General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4237 Views
  • 0 replies
  • 0 Likes

Resolved! AutoFocus-Hosted MineMeld: access to API

Hi, we have an autofocus instance with MineMeld application enabled. I'd like to call this Minemeld's API in order to get some metrics for our internal reports about Intel. With self-hosted Minemeld is easy, but, is it possible with AutoFocus-Hosted application? I don't know the URLs to make the request, the user or authotization header to ...

Major issue PanOS 8.1.3: Network intefaces go down

We have some issues for some users with the globalprotect vpn to connect to our PA-3260 firewall.To solve this issue technical support told us to upgrade to our PanOS from 8.1.2 to 8.1.3.We did this morning and everything went fine till 1PM.From some users we received there was a connectivity issue to internet, other users told us they couldn't ...

ZEBIT by L3 Networker
  • 10579 Views
  • 12 replies
  • 2 Likes

Cisco QSFP adapters

Has anyone used these Cisco QSFP adapters for the QSFP and HA2 ports? Officially not supported but they will probably work as they support the same QSFP standard. The PA5220 HA2 uses an HSCI/QSFP port. We want to use a Cisco BiDi QSFP Transceiver here:Solution with Cisco 40-Gbps QSFP BiDi TransceiverThe Cisco QSFP BiDi transceiver, shown in Figu...

djon by L1 Bithead
  • 10541 Views
  • 4 replies
  • 0 Likes

Unable to contact updates.paloaltonetworks.com or staticupdates.paloaltonetworks.com

Hello, I am unable to contact updates.paloaltonetworks.com or staticupdates.paloaltonetworks.com Based on the following articles I should be able to ping the two addresses as part of my testing. https://www.paloaltonetworks.com/documentation/80/virtualization/virtualization/license-the-vm-series-firewall/activate-the-license/activate-the-license...

HTTPS and SSH Traffic Is Not Working

Hello,I’m new to the Palo Alto community. I’m hoping someone would be able to help me with this problem we are having.We have a Palo Alto PA3060 firewall that has a Layer 3 interface configured with a sub-interface that is also Layer 3 and tagged with VLAN250. The sub-interface is assigned an IP address of 192.168.250.1. On the other end of the ...

PaloAlto_Network_Drawing.png

URL Filtering

Is anyone using the URL filter in replace of a proxy? I made this attempt but ran across an issue with user I’d mapping not being mapped accurately or fast enough and it was causing issues with users being allowed internet access. I want to only allow a certain AD group internet access. Has anyone been successful with this?

negate destination IP's

@reaper @BPryIs you create an allow rule and then select to negate the destination IP's does that mean those IP's are blocked?

jdprovine by L4 Transporter
  • 4596 Views
  • 6 replies
  • 0 Likes

PA-3220 HA-2 Port Configuration

I have purchased a pair of PA-3220 to run as internet gateway. I planned to configure active/passive for HA but I got the status that the HA-2 link is down and I found on website we need to use HSCI port as HA-2(Data Link). Unfortunately, I haven't purchase any cable or sfp module for HSCI. So, there are any option to configuer other port as as ...

Putmano by L0 Member
  • 5905 Views
  • 4 replies
  • 0 Likes

Global Protect Agent and SSID

Hi I have configured GP agent with internal and external adresse to seamlessly work w/ always on for my endpoints and this works great. And users can not connect to other networks w/coppper cable without the internal GW. And SSID has to be punched in manually. But one challange;How do i protect new endpoints when its getting windows image from ...

Resolved! Traffic originate from PaloAlto Firewall

Hello Experts - Can you clarify how to configure Paloalto firewall to source traffic from Data Interface rather than Management Interface Scenario: When Firewall send syslog message to exernal Syslog Server, the Firewall has to be configured to have Source IP address of Internal Interface instead of Management Interface. It is similar command in...

GlobalProtect timeouts.

When configuring a timeout on Globalprotect, the documentation reads: On the GlobalProtect Gateway Configuration dialog, select AgentTimeout Settings and then configure the following settings:Modify the maximum Login Lifetime for a single gateway login session. The default login lifetime is 30 days—during the lifetime, the user stays logged in a...

Windows Install Failing

Hopefully someone can help or point me in the right direction. We've been askedby one of our clients to use Global Protect but the client is failing to install on some PCs. They are running Windows 10 Pro and get the following error when trying to install

error.jpg
monkums by L1 Bithead
  • 3652 Views
  • 5 replies
  • 0 Likes
  • 24358 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels