General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Device Group name change query

Hi, I want to confirm if I change the device name of existing device group in Panorama, will it create any issue in the configurations or settings. Thanks

Resolved! Cisco ISE integration for UserID

Greetings all, I'm wondering if anyone else is using Cisco ISE for network access control and has experience integrating it to publish User ID to the Palo Alto firewalls? I saw a support article for it but the regex appears to be out of date. I found another guide somewhere else that suggested using field identifiers instead of regex which is w...

jsalmans by L4 Transporter
  • 32986 Views
  • 13 replies
  • 0 Likes

Wait time

What's up with the horrendous wait time to speak to a tech regarding a case? Been on hold for over two hours.

Getting Inbound connections from Malicious Palo Alto IP

Hello all,I've recently detected inbound traffic from an IP address 147.185.132.201 where the ISP is showing as Palo Alto Networks, Inc. The IP has a malicious reputation over VT, AbuseIPDB, and IPVoid. Can anyone with information about this IP address share their insights? Have you noticed any unusual activity associated with this IP? Are there...

Certificate Expired Warning in Deploy but all certificates are good

The Sub CA Certificate of our old internal PKI expired a few days ago. It didn't have any impact and wasn't a security risk, but today i cleaned everything up. Problem is, i still get a warning on one of our firewalls. Certificate %redacted% in shared expired on %redacted% I triple checked the configuration and the new certificate i configur...

Resolved! How to request a URL filtering change to High-Risk?

How does one submit a request to PA to recategorize a URL to the High-Risk category? The root domain associated with CVE-2023-6961 (WordPress XSS vulnerability) is categorized as High-Risk, but the subdomain actually serving the exploit is categorized as Insufficient-Content, Low-Risk. The Request Change function in the URL Filtering test does...

Resolved! Management Interface Settings - Can't Change?

Got a weird one here, I'm using templates from Panorama but I have one firewall, in an HA pair, that has Telnet enabled on the Administrative Management Services section and it should be set to OFF per my template. The interface is showing "Template Values Overridden" and when I go into the configuration and try to re-sync the template (hence d...

R.Nill by L1 Bithead
  • 2956 Views
  • 4 replies
  • 0 Likes

VM series log not detected in Azure Sentinel

Here’s the problem statement: 1] If Syslog UDP 514 is configured in PAN FW on-prem and vm-series, There were missing logs in AZ Sentinel, Incomplete logs is experienced and there were packets fragmentation.2] MS Sentinel support recommended to changed syslog transport UDP to TCP 514.3] If Syslog TCP 514 is configured in PAN FW, On-prem able to s...

Resolved! Log Container Page Only - impact?

Hello, Has anyone experienced a negative impact from having the "Log Container Page Only" feature checked/turned on? I ask because of the warning, "If you enable the Log container page only option, there may not always be a correlated URL log entry for threats detected by antivirus or vulnerability protection." Do you have examples of instan...

Google URLs not-resolved

I know this has happened a few times over the last year but is anyone currently experiencing issues with various google urls getting flagged as not-resolved again? The ones that seem to be popping up the most for use are various drive.google.com, docs.google.com and googleapis.com. Cli shows base-db as not resolved and cloud db shows correct. ...

Claw4609_0-1704737501769.png
Claw4609 by L5 Sessionator
  • 3040 Views
  • 4 replies
  • 0 Likes

Resolved! Error The number of PBF return addresses cannot exceed 8 paloalto

HI team We are migrating a FW Paloalto model 3250 to a model 1420 but I find a limitation, in the previous model I had 16 PBF but now it only allows me 13. Do you know if it is a limitation of the model? 2024-12-10 17:45:19.569 +0100 Error: pan_pbf_policy_from_obj(pan_config_parser.c:18674): The number of PBF return addresses cannot exceed ...

Alpalo by L4 Transporter
  • 1833 Views
  • 1 replies
  • 1 Likes

cannot commit as one service keeps shutting down

first here is the specs: Firewall : Pa1410 version : 11.2.4-h1 here is all the details of the issue : 1- device > syslog -> syslog profile -> custom log format -> and changed the default format of GlobalProtect to location=$location, portal=$portal, actionflags=$actionflags, attempted_gateways=$attempted_gateways, auth_method=...

  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels