General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4133 Views
  • 0 replies
  • 0 Likes

Resolved! Disable User-ID Syslog messages

I get litterally millions of the syslog messages below (different users), and I think that they have to do with the user-id agent or user identification in someway. Currently I am logging absolutely everything to a syslog server that pumps it all over to a SoC. I would like to disable these syslog messages. Does anyone have any ideas on this?...

DIRTT by L2 Linker
  • 3372 Views
  • 2 replies
  • 0 Likes

ssl err_cert_authority_invalid

Hello I have added our selfsign SSL that we generated from a windows CA server for our district. When I add it to the firewall under the Device Cert and use it for the forward trust I am getting this error ssl err_cert_authority_invalid I am not sure what could be causing this error Unless it is caused by the fact the domain is not listed in t...

Resolved! Power Module failure

Is there any other way to see if a power modules as failed? I just happened to notice the LED lights were red on the front of the secondary PA but my primary PA is in another building altogether so I would not know without going over there.

jdprovine by L4 Transporter
  • 6922 Views
  • 13 replies
  • 0 Likes

Qos Policies for G-rollout.

For G-site rollout effort,is there a way to write Qos policies so they apply per client IP flow when they are communicating to google IP address? A way to give rate limiting per client IP(thousands of clients) for google destination IP? The keyword is per client, so everyone has the same limited bandwidth. Each client IP has 165kbp's 'a...

kpotru by L1 Bithead
  • 3292 Views
  • 4 replies
  • 0 Likes

Resolved! Minemmeld access error : EDL external dynamic list file either empty or not found

I am getting the follwoing error repetedly in PAN-OS 8.0.5 > tail mp-log ms.log2017-10-18 21:14:53.743 -0700 Error: ebl_verify_fetched_copy(pan_cfg_ebl.c:2241): EDL entry(0x1068000, 0x1e760800, 0x12cb6000 vsys1/EDl-IP, 0, 1 ip) Old refreshed file type is either not a text file or empty file or no old file exist.2017-10-18 21:14:53.743 -0700...

MineMeld age_out not withdrawing ips

I'm very new to MineMeld, and I am having issues withdrawing ip addresses from a list. The miner checks a local list, and the list has two ips in it currently. I'd like the ips to be age_out after 24 hours, even if they are still on the local list. In the logs I see TRACE / EMIT_WITHDRAW with the indicator of the ip, but then the very next...

PF by L1 Bithead
  • 9824 Views
  • 12 replies
  • 0 Likes

Logs in GUI are blank

We noticed that the log view in the gui for the nodes, indicators, etc no longer populate anything. The node view does show indicators being added and removed, so we know they are pulling in data, the logs just don't show anything. Any idea where we can start to troubleshoot. ver 9.44

feeeds by L1 Bithead
  • 5333 Views
  • 4 replies
  • 0 Likes

Output Node Disables

using the minemeld.ft.redis.RedisSet prototype for output and 'state' is started but the output is disabled. on the configuration tab the output says 'enabled' however still not working. I have the URL in the Palo Alto and it connects successfully to the url but not populating the PA.

jsamide by L2 Linker
  • 3918 Views
  • 1 replies
  • 0 Likes

Ethernet Port down has Severity as "Informational" in System Logs

Hi All,We had an incident with one of our clients where the one of the Ethernet port on Palo Alto went down and the log severity which was reflected on PA was "informational", whereas client want this to be in a severe level like "high" or "critical" Please let us know if the severity level can be changed to critical for link down on Palo Alto....

Resolved! Create EDL, first line invalid

Hi, trying to create an dynamic IP-List (EDL) including two subnets:10.0.1.0/2410.0.2.0/24The firewall downloads the list but displays the following error "Valid entries(1) lines skipped(1)" and when I display the list only 10.0.2.0/24 shows up. If I add an comment at the very top of the list it all works. Can anyone explain why?#My list10.0.1.0...

iMac Pro with Intel Xeon chip Doesn't work with GlobalProtect 3.1.1-27

Hi, Been using Global Protect for almost 4 years now. Worked fine on the windows laptop they gave me. When I returned as a contractor, I use my macbook pro - absolutely no issues. Going for more power and multiple virtual machines, I purchased the recently released iMacPro. 8 cores, Xeon chip. Same OS 10.13.3. I downloaded GlobalProtect as ...

  • 24337 Posts
  • 124 Subscriptions
Labels