General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 1350 Views
  • 0 replies
  • 0 Likes

Resolved! moving policies and objects to another device group

Policies and objects are currently in the wrong device group. able to move everything successfully except for the address objects. i feel the move is pretty self-explanatory, but i have taken the time to read the user guide and still no luck. is ther

...

SFP Compatibility

Hi 

 

I have got 3 firewalls. 5050 and (3020-1 & 3020 -2 HA pair). We are trying to replace the core 6500 switch with meraki 425. and we have got the MA-sfp-10gb-sr and we need to look for supported sfp in palo side. I found one good fit as PAN-SFP-PLU

...

Minemeld Installation on RHEL 7.4

Dear Team,

 

I have successfully installed minemeld on RHEL 7.4 and Am able to access the web console from Local Machine but am not able to access from Network.  

 

Please help if anyone faced the same issue.

 

Thanks and Regards,

Ramprasath

 

Virtual IP address in HA- Active Passive Mode

Hi Experts,

 

I've query about High Availability Active-Passive. As we know, interface IP addresses are same on both the firewalls and when Active device goes down, secondary firewall will take over by sending gratuitous arp to switches. So switches ca

...

5250's failing to pass traffic after AV software update

 

Hi,

 

We are on the version 8.1.2 and If I upgrade to the latest ‘Applications and Threats’ version,  currently 8044-4859, and then upgrade AV from 2678-3175 to 2683-3180 all rules fail, and traffic drops through the default deny.

 

I do not see any par

...

Bomi by L1 Bithead
  • 2578 Views
  • 3 replies
  • 0 Likes

Resolved! tcpdump - view whole packet in CLI

Hello.

 

I know I can capture whole packets (snaplen 0) and select verbose (and verbose ++) output when viewing packet captures with tcpdump on mmt interface.

But can I see whole packet in CLI? Verbose output only seems to add some header fields, I can'

...

Upgrade to PAN-OS 8.0.11 causes device restart loop

I performed an upgrade on a HA Pair of PAN-5220 firewalls from PAN-OS 8.0.7 to PAN-OS 8.0.11 and once the firewalls booted up they would run for about 5 minutes, alarm (red LED on device) and then reboot, over and over and over.  Even with only one f

...

mlinsemier by L4 Transporter
  • 13753 Views
  • 13 replies
  • 0 Likes

PA-3260 High Availability

We are migrating our Active-Passive PA-500 enviroment to an Active-Passive PA-3260 enviroment.

In the PA-500 for the High Availability Control Link (HA1) was ethernet 1/7 and for the Data Link (HA2) it was ethernet 1/8.

For the PA-3260 I can use HA1-A

...

ZEBIT by L3 Networker
  • 2960 Views
  • 1 replies
  • 0 Likes

prevent file copy over ssl vpn

Hi all

 

is there a way to prevent file copy over ssl vpn tunnel. user work from connects via SSL VPN and we want to make they cannot copy file to their personal PC. we have disabled RDP clipboard but thats not enough.

 

regards

Wadhwani by L0 Member
  • 4695 Views
  • 4 replies
  • 0 Likes

SSL/TLS proxy

An internal client can only make sslv3 connections while an external server only accepts tls 1.2 so the goal is to create a policy that will allow this, using the PA as an SSL proxy. 

 

Is this possible?  I was looking at decryption policies but I'm n

...

How do you completely remove a Firewall from Panorama

We are in a situation where we have over 50 Palo Altos that we have migrated to panorama over the years. Many of our Palos still have local rules on them as well as Panorama based rules. We would like to convert these firewalls to use only Panorama r

...

panorama-error.png
CZellars by L1 Bithead
  • 9651 Views
  • 3 replies
  • 0 Likes

Filter security policies by no description

I am trying to view only security policies that do not have a description.  I have found the following links but am unable to get the output i need.  I need to show rules with no description and for all the operations i must define a valuen and all i

...

  • 24184 Posts
  • 117 Subscriptions
Top Solution Authors
Top Liked Authors
Labels