General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4116 Views
  • 0 replies
  • 0 Likes

DHCP Server on Palo Alto

The DHCP server on Palo Alto does not clear the Expired sessions, its stays and we have to manually go and clear the sessions. Can you please help.

Denis by L2 Linker
  • 5765 Views
  • 10 replies
  • 0 Likes

Commit process hangs at 99%.

I have job stuck in queue . Tried clearing job,restart mgmt getting same error. Server error : Timed out while getting config lock. Please try again.

Site to Site VPN Tunnel is up, but no traffic pass through

Hi all. I am trying to setup a site to site VPN tunnel with one of our customer. I've got the dedicated layer 3 zone, tunnel interface, IKE Gateway, Virtual Router etc. configured per the Palo Alto admin guide. In the "IPSec Tunnels" section, it shows the VPN tunnel is up. However, I cannot access any of the server located at the customer's ...

User-ID client device specific

Hi All, I'm trying to figure out a work around to a user-id issue I'm having. We're currently running Novell Open Enterprise Server as our back end identity store. I have the User-ID agent installed on a windows box and communicating via ldap to my novell servers. It will ID people correctly sometimes. If someone puts their laptop into stand...

ICarder by L1 Bithead
  • 4231 Views
  • 4 replies
  • 0 Likes

Trouble with IPSec-SA

The partner company requires that I translate all packets to them so they appear to come from one public IP address. In monitoring on the PAN I can see that the packet passes and the source address is translated. The problem is that the tunnel is not coming up. I've been using the article at the bottom to try and figure things out. If I run >...

palomed by L3 Networker
  • 4655 Views
  • 2 replies
  • 0 Likes

Resolved! Migration path from PA-2020 to PA-820

What is the correct way to migrate from a PA 2020 at PANOS currently at 6.1.16 (plan on upgrading to 7.0.14; the highest version show up in the avaliable releases) to a PA 820 at PANOS 8.0?

itoffice by L0 Member
  • 7080 Views
  • 8 replies
  • 0 Likes

Resolved! How VPN test commands work

What happens behind the scenes when you run.. test vpn ike-sa gateway <name> or test vpn ipsec-sa tunnel <name> Is there a debug which will show you the test packets sent/received?

palomed by L3 Networker
  • 7135 Views
  • 2 replies
  • 0 Likes

Vpn site to site encryption

Hi All, i have two different firewalls and need to establish site to site vpn IKE Phase 1 : Encryptin will be AES-256 CBC and the other peer have only AES-256 without CBC is it gonna work ? or it will fail

Panorama Cert Expiring

I've been finding it more difficult to take time away from daily work tasks to review the happenings on the community. That said I just reviewed the release notes for 7.1.9 and saw the impending cert expiration. While the "sticky" thread is a good idea, it might be a good way for Palo to reach the appropriate masses if you guys send a "notifica...

User-id with RDP users

hi, am having an issue with user-id for users login to servers over RDP, what happens is when user1 login to serverA over RDP and then user2 login to serverA user2 will get the policy of user1. on PAN when i run the command ( show user-id-mapping ip serverA ) it shows user1 login .when i installed the TS-agent on serverA it solved my issue but t...

Resolved! Simple two PC ping test setup with PA200?

Hi folks, I want to setup a simple two PCs connected to PA200 so that I may practice a ping test and packet capture.PC#1 - IP address 192.168.1.2 - connected to interface 1/1PC#2 - IP address 192.168.2.2 - connected to interface 1/3. I can not get my interfaces to come alive after committing changes! Anyone know what I could be doing wrong?

ping3.jpg
ping2.jpg
OMatlock by L4 Transporter
  • 6604 Views
  • 8 replies
  • 0 Likes

Resolved! Settings inheritance thru Template-Stack ?

If I have two devices in the same Template-Stack, will member template enforce same setting on both devices including i.e. same L3 addresses ? This is what I want to avoid

niuk by L3 Networker
  • 5803 Views
  • 3 replies
  • 0 Likes

How to IPSec over GRE with dynamic routing

I saw a document on how to configure VTI tunnel with OSPF. But that is for PAN-OS 4.1. Does anybody know if PAN-OS 7.1 supports GRE tunnel? I need to configure IPSec over GRE on the Palo Alto to talk to a Cisco router. Thanks

jac101 by L2 Linker
  • 4514 Views
  • 2 replies
  • 0 Likes
  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Labels