General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4126 Views
  • 0 replies
  • 0 Likes

MineMeld install failing on Ubuntu Server 16.04.4

Having a devil of a time installing MM. I got to the 37th task in the install but got this error:TASK [minemeld : create extensions frigidaire] **************************************************************************************************************fatal: [127.0.0.1]: FAILED! => {"changed": true, "cmd": ["/opt/minemeld/engine/current/bin...

Abruner by L1 Bithead
  • 7188 Views
  • 6 replies
  • 0 Likes

Resolved! Management Interface not sending a frame.

I have two PaloAlto 850's in HA. I am unable to ping or reach the secondary/standby webgui. Both are connected to the same switch, when looking at the switch CAM table the secondary MGMT interface is not getting populated with the FW MAC address. Being that the switch is not recieving a frame from the FW to populate the CAM table I have tried th...

PA-220 WAN link "not configured but up"

Hello,I need to add a fiber internet line on a PA-220 router but I have an error message:: Not configured but upLink speed: 100 MbpsLink Duplex: half The physical link, the IP configuration and the fiber box are OK I suspect the "HALF" setting should be "FULL".If I configure the link "full", it comes back "half" when I reconnect the fiber box......

paloalto.jpg

How to Block a Specific HTTPS Site with URL Filtering

Hi If I want to use URL Filtering Profile to block a particular "https" website (for ex, youtube.com) do I compulsorily need a decryption profile as well? This question is partly answered here:https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Block-a-Specific-HTTPS-Site-with-URL-Filtering/ta-p/53840 But the example is specific t...

Resolved! error activating extension

Hi Guys need some help. I copied the taxii class and renamed it then i followed youtubeminer to make and extension out of it. when I install it it shows me install success and shows success in activation. but i don't see the prototype in the list. In the logs in see: loader._initialize_entry_point_group ERROR: vinamrataxii.prototypes not...

Resolved! Issues with incomplete application

Hello, I've been looking into issues I'm having with our Azure environment and RDP. Our setup is pretty nominal currently but we do have a couple of VM's that we can get into. At some point, something changed and I cannot log into specific VM's that were already setup, as well as new VM's I create. I can however log into the currently accessi...

Office 365 access issue

Hi Guys, we have a problem: if a pc is in the lan, behind the firewall, we are not able to log in to office365, but if we use an external connection it works.i don't see any log with application containing 'office'We have not decryption enabled, PA-3020 with 7.1.14 Do you have any hint?Regards,Daniele

DKanta by L2 Linker
  • 3536 Views
  • 3 replies
  • 0 Likes

Resolved! User-ID Agent installed on Domain Controller doesn't appear to be collecting event logs

Hi guys, I've installed the Palo User-ID agent on a single domain controller (8.0.906) using the Palo Networks guide below: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/user-id/map-ip-addresses-to-users/configure-user-mapping-using-the-windows-user-id-agent/install-the-windows-based-user-id-agent Our environment already has Us...

Palo Alto 5250 - Configuring HA between vsys

Hi, Is it possible to configure two physical Palo Alto 5250 in Active - standby mode while distributing the load for Vsys across both the physical firewalls. For eg.I have two physical firewalls - PA1 & PA2I have 6 vsys in each firewalls - Vsys1, Vsys2, Vsys3, Vsys4, Vsys5, Vsys6 Is it possible to have the below mentioned setup? PA1Vsys1 -...

MGRashmi by L2 Linker
  • 6095 Views
  • 2 replies
  • 0 Likes

ECMP Config for 2 Internet links Site (Dual ISP)

Hello Everyone! Site with 2 X PA500 in HA2 Internet LinksPANOS 7.1.16ISP1 - 187.190.74.22 (internet dedicated)ISP2 - 192.168.0.66 (DSL link) Config doneVirtual Router 1 - RT-LANVirtual Router 2 - RT-WAN @RT-LAN0.0.0.0/0 points to next VR "RT-WAN" @RT-WAN0.0.0.0/0 points to 1/1, next hop 187.190.74.1, metric 100.0.0.0/0 points to 1/2, next hop 19...

Problems after RMA

hello After RMA the device we had prepared new device.Updated software and APPs and Threats signatures and also other signaturesThen imported the old config.But there are many problems.First time after time it is impossible to update dynamic updates (wildfire,antivirus and so on).Only after dateplane restart everything works but for awhile and t...

Radmin_85 by L4 Transporter
  • 2509 Views
  • 3 replies
  • 0 Likes

Connecting to Management GUI remotely on a different port.

I have a PA500 offsite that I manage remotely by connecting to the outside interface IP address, let's call it 188.1.1.1. My issue is I want to also set up a Global Protect SSL VPN gateway and the only IP choice it gives me is the outside interface 188.1.1.1/28. If I configure that then I can no longer reach the Management GUI remotely. Is there...

Walt by L1 Bithead
  • 8021 Views
  • 2 replies
  • 0 Likes

SNMP aged out

Dear Guys, I have a WAN router where we are trying to do a SNMP read only, but it keeps saying aged out. we have different devices as well which are working but SNMP on this router doesnt seem to be working.How can i prove that it is not the issue with Palo alto but on the remote side .The Service provider is telling us that we are sending the ...

NiteshS by L2 Linker
  • 4055 Views
  • 3 replies
  • 0 Likes

Is there a minimum upload and download speed required for Global Protect to operate?

I have a group of users that use Sprint and Verizon hot spots in order to establish a VPN connection from a remote location to our corportate network using the Global Protect Agent. Some of the hotspots are experiencing a 2-3 Mbps upload and 2-3 Mbps download speeds. The users at these locations are experiencing VPN disconnection issues such as ...

  • 24336 Posts
  • 124 Subscriptions
Top Liked Authors
Labels