General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4254 Views
  • 0 replies
  • 0 Likes

Migrating from PA-5250 to PA-5410

Hello folks, i need to migrate from PA-5250 to PA-5410, the old devices are managed via panorama using stack and stack template, the new devices are reachable with no configuration other than the management. What is the best way to move the configuration from the PA-5250 to the new PA-5410 with less effort? Can i just add the 5410 in the exist...

PA.jpg
MAerre by L2 Linker
  • 6866 Views
  • 11 replies
  • 0 Likes

Captive Portal SSO browser-challenge issue

Hi, We would like to deploy captive portal instead of using userid. We would also configure it so that the user does not have to login or get a login page. However, the browser-challenge seems to fail and then the user gets redirected to the default web form. Is it even possible to configure captive portal to authenticate the user without ...

rbrainar by L0 Member
  • 996 Views
  • 1 replies
  • 0 Likes

Doubt configuration HA Paloalto-Aruba

Hello to all I have a pair of FW PA-460 active-passive. When we perform Failover I lose 40 seconds the network to the internet. i have only HA1 connected on a pair of SW aruba. I suspect it may be an Aruba or Paloalto configuration issue. Any idea? Best regards.

Alpalo by L4 Transporter
  • 4043 Views
  • 6 replies
  • 0 Likes

Resolved! mail and dns server

Hello friends , I am runnng pv-vm on kvm , which has no license presently ,(version 9.0.4) baiscally this setup is understand palo alto firewall i have domain /fqdn (want to run all a mx ns server to run locally ) i have setup a web ,mail and ftp and dns server ,web server and ftp server working but need some help/understanting on mail and d...

shrikant by L2 Linker
  • 3934 Views
  • 5 replies
  • 0 Likes

Meraki behind PA - Unfriedly NAT

Hello community, another person with the problem. I know, I know. Finding a solution to this problem is obviously not easy. I have a problem with a Meraki cluster behind a PA cluster.The problem is the familiar “Unfriendly NAT”.I just can't figure out how to configure the PA so that it works. Countless articles on the internet don't help eit...

Resolved! Internet Bandwidth comsumed, who?

Hello Team, Firstly, thank you all for your cooperation. I have an issue that is I have my internet connection fully utilized most of the time. is there a way or work arround to find out which host IP is utilizing the bandwidth, knowing that I am not running the SD-Wan. software version 11.1.2-h3 TIA,

End users selects DENY on the MFA prompt on the phone still are able to connect to GlobalProtect agents

I need some advices on this GP VPN Client with MFA issue: End users selects DENY on the MFA prompt on the phone still are able to connect to GlobalProtect agents The current auth environment is that users use Active Directory in Azure for MFA and use Radius to authentication process in Globalprotect.

Resolved! SSL Decryption: Forward Trust unavailable

Hello, After creating a external CA cert, the Forward Trust Certificate, Forward Untrust Certificate and Trusted Root CA are greyed out. So I can't select. All options are available when a create a self-sign certificate. Any idea? Thanks

KTarver by L1 Bithead
  • 4744 Views
  • 7 replies
  • 0 Likes

Automatic Deploy of Firewalls into Panorama trough api or sdk

Im trying to automate the deploy of a firewall into panorama using the python sdk (pan-os-python)It seems I can add devices to panorama by the serial number, but i cannot make them connect cause it need the auth key to be set when adding the firewall to panorama, the SDK does not provide that option, and I cant find a way to do it on the API as ...

HIP check report interval

1. What is the interval for HIP reports that the GP client sends to the gateway? 2. Is it configurable?3. What triggers HIP report sending?

ET by L3 Networker
  • 24436 Views
  • 6 replies
  • 0 Likes

Resolved! Intermittent UserID - Syslog Parser -

Anyone see this behavior? we are using syslog parser string for userid, no logout action, timeout set to 45 minutes ( default). You can see here that a flow within the same second shows a userid and then blank with same source address. FW running 10.2.7 h-8 . Any ideas?

NSutfin_0-1723726668467.png
NSutfin by L2 Linker
  • 1715 Views
  • 2 replies
  • 0 Likes
  • 24362 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels