General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4117 Views
  • 0 replies
  • 0 Likes

globalprotect on windows 7

I had an odd thing happen today, I could not get GP version 4.0 to work on a windows 7 install for a users, though I am using it on my personal pc at home

jdprovine by L4 Transporter
  • 8620 Views
  • 18 replies
  • 0 Likes

AIM 8.0.10.2 client does not use the "aim" App-ID, it uses "aim-express" which we need block

I opened a case - 00720785 - but after significant troubleshooting, repeating the behavior via screen shares with Palo Alto technical support and sending packet captures, I was asked to post this here. We need to use the America Online Instant Messenger (AIM) client since our compliance recording solution requires it. However, the traffic from t...

GGallent by L0 Member
  • 2646 Views
  • 1 replies
  • 0 Likes

Resolved! high dataplane cpu at PanOS 7.1.5

Hello all. We use pa-3020.PanOS 7.1.5 1, session 43%2,CPU 100% Why CPU 100% used?Normaly, 500Mbps use. BUG?? I get show tech messages. ::Resource monitoring sampling data (per second):::CPU load sampling by group::flow_lookup : 95%:flow_fastpath : 91%:flow_slowpath : 95%:flow_forwardi...

awawa100 by L2 Linker
  • 6507 Views
  • 6 replies
  • 0 Likes

Resolved! Apply QoS for Youtube or Streaming Media

I'm trying to wrestle down some NetFlix and Twitch users on my network. Because they're running in a browser, the application match for their traffic is only "SSL". However, I know that anything headed for nflxvideo.net is NetFlix traffic, for example. I can't find a way to apply QoS policy based on a wildcard match against the source DNS name...

Global Protect List of Portals

Hello, I was wondering if there's a way to be able to create a list or profiles of portals in Global Protect client which would allow to list all of the differnet portals that one uses. I have over 15 differnet portals which I use but everytime I try to vpn or use one of those portals I have to enter the port's ip or dns name into the portal fie...

Resolved! Captive Portal With SSO Breaks All Rules

Hello ALL - This is my second post here regarding Captive Portal. I enabled Captive Portal in my environment the other day thinking it would be for webaccess for my users in the event the User ID tool did not work. Upon enabling this feature other rules on my firewall stopped processing since there was no users associated with those rules. Is ...

2 factor authentication issue on Palo Alto Global Protect client

we need support from Palo Alto to understand the following issue:A portal and gateway profile has been created for ¿internal¿ users and ¿external¿ business partner users. All users need to authenticate using OTP (One time passcode). By default users must first authenticate against Portal and second to Gateway. Unfortunately this means that user...

mss-ops by L0 Member
  • 5575 Views
  • 4 replies
  • 1 Likes

question about global protect

Let us assume that you have users in your company and they have company comps with global protect client installedThey take their notebooks home.is it possible somehow by global protect to forbid connect to home internet without using GP?OR is it possible to make any configuration so hat user can not disconnect the global protect.?for example by...

Radmin_85 by L4 Transporter
  • 2666 Views
  • 2 replies
  • 0 Likes

Resolved! BGP/BFD

I am running BFD with BGP in a cluster(active/passive) and I am unclear on how to set up a failover of the firewall to the passive peer if BFD fails in order to bring up the BGP peer on other node. Any assitance would be appreciated.

r24481 by L1 Bithead
  • 3046 Views
  • 1 replies
  • 0 Likes

No metrics showing up in a syslog analyser node

Hi, I followed this post the other day and have been forwarding logs from my firewall for 2 days now, but without any hits, so I am wondering if I have done something wrong? I can see in a tcpdump dump on the minemeld server, that logs are received on port 13514/TCP. Also, the logs that are sent to minemeld are dropped traffic from an EDL, so ...

borising by L4 Transporter
  • 19632 Views
  • 16 replies
  • 1 Likes

Resolved! MineMeld export custom prototypes

Hey all, Can anybody tell me how we can export (and import) custom created prototypes (for backup purposes). The config does not include these, so if we need to rebuild the MineMeld instance we have an issue. Kind regards

mr.linus by L4 Transporter
  • 6185 Views
  • 2 replies
  • 0 Likes

Reason: User is not in allowlist

User 'steven.williams.da' failed authentication. Reason: User is not in allowlist From: ltdlqq6h2.domain.lan short name: domain\paloaltoadminssource type: ldapsource: Network_Administrators[1 ] domain\steven.williams.da Authentication profile contains the user group paloaltoadmins using the LDAP server profile. Created user in local admin and ad...

Resolved! Autofocus for MSP environments

Hi Guys If an MSP wants to use Autofocus for its customers and wants each one to have its own independent dashboard, is there a way to do it. Or would they just need to buy an AF license per customer

nrobison by L1 Bithead
  • 3465 Views
  • 1 replies
  • 0 Likes
  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels