General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4118 Views
  • 0 replies
  • 0 Likes

Resolved! MP utilization high after the HA failover to primary

When Secondary Firewall became active, management plane utilization is not more than 10% for over months.Last week manual failover made, Primary is active now. MP utilization is above 60% all the time. All the configurations are same as it's in HA. Both firewall has 10+ unused FQDN objects and FQDN refresh happening for every 30 seconds eventhou...

Resolved! Panorama question

Why is it for network / interface / <some interface> I can't use a name for a zone. I wanted to have a template that had all of my zones in it, but unlike policies and objects there is no shared attribute. Which means I have recreate my zones for each template I have interface definitions. Am I missing something ??

PA-220 Aggregate Interface with LACP supported?

Hi, I need to confirm whether the PA-220 is able to aggregate 2 interfaces or more in a LAG (LACP). I was able to find out that the PA-200 does not support aggregating interfaces with LACP, but the PA-220 is rather new and I have not been able to find a definitive statement about it. The product comparison indicates that it should be suported on...

Web Filtering and Reporting

I have been tweeking reports on these Palos we purchases (3020) and trying to find a good Web Browsing/Filtering report to provide for senior management that will encompass top xx users with most visited external sites, preferrably with the duration on each site; However, as of yet I have not been able to customize a report that is easy to read ...

What services are used by the Management port?

We have been tasked to follow the CIS benchmark for our Palo Alto firewalls. One item is to limit access to specific IP addresses for the Management port. That is easy enough if the only thing using the management port was users connecting to manage the firewall itself. My question is what other services use the management port (Panorama, User-I...

kjsocher by L0 Member
  • 3389 Views
  • 3 replies
  • 0 Likes

Resolved! Installing Global Protect on Mac not working.

I have downloaded and installed the latest GlobalProtect for Mac. The install does not show any errors, but the agent does not seem to have started. Rebooted and installed again, but still no joy. I am running 10.12.5, Sierra on a 2010 Mac Mini with 8GB of RAM.

mdorsey by L0 Member
  • 5712 Views
  • 2 replies
  • 0 Likes

Resolved! Logging levels

Palo Alto is currently logging URLs which includes a path such as webserver.com/code.exe?id=4 but Palo is capable of logging a message that would display just the code.exe filename as well as a content type such as application/x-octet-stream or ms-executable. I would like to have these FILE events. Does anyone have insight into this for a palo...

jerm1020 by L0 Member
  • 2897 Views
  • 2 replies
  • 0 Likes

Panorama shared objects

Hi I am about to import my config from a PA into panorama. Now with shared objects, how do you manage them, can you delete them, I haven't found a way to do it via the web uiHow do change it from shared to non shared or the reverse ?

native VPN for Iphone on Pan os 8.0.2

Hello everyone, recently, i have access the acces for a palo alto Pa 500 i made the upgrade from 7.1.8 to 8.0.2, but now i need to do the configuration for a native vpn, for conect some iphone´s, but i dont have idea how to do this, there is anyone how can help me or any link more explicit about how to do it, i dont know some terms. i hope you...

Decryption Issue

Hello All, Need help 1. Decryption is not working in IOS device2. Outlook is not working in Android via decryption

tac.in by L3 Networker
  • 2831 Views
  • 3 replies
  • 0 Likes

Resolved! Global Protect question

Hi So I recently went through a POC with a HA pair of PA-3060. Setup a Portal. Now it seems like my vendor/pa forgot to add the any GP licensing. So by my read, I can do single gateway setup. Is there some doco on how to setup a client with no portal ?

PAN 5050 Migration to PAN 5220

We are planning a migration from hardware 5050 to 5220. The PANOS migration will be from 6.1.16 to 8.0.2 (oe whatever 8.x version installed on the new 5220 hardware). I am looking for advise for the upgrade process.

Active Directory Authentication for GlobalProtect issue

Hi ! Currently, I am using GlobalProtect in my network.Also, I am configuring an Active Directory Server, and I would like to use AD users to connect to GlobalProtect (currently I'm using local users / groups in the firewall). Computers are not in the domain yet. I have followed this tutorial : https://live.paloaltonetworks.com/t5/Configuration-...

Server LDAP.PNG
Group Mapping 1.PNG
Group Mapping 2.PNG
Auth Profile.PNG

GlobalProtect Clients fall back to SSL

Hi, Our GP Clients initially try to establish a connection over IPSec, but fall back to SSL every time. I can see the IPSEC traffic coming in and being allowed and do not know how to find why the tunnel is not establishing over IPSec. Any ideas on how to troubleshoot this? Or suggestions? Thanks,Shannon

SARowe_NZ by L3 Networker
  • 3923 Views
  • 2 replies
  • 0 Likes
  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels