General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4119 Views
  • 0 replies
  • 0 Likes

DROP_UPDATE on Minemeld

Hello Community, the logs on my Minemeld shows the below error for all that IPs that catch, could you please advice how to get ride of this problem? Thanks in advance

DROP_UPDATE.png

Global Protect - Clients with excessive failed logins

We've had Global Protect in production for a while now, but it has just recently been brought to my attention that we are having a lot of users locking their accounts out.The GP client prompts them for their AD username / password. Maybe they fat-finger their password or whatever. The GP client never gives them any indication of any issue, other...

HA First time Configuration

Im installing a single Palo at present with the intent of adding a standby unit in the near future. My question is regarding the interface addresses on the standby unit. What do i need to configure on the standby unit in regards to IP addressing apart from MGMT and HA interfaces? I cant see an option for standby IP addresses (like Cisco), so the...

welly_59 by L3 Networker
  • 2770 Views
  • 3 replies
  • 0 Likes

Resolved! How to generate GlobalProtect VPN Reports

Is there any way to provide reporting for GlobalProtect remote access VPN. Like for example I want a report of users who have connected in the past week, etc. How do i generate those reports?

VPN to Azure dropouts

I have searched high and low for this and found a few articles regarding IKE configuration and nothing seems to fix it. PAN 3020 v7.0.5. IKE 2 VPN to Azure. The VPN works but around every 50 mintues the tunnel drops out for a few minutes then re-establishes. I have tried various different IKE and IPsec settings as per advice from Palo Alto artic...

dmann2 by L2 Linker
  • 33248 Views
  • 35 replies
  • 0 Likes

different content of backup files.

Hey!I'm using curl and the xml api to automtically backup the config of my PA-3020:https://live.paloaltonetworks.com/t5/Management-Articles/How-To-Backup-of-Config-Files-Periodically-without-Panorama/ta-p/77312 However, the content of that file looks completely different compared to a manual backup. device -> setup -> operations -> save...

MPI-AE by L4 Transporter
  • 5304 Views
  • 6 replies
  • 0 Likes

Skype for Business problem after migrating from ASA to PA-820

We encountered with the problem of Skype for Business application , it needs to saythat all another applications are working well, but after migration from Cisco ASA toPA-820 we saw only tcp-rst-from-server message from remote server to local server forSkype or for clients too without of local server... no matter what.. it's verystrange behav...

Radmin_85 by L4 Transporter
  • 5334 Views
  • 8 replies
  • 0 Likes

Resolved! Confidence level in logs

Hi, In minemeld logs from the nodes, taking AF-Ransomware node as an example, I have 2 questions regarding the confidence, thanks! 1. does the confidence level come from the source feed? 2. can customers change this confidence level?

chtoh82 by L2 Linker
  • 5878 Views
  • 2 replies
  • 0 Likes

Resolved! Questioning about agentless user-id.

Hello!I have questions about user-id functions.1. How much user-id be supported by agent-less user-id? I guess that 64K user-id and 640 user-group would be supported on all of PAN model. right?2. When using user-id collector, How much user-id and user-group be supported by agent-less user-id for receiving all of user-id and user-group from other...

Sharefile custom URL site allow

We block access to sharefile.com as a whole. But we do have a sharefile.com company site which we allow access to. The problem that I am running into is this, when a user attempts to download a file from our sharefile site a random number will be generated in the following URL "storage-ec2-XXX.sharefile.com" where XXX represents the random num...

Self-signed Root CA Certificate FQDN?

I’m planning a test deployment of a globalprotect vpn, so currently going through the guides to see what’s needed. Part of the requirements if not using a trusted CA is to generate a self-signed root CA.What should the FQDN be on this cert? The deployment will have inside, outside and mgmt interfaces. Should it be the ip on the mgmt interface?

welly_59 by L3 Networker
  • 2854 Views
  • 1 replies
  • 0 Likes

Resolved! Valid Object Name Requirements Documentation Wrong

When creating an Address Object (as well as other object types) the documentation for Palo Alto 8.1 says this, "The name is case-sensitive, must be unique, and can contain only letters, numbers, spaces, hyphens, and underscores." The popup that appears when an invalid object name is added in the WebUI says this, "A valid object name must start w...

JasonKC by L1 Bithead
  • 4806 Views
  • 2 replies
  • 0 Likes

Confused about zones

I'm currently migrating from a pair of Cisco ASAs and the zones have me a little confused. Right now I have interfaces on the ASAs of inside, wireless, outside, dmz-private-web, dmz-private-db, dmz-public-web, dmz-public-db, dmz-dev-web, dmz-dev-db. My plan was to group the inside and wireless together as "trusted", outside as "outside, and then...

HA sync times

Recently I have noticed that it is taking longer to commit and sync the changes from my active PA to my passive PA and the management plane ramps up to 38%. any suggestions

jdprovine by L4 Transporter
  • 4036 Views
  • 7 replies
  • 0 Likes
  • 24336 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels