General Topics
cancel
Showing results for 
Search instead for 
Did you mean: 
General Topics

Discussions

Thank You for Filling Out the LIVEcommunity Experience Survey!

If you've visited LIVEcommunity anytime recently, you've probably seen a pop-up asking for your feedback. We've deployed this survey since April 2020 for new and returning visitors alike as a way to gather feedback from our users. 

 

In the past six

...

survey-livecommunity.png
jforsythe by Community Team Member
  • 520 Views
  • 1 replies
  • 4 Likes

VPN IPSec Configuration Disappeared from GUI

An issue where I can’t view any configured IPSec Tunnels in GUI,

From CLI, the IPSec tunnels appear normally.

 

Tried failover, restarting management service, even rebooting both Palo Alto units, using different browsers, different computers, and export

...

PA-850 Migration to 10Gb SFP+ Interface

Hi, I have a customer who was a PA-850 firewall. There connection to their LAN is currently using a 1Gb Ethernet port (Port 4). They are in the process of upgrading the network backbone to be 10Gb and wanted to change their connection to the Firewall

...

dvdkevin by L0 Member
  • 652 Views
  • 2 replies
  • 0 Likes

Resolved! Block Windows 7

I am trying to block Windows 7 clients from accessing the internet.  I have followed the steps here: https://live.paloaltonetworks.com/t5/Configuration-Articles/Custom-vulnerability-signature-for-identifying-Windows-XP/tac-p/72273#M1496

but I am uncle

...

GlobalProtect and "client sleep mode"

Hello,

as described in the "GlobalProtect 1.1.6: Addressed Issues" (issue point 35361) the unnecessarily reconnection after sleep/hibernate mode should be fixed.

We are using the GlobalProtect Version 1.1.7 . The portal configuration are:"On demand" mo

...

Hithead by L4 Transporter
  • 5230 Views
  • 7 replies
  • 0 Likes

Resolved! Custom App for CRL downloads

Hi,

I am trying to create a custom app that will match CRL downloads, to allow them without any questions ask. Shouldn't be too hard : on a previous web security gateway, I would match a pattern like the following: "http://([^/:])*crl.*\.crl"

When tran

...

dennisss by L1 Bithead
  • 11409 Views
  • 20 replies
  • 0 Likes

Resolved! PAN-OS 9.1.11-h3 upgrade file

Hi support,

 

May I know the upgrade file for PAN-OS 9.1.11-h3? I could not confirm it.

 

Below is my environment

PA-5200 platform
VM series
Panorama M images

 

Thanks !!!

Global Protect HIP Check - Defender ATP

Hi, we're implementing Defender ATP as an anti-malware solution.

 

I would like HIP checks to restrict Global Protect connections from clients without a recent AV scan performed, without Real Time Protection Enabled or with out-of-date virus definition

...

Screenshot 2020-03-27 at 09.48.22.png
it_dist by L1 Bithead
  • 4131 Views
  • 5 replies
  • 0 Likes

Resolved! GP VPN agent issue

Hi Team,

 

We have a setup like GP VPN and cisco duo.

 

When a user is trying to connect to GP it will send a request to the cisco duo and once the cisco duo will approve the connection, the user will access the GP.

 

One of our system is not working prope

...

VishnuPS by L3 Networker
  • 543 Views
  • 1 replies
  • 0 Likes

Resolved! How to release a vpn tunnel?

I have alot of tunnels between nodes, and it seem periodically one will hang, almost like a zombie process.

Is there away to break/kill  this tunnel down without taking the other tunnels down?

erantanen by Not applicable
  • 2921 Views
  • 2 replies
  • 0 Likes

Licenses on Airgapped Panorama

Hi guys,

 

I was wondering if anyone has any experience using a totally airgapped panorama/firewalls deployment.
At the moment I have a case where none of the devices are allowed any outside connections.

I thought it would be do-able since both software

...

How to configure FQDN

Hello,

 

I need know how to allow create FQDN in PA firewall 3020 and to use URL name instead of adding all IP ranges.

 

Appreciate your help

 

Thanks

mmarie by L0 Member
  • 317 Views
  • 1 replies
  • 0 Likes

IPv4 Processor receive cidr and output single address

Hi folks, 

 

Actually I can create a miner that pull an IPv4 list, send it to the processor and to the output. The output is always in that format:

 

1.1.1.1-1.1.1.1 (for an entry in the list with a single ip)

2.2.2.0-2.2.2.255 (for an entry with a s

...

TCP reset packets being dropped

Hello Everyone,

 

I have TCP reset packets being dropped in the Palo when they are sent from tcp-rst-from-server or tcp-rst-from-client. I've taken a pcap to verify the traffic is being dropped. I've put in a ticket with support and their solution was

...

brieann by L0 Member
  • 677 Views
  • 3 replies
  • 0 Likes
Top Solution Authors
Top Liked Authors