General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.


Ensuring a Safe and Secure Community: How You Can Help


Dear LIVEcommunity Members,


Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun


jforsythe by Community Team Member
  • 0 replies

Custom Report Query Building Help Needed

I'm having a hard time getting my URL report built and sorted.


I want to accomplish the following


1. category must match ADULT or NUDITY

2. source user must not be a member of FILT_STAFF or M_FILT_STAFF active directory groups (basically students)

3. s


dannon by L3 Networker
  • 1 replies

Resolved! Don't Port that thing at me!

Hi All,


Heres my problem, I am setting up a L2TP/IPsec remote access VPN for staff and I am having issues with the IKE traffice on port 500. We are using an internal RRAS server which I have set the palo up to NAT all port 500 traffic and IKE service


Route all traffic through the firewall

I have one HA pair that sits at the edge of the network running internet traffic outbound. I want to also run all other traffic through this pair as well, but don't want to use it for default gateways for networks. I have done this before, but in one


Quick diagram.png

Palo Alto Networks Logs in real time



I have a problem with the Palo Alto Networks logs . The logs are appear every 10 seconds .


I need to see the logs in real time.


There is any command that let me see the logs in real time?


Thank you very much.

ra7oub4 by L2 Linker
  • 1 replies

Building New Polices for New Firewall Implementations

Is anyone using simple applicaiton filter groups to build policies for new firewalls? I find myself looking at tap traffic all day trying to build policies on what I see users hitting and its cumbersome. Is anyone just creating a applicaiton filter c


Policy with user ID don't work in palo alto networks



I have configured the users in the office to be identify with Active Directory. I can see the users identification in the Monitor tab. But when i set a rule with user AD identifier don't work!


I add two rules :


rule 1: deny access for a specif


ra7oub4 by L2 Linker
  • 7 replies

Resolved! Report bug to Palo Alto support



I think we are hitting a bug in versions 8.0.4 and 8.0.5. In firewall with several Vsys, only admins can see the logs (traffic, threats...). If you create an admin for one vsys, they cant see any logs.


If any PA team read this  

Resolved! Global Protect at the inside truted interface

PAN 5060

Outisde untrusted interface

Inside trusted interface


Wifi guest network inside


Most Global Protect corporate users go to


WiFi users normally PAT to the Internet using that same interface


palomed by L3 Networker
  • 2 replies

Resolved! Content Apps & Threats Unknown



We just several FWs in which we see any content package as "unknown" and we can not delete it???

Why this package is unknown and why it can not be deleted??? Here an example:



Vulneability SQL Injection



we have done some Vulnerability assessment on firewall with PAN-OS version 7.1.8 version. And found below vulnerability for which we are not able to find CVE or solution. Help me to find a solution for below:


Vulnerability : CGI Generic SQL Injec


using cli to enter x509 certs

Trying to use

set template TemplateName config shared certificate "CertName" public-key "xxx



I am getting it from a show template . but the string value is multiline so when i try and copy and paste. it fails on the second line


How do I work around t


Citrix Offloading


I'm having several problems with suddenly disconnections between users and xenapp citrix through PAN. Looking some information about that I think that is related about ASIC treatment of traffic... Is possible turn offload traffic only for citrix t...

nanukanu by L2 Linker
  • 2 replies
  • 23700 Posts
  • 110 Subscriptions
Top Solution Authors