General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4391 Views
  • 0 replies
  • 0 Likes

Resolved! Question regarding VM series HA after a hardware failure

I am new to VM series PAs and looking into how to setup HA. So it is interesting that the license is attached to the host and VM file location. Any change in this needs a re-registration of the license via tech support. Even using VMotion would trigger a need for a support call. I then assumed that I could put one VM on a separate Hypervisor...

Panorama Read Only mode?

Hi all, I cannot modify my Panorama templates (Network, Device), even though I logged in with the admin account. As I attached the screenshots, it says (Read Only) mode and grayed out the check boxes, so I am unable to modify the Interface Management Profile or Services. However, the Device Groups (Policies, Objects) are okay. Does anyone have a...

Panorama_ReadOnly_services.jpg
Panorama_ReadOnly_interfacemgmt_profile.jpg

Multiple DHCP Scope’s on 1 interface

I have a router with 2 VLAN’s. The router is connected to a PaloAlto and behind this PaloAlto I have a server witch serves DHCP. The VLAN interfaces on the router are configured with a helper address to the DHCP server. We would like to remove all servers (and go fully cloud based). I decided I want the PaloAlto to serve the DHCP function. So: I...

Sjoerd by L2 Linker
  • 9006 Views
  • 6 replies
  • 1 Likes

App-id not working on some Apps

I am seeing a number of applications which have definitions, but are not being identified correctly: kaokatalk, league of legends, battle.net and guild wars to name a few. these are showing the correct ports but showing as "unkown-tcp". Is there some way to update these, reset the definitions, etc.?All of my App-ids are up to date.ThanksBob

BobW by L4 Transporter
  • 7885 Views
  • 3 replies
  • 0 Likes

Resolved! GlobalProtect Enforce Connection for Network Access Captive Portal detection

Hi, We are using global protect with the following agent features : GlobalProtect Enforce Connection for Network Access enable and Captive Portal detection enable with timeout of 3600 seconds. Howver we can see many cases at some hotels, and airports where the actual portal detection is not being recognised by Global Protect agent. Hence user ca...

Traps - Permit .exe file with specific certificate

Hi, We would like to add a specific certificate ("Exacq Technologies, Inc") to the TRAPS database so that it recognizes all the ".exe" with this certificate as correct and it is not necessary to upload them to Wildfire, since due to the size limitation of the files to be sent configured in the TRAP console itself, these are not analyzed and ther...

Removing peer from HA cluster

I have a pair of PA-3020s running 7.1.x in HA configuration. I need to remove the passive switch from the rack to be used in another location. What is the best way to disable the HA and delete the config from the active switch without risk of service interruption. Thanks in advance.

Resolved! Re-creating a specific routing configuration.

Hello folks,I am trying to reproduce a configuration from work where we use a Metro Line to connect our two sites. It's working at my job, but not at home. It seems like a simple setup and I think I am close, but having an issue. Checking if anyone may have a comment? My test is trying to connect to my esxi server from vsphere client, but una...

metrof.jpg
metroc.jpg
metrob.jpg
metrod.jpg
OMatlock by L4 Transporter
  • 4800 Views
  • 5 replies
  • 0 Likes

Interface in vsys

Hello this may sound like a stupid question but i could not somehow find a definitive answer to this in the PAN OS Guide: We have to configure a 3050 iun multi-vsys configuration. We would be needing 2 interfaces per vsys and we wil be having 2 vsys only. All the interfaces wil be L3. Regarding "physical" interface assignment, what is ALLOWED an...

Resolved! Is Zone Protection on Shared Gateways Supported

I have a question regarding Zone Protection on Zones in a shared gateway. Is it supported. When I try and configure it it seems to be valid configuration. However as a shared gateway does not generate logs where do the the ZP logs go? Also when I run the command "show zone-protection zone ?" the SG zones do no show in the list so I can't col...

CHammock by L2 Linker
  • 5168 Views
  • 4 replies
  • 0 Likes

Unstable ipsec detection for ipsec-esp-udp application when connecting Globalprotect VPN

We have a setup with a primary PA firewall 1 that pass through Globalprotect VPN traffic to a second PA firewall 2. We've seen sporadic connection problems when connecting a Globalprotect client. Sometimes it can spend up to 2 minutes to establish the VPN. When these connection problems occur firewall 1 will log unknown-udp on port 4501. Besides...

GlobalProtect install restrictions

Hi allI was wondering if there was a way to restrict who can install the GlobalProtect client ? As an example, at the moment if any user launches the gateway page can download and install the client on their own computer albeit they need an active account, but the thought of them being able to install it on an infected home computer does worry m...

djh3003 by L0 Member
  • 3407 Views
  • 4 replies
  • 0 Likes

SSL decryption error

I had configured SSL decryption on PaloAlto VM-50 before 6-7 months ago. There was working normally till today. Today some users get below error when they want to enter site. There is shown “decrypt-cert-validation” message on PaloAlto traffic logs. There isn’t shown any error on PaloAlto and on user computer When I disable SSL decryption rule.

image005.jpg
Radmin_85 by L4 Transporter
  • 5885 Views
  • 4 replies
  • 0 Likes

Help with configuration for a test network going through our live environment 5050's

Just mainly need direction on where to go with this. We have 2 PA5050's in our environment and no test network for the main network. We do however have a new test satellite network where some of our DB's and others want it to have access to live environment servers. My idea is to use the 5050's to keep the devices on the test network talking to ...

JeffTQT by L2 Linker
  • 6483 Views
  • 6 replies
  • 0 Likes

Help with IPSEC VPN with overlapping subnets

I'm working with a vendor to setup an IPSEC VPN but we have an overlapping host address. My side has a PA500 and their side is a Sonicwall. Palo Alto Side: Source server: 192.168.100.20Their Server: 192.168.100.85 My server NAT address: 10.0.0.20Their Server NAT address: 10.0.1.85 I've configured a NAT rule that goes from Trust to Tunnel Zone: D...

  • 24370 Posts
  • 125 Subscriptions
Top Solution Authors
Top Liked Authors
Labels