controllers in AWS. The setup:We have an HA PA-820 pair on-prem connected to our domain in AWS via a redundant IPsec tunnel. Traffic is passing between LAN and IPsec zones; on-prem workstations can ping both domain controllers. I have configured an LDAP Server Profile, an Authentication Prof...

Tunnel Migration

Hello, I am going to migarte my production firewall PA5050 into new location, already done the setup of firewall. Can any one please suggest the best possible way to migrate my all IPVPN tunnels in New Palo Alto, is basilcy to move one palo alto to another one, do we have a specified tool for that? or i need to do it manually. Thanksamit

Resolved! Working temperature

Hello everyoneWhat are the normal working temperature for palo-alto pa-820, pa-500 and pa-3020 ? It seems that it's beyond to the normal specifications ( above 40 °C )Thanks's you for your answer

Learner by L1 Bithead
  • 7038 Views
  • 6 replies
  • 0 Likes

Resolved! Microsoft authentication issues with Akamai IPs blocked by Palo Alto (?)

There was a massive outage on Microsoft sites. It has been resolved now, but I was wondering if this something related to Palo Alto Dynamic updates.https://www.reddit.com/r/sysadmin/comments/9nc9oj/microsoft_authentication_issues_with_akamai_ips/We just got nailed this morning with issues caused by Palo Alto Firewalls adding an Akamai IP/IP-rang...

Resolved! AutoFocus-Hosted MineMeld: access to API

Hi, we have an autofocus instance with MineMeld application enabled. I'd like to call this Minemeld's API in order to get some metrics for our internal reports about Intel. With self-hosted Minemeld is easy, but, is it possible with AutoFocus-Hosted application? I don't know the URLs to make the request, the user or authotization header to ...

Major issue PanOS 8.1.3: Network intefaces go down

We have some issues for some users with the globalprotect vpn to connect to our PA-3260 firewall.To solve this issue technical support told us to upgrade to our PanOS from 8.1.2 to 8.1.3.We did this morning and everything went fine till 1PM.From some users we received there was a connectivity issue to internet, other users told us they couldn't ...

ZEBIT by L3 Networker
  • 10440 Views
  • 12 replies
  • 2 Likes

Cisco QSFP adapters

Has anyone used these Cisco QSFP adapters for the QSFP and HA2 ports? Officially not supported but they will probably work as they support the same QSFP standard. The PA5220 HA2 uses an HSCI/QSFP port. We want to use a Cisco BiDi QSFP Transceiver here:Solution with Cisco 40-Gbps QSFP BiDi TransceiverThe Cisco QSFP BiDi transceiver, shown in Figu...

djon by L1 Bithead
  • 10371 Views
  • 4 replies
  • 0 Likes

Unable to contact updates.paloaltonetworks.com or staticupdates.paloaltonetworks.com

Hello, I am unable to contact updates.paloaltonetworks.com or staticupdates.paloaltonetworks.com Based on the following articles I should be able to ping the two addresses as part of my testing. https://www.paloaltonetworks.com/documentation/80/virtualization/virtualization/license-the-vm-series-firewall/activate-the-license/activate-the-license...

HTTPS and SSH Traffic Is Not Working

Hello,I’m new to the Palo Alto community. I’m hoping someone would be able to help me with this problem we are having.We have a Palo Alto PA3060 firewall that has a Layer 3 interface configured with a sub-interface that is also Layer 3 and tagged with VLAN250. The sub-interface is assigned an IP address of 192.168.250.1. On the other end of the ...

PaloAlto_Network_Drawing.png

URL Filtering

Is anyone using the URL filter in replace of a proxy? I made this attempt but ran across an issue with user I’d mapping not being mapped accurately or fast enough and it was causing issues with users being allowed internet access. I want to only allow a certain AD group internet access. Has anyone been successful with this?

  • 24336 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels