General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4435 Views
  • 0 replies
  • 0 Likes

Post Expiration Admin Login Count

Hello expert, I wanted to check if someone encountered same issue as mine. We did configure password profiles in our PA-820 (version 10.2.9) by enabling "Post Expiration Admin Login Count" to 3 times. Somehow, after password was expired it just straight away locked the ID and didn't allow us to login 3 times as configured. , Please advise ...

password profiles.jpg

Настройка mikrotik на Palo Alto

Здравствуйте всем можете помочь у меня интернет настроен на mikro tik с внешней и внутренней интернетом и подключена на d link. Я хочу подключить интернет на mikro tik и Palo Alto и патом d link . Я настроил Palo Alto как мост (bridge) но все ровно не работает интернет

aza95_95 by L0 Member
  • 1158 Views
  • 2 replies
  • 0 Likes

General TLS protocol Error

We have forward proxy (ssl decryption configured) We are having intermittent access to some webpages users have to reload the page to gain access.We are seeing General TLS Error on the decryption logs under Error. What Iv found out about the error is that This message indicates that an error doesn't meet the criteria for any of the afo...

image.png
Salathiwe by L3 Networker
  • 6245 Views
  • 4 replies
  • 0 Likes

User ID Anomalies

Hi, I had a strange behaviour with some user on user ID. We have 2 site A and B and our firewall have the mapping from the same agent. we found that user1 access site A and user2 access site B. issue that we found that user1 is access site B using the user2 IP. We check on each site the mapping is fine, but we dont find the user1 mapping ...

DennyChanditya_0-1729151292634.png
DennyChanditya_1-1729151338014.png

Resolved! SSL Inspection issues with GlobalProtect users

We're having some strange SSL/TLS Inspection errors while on GlobalProtect. We are getting unsupported-parameter errors while a user is connected to GlobalProtect trying to get to any internet site, including things like google.com. Doing a packet capture on the firewall it shows the connection trying to happen on tls 1.0 which we do indeed not ...

Claw4609 by L5 Sessionator
  • 40650 Views
  • 23 replies
  • 1 Likes

Resolved! Ping and other Applications in the same rule on a non-standard port

Is there a way to allow ping on a rule that has another application that uses a non-standard port? So for example, if yum uses port TCP 3142 instead of its default tcp/80,21 is there a way I can attach ping to that rule and still have it work? Like on Cisco ASAs you can add icmp as a port/service. Example that doesn't work: Example that does work:

bafergel_0-1632856860628.png
bafergel_1-1632856909682.png
bafergel by L2 Linker
  • 5507 Views
  • 3 replies
  • 0 Likes

Resolved! Upgrade from version 10.2.7-h8 to 10.2.11-h2

Hi, could you help me?I should make a release change from version 10.2.7-h8 to 10.2.11-h2for palo alto 3440. The two firewalls are in HACan you tell me the various release jumps I should do and if there is a procedure to follow?

F.Basco by L0 Member
  • 2363 Views
  • 3 replies
  • 0 Likes

Minimize log size

Hi All, if there's a way how to reduce or minimize the log size sent to the syslog server? if any KB / document / best practice how to reduce logs to sent to syslog server Thank you

deactivate bundle license from PA1410

Hi, I have a problem to deactivate bundle license, because it is... bundle license. Cannot deactivate license key Advanced_Threat_Prevention_2023_11_13.key which is part of bundle without parent_id attribute. What is parent_id attribute and how to find it? where in configuration I can use it? how to deactivate bundle license?

Problem with (URL Category custom), (Destination Address any) and (application any)

We have identified for some time that when rules are created with 'Application: Any' + 'Destination Address: Any' + 'UrlCategory: Custom' for example: Name: Rule_google.com_permitSource Zone: TrustSource Address: AnySource User: AnyDestination Zone: UntrustDestination Address: AnyApplication: AnyService: 443-tcpURL Category: URLC_Google.comURL F...

issues with ssh access from macos/ linux

Hi folks I am having issues with access via ssh from macos/ linux pcs pc ~ % ssh admin@10.10.10.1 Unable to negotiate with 10.10.10.1 port 22: no matching host key type found. Their offer: ssh-rsa ...

Screenshot 2023-05-06 at 10.49.13 AM.png
nevolex by L3 Networker
  • 17398 Views
  • 8 replies
  • 1 Likes

Migrating Panorama license from VM to another

Hi, I need to take the uuid and cpuid from Panorama, but when i run "show system info" its not appears these paramethers. How can i get these uuid and cpuid to transfer the license?????? My PanOs version is 5.1.0 hostname: Panoramaip-address: 192.168.22.191netmask: 255.255.255.0default-gateway: 192.168.22.10ipv6-address:ipv6-link-local-add...

regarding upgrade certificate on 18 NOV

Hello,I want to ask regarding this topic https://live.paloaltonetworks.com/t5/customer-advisories/update-to-additional-pan-os-certificate-expirations-and-new/ta-p/572158Do I have to upgrade the version of PaloAlto ? The version I have is 10.2.4-h3 ? do I need to upgrade this version ? so not to have problems ? Best regards,

Zurattos by L1 Bithead
  • 1004 Views
  • 1 replies
  • 0 Likes
  • 24374 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels