General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

show system disk-space

Is this information still correct for 7.1.16 , I am trying to plan my upgrdae from 7.1.16 to some version of 8 and trying to make sure I have enough space on the disk to do it /dev/md6 - PAN-OS Image repository.(Device/Software)/dev/md2 - Service related logs./dev/md8 - - Allocated for PAN logs./dev/md5 ...

jdprovine by L4 Transporter
  • 11153 Views
  • 18 replies
  • 0 Likes

How was determine or verify after with application override bypass L7

Hi Expert , I would like to verify after config and traffic is match with Application Override Policy that it already bypass L7 how to check it via cli or gui so, I have understood about can check with show session id after filter application is already override but I have to clarify and verify it. Sorry to bad english

Shutdown Clustered/HA FWs

Is there any documentation on how to properly shutdown a clustered/HA FW pair and then restore connectivinty power verifying proper function once power is restored?

GMasanz by L0 Member
  • 5013 Views
  • 3 replies
  • 0 Likes

Dynamic TCP port APP query

Hi community, In a situation where there is a security policy allowing: SOURCE Source IP: any Source Zone: outside DESTINATION Destination IP: public IP 1.2.3.4 -> NAT'd to private IP 10.10.10.10 (servername1) (the security policy is using the post NAT zone). The inbound NAT is also correctly configured, and NATing correctly. APP: appX -> ...

ash83 by L2 Linker
  • 3655 Views
  • 3 replies
  • 0 Likes

Resolved! Auth Profile 8.1.x LDAP

We'd like our users to be able to log into Captive Portal or Globalprotect with [email protected] or just user. We've messed around with seemingly every combination of username modifiers, but have not been able to get it to work both ways. Currently, logging in with [email protected] works and the filter can see the user's AD group memberships. I...

Resolved! User ID Agent

Where the userid agent save log file ? We want to start audit when User ID update task failed on PAIs there a possibility to move the logs of userid to the siem / syslog server

Resolved! LACP NEGOTIATION LOG FILE

Hello, In order to debug an issue in our LACP interfaces.I need to run lacp debug and to find the log file of lacp negotiation. And there is a log file of all ethernet negoatiation? Thanks in advance.

Resolved! ISP redundancy and route load balancing.

Hi, Community! I'm looking for some help with a customer today 🙂 Here's the situation: a customer has a dual ISP configuration and wants the traffic both to be balanced between the routes of the two providers and that a redundancy scheme is put in place, so that in the case one ISP fails, users can go out to the internet through the other one....

CMachado by L2 Linker
  • 12146 Views
  • 8 replies
  • 0 Likes

PA-220 Not Decrypting any HTTPS Traffic even after I have followed ALL the Palo Alto Live Videos

For some reason SSL Decryption is not working on my PA-220 - I have followed many many many of the palo alto instructions to try to get it to work but some how it is still not working - the PA-220 is simply not decrypting any of the Https Traffic. I cannot even decrypt a single https traffic for some reason. I have installed the Certificate that...

Resolved! Replace passive member in HA (A/P)

Hi, We need to replace the passive member in a cluster. So in the HA preempt is not enabled. And priority in the active member is 100. So i understand that we can directly connect all the cables for new devices and this new member will take passive role since there isnt preempt enable, right???should i connect first of all HA cables in order to ...

BigPalo by L4 Transporter
  • 2985 Views
  • 1 replies
  • 0 Likes

Stuck in Failsafe Bootloader. what now?

My PA-820 is stuck in failsafe bootloader mode. what are my options now? I am no longer getting the option for MAINT mode either. If I let the system boot on it's own I get the below and it just keeps rebooting. Welcome to the PanOS Failsafe Bootloader.U-Boot 8.0.6.0-29 (Build time: Oct 13 2017 - 12:13:40)Octeon unique ID: 044000214719f31e0...

GPL-DDay by L0 Member
  • 9382 Views
  • 4 replies
  • 0 Likes
  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels