General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

syslog-ng 3.5.4.1 failure on boot

Hi, We have integrated syslog-ng 3.5.4.1 on a client machine which sends logs to server which is running syslog-ng 3.16.1, some times, I see below error at the boot up of our targetsyslog-ng[1762]: Error opening control socket, bind() failed; socket='/var/lib/syslog-ng/syslog-ng.ctl', error='Permission denied (13)'and logs will not be sent to th...

User100 by L0 Member
  • 3471 Views
  • 2 replies
  • 1 Likes

VPN Cisco concentrator/ISE - USER-ID log to PA

USER-ID log from VPN Cisco concentrator Dear Live community, how is everything going ? Have you ever had to do the following? We have to integrate a Cisco ASA, with Palo Alto, so that the PA receives from a Cisco ASA and/or Cisco ISE the users to be able to have mapper with USER-ID the users that connect by VPN. ( There is no global protec...

Metgatz by L4 Transporter
  • 6933 Views
  • 7 replies
  • 0 Likes

Resolved! HA Firewall Device Migration/Hardware Swap

Need to replace an HA pair of Panorama managed, currently deployed firewalls (PA-5220s) with a different pair of Panorama managed firewalls (also PA-5220s), with minimum/no downtime; device licensing is different between #1 & #2 pairs, necessitating the swap. Proposed procedure (detailed in attached picture)- Copy Panorama DG/Template for H...

Resolved! Remote VPN gateway - IKE intitiator drop on Palo FW

Hi all, so a weird issue.. i have a pa1410 with multiple VPNs all working happy days. I have one client with a linux software based FW (cant recall fw vendor) we are using same ike/ipsec settings both ends all is good.. if i initiate vpn (test vpn ike-sa gateway xxxx) from Palo side, the VPN comes up and all is working.. however if client initi...

PA_nts by L4 Transporter
  • 2955 Views
  • 6 replies
  • 0 Likes

Bad support from plaoalto

Bad support from plaoalto we have in customer support call center more then a hour to connect for P1 call its really surprise support from paloalto

mojeebk by L0 Member
  • 14373 Views
  • 17 replies
  • 1 Likes

Activate Firewall with Expired License / Unknown Auth Code

I have a PA-440 on the shelf and want to make it a LAB unit. The support for the serial number expired on 12/15/2023. The device runs perfectly. I believe the original VAR is out of business. I tried my current VAR and was told the device was not registered. Is there anything I can do? I registered the device under my company's name, but the aut...

shobeav by L0 Member
  • 3098 Views
  • 6 replies
  • 0 Likes

Black Screen Issue When Accessing GlobalProtect VPN

Hi everyone, Black screen issues are preventing me from using the GlobalProtect VPN client properly. Every time I launch the application and try to log in, the screen goes completely black, and I can’t interact with any options. I’ve already tried restarting my computer, reinstalling the client, and ensuring I have the latest version of Gl...

Resolved! How to show connected remote users with Panaroma

Hello directly at gateway you can show connected globalprotect users. Network - GlobalProtrect - Gateways - Info - Remote Users With Panorama you don't see the information about remote users. By the way - max user is in both views empty Using Panorama 10.1.7 Any idea how to see remote users with panorama?

kuschg by L0 Member
  • 3750 Views
  • 2 replies
  • 0 Likes

Admin Role-based can't view log in Panorama after upgrading to 11.1.5-h1

Hi, normally we manage Panorama with 2 different accounts (one super admin and one Admin Role-based). Before upgrading to 11.1.5 h1, both account can view traffic logs normally. However, after the upgrade, the admin role-based account can't view any log while the super admin still can. Is it because of some change in 11.1.5 h1

KhoaDang by L1 Bithead
  • 1036 Views
  • 1 replies
  • 0 Likes

IOT software not showing on new Palo's

I have deployed 6 new firewalls and 4 of the 6 are showing the IOT software on the devices But 2 of the Palos are not showing this and it has been over 24 hrs.. All of the devices have the IOT licence applied Why is this not being pulled to the dynamics updates on 2 of the Palo's?

MAllen_0-1732789239834.png
MAllen_1-1732789288733.png
MAllen_2-1732789338278.png
M.Allen by L2 Linker
  • 890 Views
  • 1 replies
  • 0 Likes

Testing the quality of the main link

Hello, The ISP had a failure on its side, which involved slow connection, which made it difficult for people inside the company and those working on VPN to work. We have a backup connection that switches in the event of a failure of the main connection. Is it possible to introduce a mechanism that tests the throughput of the main connection and,...

Route convergence when using a Redistribution Profile

This is my scenario. I have an eBGP relationship from my PA to Vendor A and Vendor B. I have users that traverse this firewall and use their respective applications. I have Vendor C which is a site-to-site vpn. I'm doing a routed vpn with this vendor and I have static routes for Vendor C going across the tunnel interface. The issue I am hav...

Resolved! Panorama: how to manage Security/NAT policies

This is something we're struggling with. How do you write Security Policies and NAT Policies in Panorama when each firewall uses different IPs for NAT and the Security Policies include the IPs in them?On our FreeBSD firewalls, this was easy. We just used generic variables in our rules scripts such that the rules were the same across all the fire...

fjwcash by L4 Transporter
  • 8865 Views
  • 6 replies
  • 0 Likes
  • 24412 Posts
  • 125 Subscriptions
Top Solution Authors
Labels