General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

HA Pair - peer version too old

I have two hardware gateways in a HA pair running 9.1.19. Ive upgraded one to 10.0 and then to 10.1.14. It now complains that the HA 'peer version is too old' and it has suspended HA. If i suspend HA on the remaining 9.1 gateway, HA doesnt activate on the 10.1 gateway. If i suspend the 9.1 gateway and try to manually "make local device functi...

Build in tool to test throughput

Hello experts, Im wondering if Palo Alto firewalls have a build in tool to test throughput on specific interface. We are trying to use iperf on an endpoint and test channel utilization from the firewall or if possible, firewall acting as iperf server. Thanks in advance.

Resolved! Difference Between 1 and 2 VM-Series Firewalls Without Subscription Licenses

Hi Team, I am looking to understand the practical differences between deploying 1 unit and 2 units of Palo Alto VM-Series firewalls, particularly without any subscription licenses. I am aware that subscription licenses enable services like Threat Prevention, URL Filtering, and WildFire, but in a scenario where no subscriptions are used, what w...

Vulnerabilities

The vulnerabilities which it will show in vulnerability assessment are live or any particular time the data get updated?

PAN-GPLimiter: Limit Concurrent GlobalProtect Sessions/Connections Per Unique User

PAN-GPLimiter: Limit Concurrent GlobalProtect Sessions/Connections Per Unique User Hi All, I would like to introduce my Go program for limiting concurrent remote user logins in a single GP Gateway on a PAN-OS Firewall.(Keywords: Limit the maximum number of simultaneous GlobalProtect sessions/connections per unique user.) PAN-GPLimiter [ ht...

enginy by L2 Linker
  • 5245 Views
  • 5 replies
  • 10 Likes

Can't add tunnel interface created by restapi, to Security Zone using restapi.

Using restapi to create IPSec tunnels for a new firewall attached to Panorama. I create the tunnel interface using restapi. I can see the new interface successfully created in Panorama. When I try to assign that interface to a Security Zone it fails with: "Invalid Object: Branch-VPN -> network -> layer3 'tunnel.781' is not a valid ref...

I.Miller by L0 Member
  • 1144 Views
  • 1 replies
  • 0 Likes

questions while creating first IPsec tunnel

We have our egress on Eth1/1 with a public IP assigned by our provider. We also own a separate public subnet. We have the internet working and want to add an IPsec tunnel from our PAN to a partner also running PAN. I'm told to continue using the Eth1/1 interface. Do you see problems with this solution? Diagram attached. Eth1/1 is untrust. It h...

Resolved! HA State is "not sycned" even though Sync Task is completed on Peer (Passive) Gerät)

Hello,There are a few config differences between Active/Passive Firewalls like (asssigned Auth. Profil under Device section, login banner, snmp features)When i perform sync it shows on Task Manager of Passive Firewall it is succesfully synched. However on the Active Firewall it shows us always "not synced" here is the show high avaiabiltiy st...

fkuecuek_0-1728893393917.png
fkuecuek_1-1728893480464.png

How to limit concurrent GlobalProtect connections per user

Hi communit So far it isn't possible to limit the concurrent GlobalProtect connections per user directly in PAN-OS. There is a feature request #4603 for which you can vote and wait/hope that this will be implemented. If you need a solution (workaround) right now, once more the PAN-OS API is your friend. Because we (like probably some or a lo...

Remo by L7 Applicator
  • 55670 Views
  • 39 replies
  • 16 Likes

Find more info about process based on PID

The command 'show system resources' lists the active processes and their PIDs and their resource utilization, but is there another command where based on the PID I can get more info about a specific process ? Similar to show jobs all shows all the jobs and show jobs id xxx shows more detailed info about the specific job based on the ID.

DHCP Relay

PC1 in DMZ Zone cannot receive IP from DHCP Server. I already allowed DHCP Traffic in firewall and also configure DHCP Relay which is ethernet1/4 interface with dhcp server ip 192.168.10.1 NOTE: i have configured vlan: 192.168.10.0/24

geminigumisong_0-1725427056164.png

Boot PXE Fog

Hello everyone, I have a little problem with my boot PXE with Fog server My station boot on port 69 at the gateway of his network Fog server and the station they are not in the same network. I tried to use DNSMASQ but that not resolve the problem Here is felt capture of my configuration : DNSMASQ on Fog: Option on Paloalto DHCP Service ...

asbui_0-1728633248747.png
asbui_1-1728633439225.png
asbui by L0 Member
  • 1403 Views
  • 1 replies
  • 0 Likes
  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels