General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4117 Views
  • 0 replies
  • 0 Likes

Palo Alto firewall does not display traffic log

I've just installed Palo Alto firewall VM version in virtual box.I was able to access it via WEB (https) and SSH.However, when I check traffic log it was empty. I generated a few traffic such as ping and nmap scan against firewall IP, but still no traffic log appear in it. log-receiver statistics shows 0 traffic logs written meaning no traffic ...

PA traffic log.jpg
prenatip by L1 Bithead
  • 8293 Views
  • 7 replies
  • 0 Likes

Resolved! Challenge with Cisco ISE (Identity Service Engine) Integration for user-id mapping

Hello All,I am currently trying to integrate the cisco ise (radius server) to the Palo Alto Syslog filters so that the users that be tagged and policy applied to different categories of guest based on ISE permission.Currently ISE seem to be sending authentication logs to Palo Alto but cannot seem to build the right regex to pull the relevant inf...

risi76 by L0 Member
  • 6163 Views
  • 3 replies
  • 0 Likes

Intermittent firewall/application issue

Hello, I apologized if i posted i the wrong area. To start off with, we just got our PA-820 recently. We have a weird issue, where one day an application will work without problems and another day the Instant Messaging part of the app fails to connect. I looked at the logs yesterday when it wasn't working and noticed a lot of logs in the traff...

Exporting Application Groups

Is there a way of exporting Application groups from one Panorama and importing to a different Panorama? I am trying to move my groups over for a GPCS POC. NOTE: GlobalProtect Cloud Service has changed to Prisma Access.

kamorris by L1 Bithead
  • 4152 Views
  • 2 replies
  • 0 Likes

IPSec Tunnel Question

I have a IPSec tunnel up where the Peer IP is the same as the Remote IP (Proxy ID - Remote). The Tunnel is up, but traffic destined for that Remote IP isn't traversing the tunnel. Typically, there is a Private IP as the Remote and a static route could then be set in Virtual Router to send the traffic back across the tunnel. I'm sure I'm not t...

Packet flow not properly defined

Hi Team, i have seen two diagrams of packet flow from palo alto website. in Below NAT Policy evaluated is shown in first step. which is part of Network processor (slow path) and NAT applied after Application and security Policy it means from security processor it is again sent to network processor for applying NAT. which says that packet is pa...

PA Small PF.PNG
PA large PF.jpg
ss198939 by L1 Bithead
  • 4003 Views
  • 3 replies
  • 0 Likes

Agentless vs Agent based User-ID

Hello, We have 500 users on site and currently using Agentless User-ID with PANOS 7.1.7 We are thinking of scaling up to Agent based. Can someone please guide me to a link/article that discusses the Pros and Cons of both? What are the common issues one facing with Agent based? Are there any limitations? etc. Thanks in advance!

Farzana by L4 Transporter
  • 7075 Views
  • 5 replies
  • 0 Likes

MineMeld engine:fatal message

I'm getting the below message in my minemeld logs and not sure what is causing it 2018-07-11T00:30:28 (16652)config._destroy_old_nodes INFO: Destroyed nodes: [_ConfigChange(nodename=u'Amazon_IPv4_Agg_General', nodeclass=u'minemeld.ft.ipop.AggregateIPv4FT', change=1, detail={'inputs': ['Amazon_AWS', 'Amazon_CloudFront', 'Amazon_EC2', 'Amazon_...

Resolved! NTP server synched with Firewall but shows wrong time on firewall.

We have configured NTP server on the network which synchronizes with Australian/Melbourne time. So all devices including firewall configured with the NTP server. but all other device showing correct time as per NTP Server but Firewall show incorrect time by entering "show clock" command though firewall synced with NTP server display in "show nt...

ntp.JPG

Supressing Application Dependancy Warnings.

On our "SKYPE" rule I have removed web-browsing, this causes dependancy warnings on commit. I read this "solution" https://live.paloaltonetworks.com/t5/Management-Articles/Application-Dependency-Warnings-with-Allowed-Enabler-Application/ta-p/55142 But not sure if it's correct or makes the rule insecure? Rob

  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels