General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4112 Views
  • 0 replies
  • 0 Likes

Resolved! Ping and other Applications in the same rule on a non-standard port

Is there a way to allow ping on a rule that has another application that uses a non-standard port? So for example, if yum uses port TCP 3142 instead of its default tcp/80,21 is there a way I can attach ping to that rule and still have it work? Like on Cisco ASAs you can add icmp as a port/service. Example that doesn't work: Example that does work:

bafergel_0-1632856860628.png
bafergel_1-1632856909682.png
bafergel by L2 Linker
  • 5353 Views
  • 3 replies
  • 0 Likes

Resolved! Upgrade from version 10.2.7-h8 to 10.2.11-h2

Hi, could you help me?I should make a release change from version 10.2.7-h8 to 10.2.11-h2for palo alto 3440. The two firewalls are in HACan you tell me the various release jumps I should do and if there is a procedure to follow?

F.Basco by L0 Member
  • 2278 Views
  • 3 replies
  • 0 Likes

Minimize log size

Hi All, if there's a way how to reduce or minimize the log size sent to the syslog server? if any KB / document / best practice how to reduce logs to sent to syslog server Thank you

deactivate bundle license from PA1410

Hi, I have a problem to deactivate bundle license, because it is... bundle license. Cannot deactivate license key Advanced_Threat_Prevention_2023_11_13.key which is part of bundle without parent_id attribute. What is parent_id attribute and how to find it? where in configuration I can use it? how to deactivate bundle license?

Problem with (URL Category custom), (Destination Address any) and (application any)

We have identified for some time that when rules are created with 'Application: Any' + 'Destination Address: Any' + 'UrlCategory: Custom' for example: Name: Rule_google.com_permitSource Zone: TrustSource Address: AnySource User: AnyDestination Zone: UntrustDestination Address: AnyApplication: AnyService: 443-tcpURL Category: URLC_Google.comURL F...

issues with ssh access from macos/ linux

Hi folks I am having issues with access via ssh from macos/ linux pcs pc ~ % ssh admin@10.10.10.1 Unable to negotiate with 10.10.10.1 port 22: no matching host key type found. Their offer: ssh-rsa ...

Screenshot 2023-05-06 at 10.49.13 AM.png
nevolex by L3 Networker
  • 16727 Views
  • 8 replies
  • 1 Likes

Migrating Panorama license from VM to another

Hi, I need to take the uuid and cpuid from Panorama, but when i run "show system info" its not appears these paramethers. How can i get these uuid and cpuid to transfer the license?????? My PanOs version is 5.1.0 hostname: Panoramaip-address: 192.168.22.191netmask: 255.255.255.0default-gateway: 192.168.22.10ipv6-address:ipv6-link-local-add...

regarding upgrade certificate on 18 NOV

Hello,I want to ask regarding this topic https://live.paloaltonetworks.com/t5/customer-advisories/update-to-additional-pan-os-certificate-expirations-and-new/ta-p/572158Do I have to upgrade the version of PaloAlto ? The version I have is 10.2.4-h3 ? do I need to upgrade this version ? so not to have problems ? Best regards,

Zurattos by L1 Bithead
  • 959 Views
  • 1 replies
  • 0 Likes

🚀 Join us at Palo Alto Networks Headquarters for Ignite - November 14, 2024 🚀

Enterprises are embracing AI to revolutionize their operations, but with innovation comes new cybersecurity challenges. That’s why you can’t miss Ignite on Tour! This event is your gateway to exploring how AI is transforming cyber defenses. Join us to: Defend Against AI-Driven Attacks Secure Employee Usage Protect AI Development Simplify Cy...

emgarcia by Community Team Member
  • 2137 Views
  • 2 replies
  • 4 Likes

How EDL Tor Exit IP Addresses is updated?

Hello, I have noticed the EDL Tor Exit IP Addresses includes only over 1200 entries and the total list of exit nodes is over 12000: https://www.dan.me.uk/tornodes I was wondering based on what criterion Palo Alto is updating the EDL. Does anyone know this? Just because the EDL doesn´t reflect not even near the total number of IPs. Thank you!

Carracido by L4 Transporter
  • 3557 Views
  • 3 replies
  • 0 Likes

Autocommit loop error and interfaces 'connected but down' after upgrade from 11.0.4-h2 to 11.1.4-h1

Hi All, I already posted this in "Discussions > Network Security > Next-Generation Firewall Discussions", but I'm unsure if that is the best place for this issue. https://live.paloaltonetworks.com/t5/next-generation-firewall/autocommit-loop-error-and-interfaces-connected-but-down-after/m-p/599882#M3856 After upgrading my PA-VM VM-...

OKelly by L1 Bithead
  • 3021 Views
  • 3 replies
  • 0 Likes

ESP_TFC_PADDING_NOT_SUPPORTED

Working with PA 5250 and ASA on the other end. The tunnel between is up and communication flows across however we are seeing constant system errors being logged. When we enable the tunnel we get the following. IKEv2 child SA negotiation is succeeded as initiator, non-rekey. Established SA: x.x.x.x[500]-y.y.y.y[500] message id:0x00000C44, SPI:0x...

vnt90 by L2 Linker
  • 45664 Views
  • 10 replies
  • 1 Likes

Issues with decryption on versions higher than 10.2.8-x, TAC no help

Brief summary, we have a pair of 3420's that where on 10.2.8-h3 for several months with no issues, suddenly one day we had issues with what seems to be OOM but was never fully confirmed by TAC, but recommended to upgrade to 10.2.10-hx(we choose 7 as it included the fix and other fixes as its incremental). This seems to have fixed the OOM issue, ...

Log Forwarding - Traffic Works, Others Do Not

I have to be missing something simple, for forwarding logs to a collection server. I can get the traffic logs, no issues, but all the other logs, will not send (Threat, Wildfire...). Do the other logs need some kind of special forwarding, or permissions in the OS? I have all the log types set in one section of the Objects->Log Forward, i am a...

  • 24332 Posts
  • 124 Subscriptions
Top Solution Authors
Labels