General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4254 Views
  • 0 replies
  • 0 Likes

Resolved! LDAP group member enumeration problem

I am running PAN OS 8.0.7 and having a problem with getting the members of a group enumerated by the firewall. The group is shown by the firewall in the GUI and can be added to security policies, and the CLI if I run the "show user group list" command, I can see the group in the list that I have added to the Group-Mapping settings.The problem is...

rbentley by L0 Member
  • 4511 Views
  • 1 replies
  • 0 Likes

Strange packet drop

Hello guys, I have a PA820 in active/passive mode who has a strange behaviour. I have created a rule that permits that traffic but the device drops it. I see "allow"in the logs, but with a capture I can clearly see the SYN in the dropped section and not "syn/ack" and "ack". I have also tried to put an "any/any" rules, it matches but the behaviou...

PA_log_forum.png
PA_rule_forum.png
Shye80 by L1 Bithead
  • 2788 Views
  • 2 replies
  • 0 Likes

Any issues not documented on version 8.0.6?

Hello Community,Since the security advisories were released yesterday, we are looking to upgrade to the newer version. Has anyone experienced any issues with 8.0.6 from 8.0.5 that are not in the release notes? https://securityadvisories.paloaltonetworks.com/ https://downloads.paloaltonetworks.com/software/PAN-OS_8.0.6_RN.pdf?__gda__=1512621490_...

Resolved! TEST VM-500 on ESXi Deployment

Dear Community, I hope you are doing alright.We are in process of renewing our firewalls and I would like to test-deploy latest version of the Palo Alto VM-Series 500 on VMware vSphere Hypervisor (ESXi). Could you please let me know how I can the following?Obtain the OVA packages needed for deploymentObtain a test license for PA's trial periodWh...

Resolved! PA cluster certificate missing

Hi, We have two devices in HA, we realized that active node has a certificate (captive portal) but the passive not. The configs are synchronized but the passive doesnt have this certificate. We tried to export this certificate from node active and import in node passive, the proccess is done properly but the certificate is not showed. Why the pa...

Resolved! ROBOT attack - some advice needed

Hello According to https://live.paloaltonetworks.com/t5/Threat-Vulnerability-Articles/PAN-OS-exposure-to-ROBOT-attack/ta-p/192397For complete protection, signature #38407 must be applied upstream from any interfaces implementing SSL Decryption, or hosting a GlobalProtect portal or a GlobalProtect gateway. I have 760 content update applied. I try...

_slv_ by L4 Transporter
  • 8516 Views
  • 5 replies
  • 0 Likes

Edge Firewall Design

I am trying to design the edge firewall and core network currently and I have a core Layer not in a "stack" or "VSS" so they are independent Core switches. They are doing the routing to the private WAN, and will be doing the routing to the Edge Firewalls. ECMP requires a dynamic routing protocol which usually you wouldn't run on an edge firewall...

UserID and VPN

Is it necessary to have userid enabled on the VPN zone interfaces to see the userids?

jdprovine by L4 Transporter
  • 3826 Views
  • 8 replies
  • 0 Likes

Trust and Untrust on same interface

I am pretty new to the Palo Alto's so I have a questions that will be pretty easy to answer. I am setting up a PA-820 in Virtual Wire and we have both Trusted and Untrusted networks on the same interface from the router. The External interface is the route to the internet but is also the route to all our branches through GRE Tunnels. What woul...

Resolved! 'Certificate for Secure Syslog' option in PAN-OS 7.1.X ?

Hi, Good day. I'm testing about Syslog setting using SSL in PAN-OS 7.1.14 environment. Under 7.0.X, when I created a certificate, then I clicked it, I can see an option 'Certificate for Secure Syslog'In PAN-OS 7.1.X, however, when I generate a certificate or import it which is created by not encrypted,I couldn't find any option for that. Firs...

syslog01.PNG
syslog02.png

Default cursor location on GlobalProtect iOS login

Is there a place to report issues? On GlobalProtect forIOS, you can save your default username for your VPN, and the app pre-populates the field, however it leaves the cursor in the username field. It should, however, start in the password field. It would save users that extra click/tap ever single time they log on. Small thing but would certain...

wseguin by L0 Member
  • 3066 Views
  • 3 replies
  • 0 Likes

Resolved! Does globalprotect detect roaming between networks?

Dear Community, I´d like to check with you regarding the following globalprotect scenario: I´m connected with my laptop to the LTE mobile network to be outside and I´m connected to the external gateway, when I connect to the wifi network... Is it possible that the agent will detect this change and automatically connect to the internal gateway o...

Carracido by L4 Transporter
  • 3814 Views
  • 2 replies
  • 0 Likes

Failover IPsec VPN with Dual ISP

There are serveral resource available for Dual ISP and with Failover VPN on Live community such as https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774 . But here are still lake of of some information in documents, example partner IP address for VPN tunnel, IP Monito...

Ch.Ratha by L1 Bithead
  • 11736 Views
  • 5 replies
  • 0 Likes

Resolved! Determine IPSec tunnel performance?

Hi folks, We have several IPSec tunnels, but only one is complaining of poor performance using a specific application that the tunnel is meant for. Management asking for firewall stats to prove if it is related to IPSec tunnel/firewall performance issue or not. I am following this article and see the first twenty ports, but do not know which on...

OMatlock by L4 Transporter
  • 10926 Views
  • 5 replies
  • 0 Likes
  • 24362 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels