General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4243 Views
  • 0 replies
  • 0 Likes

Failed to install licenses. Model incompatible: feature model is VM300 while the device model is PRA

Hello all, I have just setup a Palo Alto firewall virtual instance. I have the interfaces setup now so that I can download updates/content. I attempted to apply my license using the authorization code. The first time that I tried I got an error that I needed a minimum of 6.5 GB of memory, so I shutdown the VM and changed it to 4vCPU and 8GB...

PFerris by L1 Bithead
  • 18088 Views
  • 8 replies
  • 1 Likes

Resolved! Panorama Shared Policy Zones

Hi all,I want to understand before I deploy shared policy in Prod I have 2*2 firewalls in HA (2 For DMZ, 2 For LAN) - I want to create a shared policy to both firewalls (LAN and DMZ)For example,In LAN I have 3 zones (Users, Servers, DMZ) In DMZ I Have also 3 zones (LAN, DMZ Servers, Internet)when I want to create one policy to shared device-grou...

VMWare ESXi PAN-OS upgrade: from 8.0.7 to 8.1.3 ->Active/Passive HA (without Panorama)

Hi community, Having reviewed: https://www.paloaltonetworks.com/documentation/81/pan-os/newfeaturesguide/upgrade-to-pan-os-81/upgrade-the-firewall-to-pan-os-81/determine-pan-os-upgrade-path#id181QEN0D0QY and https://www.paloaltonetworks.com/documentation/81/pan-os/newfeaturesguide/upgrade-to-pan-os-81/upgrade-the-firewall-to-pan-os-81/upgrade-an...

ash83 by L2 Linker
  • 4268 Views
  • 5 replies
  • 0 Likes

Resolved! zone protection issue.

Hi to all!I have such kind of problem.I have applied Zone Protection profile on my outside(untrust) interface.The problem is, that PAN is behind IBR(is configured as virtual wire), where are configured all our public ip.What can we do in this case?Thanks in advance!

Re: configure airgapped miner for on premise minemeld

Hi guys, we recently setup a minemeld server meant for a airgapped environment and we are trying to figure out how to setup a airgapped miner with the other information found here on customizing a miner. https://live.paloaltonetworks.com/t5/MineMeld-Articles/Using-MineMeld-to-Create-a-Custom-Miner/ta-p/227694 is there any available article for...

Resolved! Traffic using unintended Security Rule?

Hello folks, We have recently installed Cisco Nexus switches and UCS system. All of our routing has been through our PA firewall and continues to be, except for a new Management network created on the Nexus switch. We are trying to use this management network for our vsphere hosts, etc. We added a static route on PA to route requests to the N...

pasecurityrule3.jpg
pasecurityrule2.jpg
pasecurityrule.jpg
OMatlock by L4 Transporter
  • 4453 Views
  • 5 replies
  • 0 Likes

Query on HA pair upgrade

Hello, We are using PAN-OS 7.0.2 which is end of life and wanting to upgrade to 7.1.17. Can we upgrade one firewall through all the versions 7.0.2-->7.0.19-->7.1.0-->7.1.17 before moving on to another in the pair or do we have to bring both firewalls in pair on same version before making a move onto the next version in line? Thanks in ...

Farzana by L4 Transporter
  • 3565 Views
  • 4 replies
  • 0 Likes

Miner shows 422 Unprocessable Entity

Hi, I am trying to configure a miner that downlods a stream of IP addresses via HTTPS request. Data stream looks like this1.1.1.12.2.2.22.2.2.33.3.3.3etc. I created the following protype NSFOCUS_ip-v2: class: minemeld.ft.http.HttpFT config: attributes: NS-NTI-KEY: ***************** ...

otto38dd by L0 Member
  • 4655 Views
  • 3 replies
  • 0 Likes

SSL Decryption breaks certain website functionality

So I’ve enabled SSL decryption and as expected some sites or applications fail when it’s turned on. No problem I can exclude the domain from decryption.I have a special case though, in the fact that one of these web applications is a service that my company is developing. When decryption is on it breaks screensharimg from our web application. Th...

welly_59 by L3 Networker
  • 5726 Views
  • 3 replies
  • 0 Likes

Wildfire fails to update since Content Update 8058 installed

Hi All, Came into work today to 100 emails that wildfire has been downloading but failing to update. I have narrowed it down to content update 8058 being installed. Device PA3020OS 8.1.2No HA, No Panorama. If i try to install the wildfire updates manually you get an error that it failed to commit. I have made a change (stop my boss receiving the...

PhilH by L2 Linker
  • 3056 Views
  • 3 replies
  • 0 Likes

Resolved! Route specific traffic out backup ISP?

We have dual ISP (ISP-A and ISP-B) and utilizting PBR which works just fine. Now I have use case whereas I have a NAT configured on ISP-B (1 to 1) and I want to force traffic to a specific destination out the backup interface. I want to do this to ensure traffic destined for a specific address IP-B is sent out the backup interface. I tried ad...

drewdown by L4 Transporter
  • 14344 Views
  • 13 replies
  • 0 Likes

Resolved! Upgrading GlobalProtect while on corp network

Hi everyone, I have a client who said every time they try to upgrade globalprotect, they have mixed results. The issue seems to be that they'll set the GP App to "Allow with prompt". However, the users will never get the prompt while they are on the corporate network. It seems possibly, when the users go home, they'll get the prompt to download ...

ce1028 by L4 Transporter
  • 6059 Views
  • 9 replies
  • 0 Likes

Resolved! Adding app depencendies

This might be a dumb question, but I visited 3 clients in the past 2 weeks that did not include application depenendcies in their policy rules For example, they'll have a rule allowing webex-base, but don't add rtcp, rtp-base, or stun. To be fair, at least 1 of them had a rule that contains an application filter that allows risks 1, 2 and 3, so...

ce1028 by L4 Transporter
  • 3060 Views
  • 2 replies
  • 0 Likes

SSL Version

Is there any way for the traffic logs to display the SSL/TLS version that's in use for a particular flow? I don't see the data in the traffic logs or in the session info at the CLI.

  • 24359 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels