General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4243 Views
  • 0 replies
  • 0 Likes

Log forward without internal logging?

Should it be possible to LOG forward without having internal logging? Some stuff I need to be able to deal with on the firewall, but others I just want recorded long term. Seems to be no option to do it.

what NAT and Network config

Hi,I have a router from my carrier. This gives me an internal IP 10.0.9.3 /16 from my internal Network 10.0.0.0/16 network and the GW IP he gave me is 10.0.30.99.Now he makes natting so i could get internet access and there i have a static official ip adress. for example 123.456.789 My test pc give it the ip 10.0.9.3 subnet 255.255.0.0 and gw 10...

Resolved! Global protect domain based local breakout

Hi, I have a question regarding Global protect and partial split tunnelling. Does GP have an option to only allow specific domains via local breakout, all other traffic should be forwarded into the tunnel. I'm asking this question regarding 0365, all domains should pass our company security checks only O365 traffic should be allowed to use end-u...

Skype for Business not work if use SSL Decrypt

Hi, Is it possible to exclude Skype for Business application from SSL Decrypt? Custom No decrypt URL category is not an option because new clients with on-premises Skype instances coming constantly. brToni

ToniE by L2 Linker
  • 7110 Views
  • 6 replies
  • 0 Likes

Any special instructions to move A/A firewalls from 7.1.x to 8.0.6 via Panorama?

Greetings all, Title pretty much says it all but we're wanting to move to 8.0.6 since it is a Palo Alto support recommended version. We're currently running 7.1.4 I believe with both of our active/active firewalls. Panorama is already on the 8.0.x track. My normal update procedure is to apply the update to one firewall, let it reboot and come ...

jsalmans by L4 Transporter
  • 8036 Views
  • 15 replies
  • 0 Likes

Panorama scheduled config-export failure with 20 character SCP password.

I noticed my Scheduled config-export backups were not working. At some point they were working file. Upon Further troubleshooting I found that the Panorama scheduled config export was failing because the password was 20 characters long. Upon changing to a 15 character password for the account the exports were successful. This appears to be an...

ECPP by L0 Member
  • 4170 Views
  • 1 replies
  • 0 Likes

Mixing App-ID and Service

Am I correct in assuming that if you use App-ID you can't also use TCP sercice ports to allow aditiona other services on the same rule. ThanksRob

Resolved! Not synched

My HA pair don't show synched and when I do a manual synched it say it completed successfully but the GUI show otherwise

HA.PNG
jdprovine by L4 Transporter
  • 6960 Views
  • 9 replies
  • 0 Likes

Resolved! MineMeld to trigger PA EDL Refresh if indicators change on update.

I’m interested in whether MineMeld can, or should, be used to trigger a PA EDL refresh if the indicators for a feed were changed after an update? Has anyone seen this done before? I’m curious whether this would be a recommended solution or whether interfacing with a PA’s API should be left to another scripting platform? If it is appropriate ...

PA-User by L1 Bithead
  • 5047 Views
  • 1 replies
  • 0 Likes

Drive-by Downloads & Block-Continue Page Exceptions

Hi all, In my environment, some developers use NuGet in Visual Studio, and in certain cases, commands will call out and download PowerShell scripts.Obviously I want generally to block PowerShell script downloads, but in special cases I need to allow them when they come from specific places. Unfortunately for my devs, since we wholesale block .ps...

Global Protect still lacks detail reporting feature

Greetings, So, I have a ticket open with support requesting on detailed reporting as seen on Network --> Global Protect --> Gateways --> Remote user link --> remote user tab, but on a cumulative basis instead of just data from the last login session. I searched around and found two links:https://live.paloaltonetworks.com/t5/Managemen...

vtan by L1 Bithead
  • 2373 Views
  • 2 replies
  • 0 Likes

Custom Region

Has anyone created a custon region and later found out that there was alrady a built in region for that country? How did you deal with it?

jdprovine by L4 Transporter
  • 16056 Views
  • 51 replies
  • 0 Likes

Resolved! Updating PA-200 7.0.x

Hello. Anyone had issues updating PA-200 on PAN-OS 7.0? Currently I'm on version 7.0.0. I downloaded PANOS 7.0.2 normally, but when I try to install I get the following message: "Failed to install 7.0.2 with the following errors. SW version is 7.0.2 Open of /opt/panrepo/releases/7.0.2/base/RPMS/openldap-clients-2.4.23-6.pan.mips.rpm failed: No s...

santonic by L6 Presenter
  • 5216 Views
  • 6 replies
  • 0 Likes
  • 24359 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels