General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 255 Views
  • 0 replies
  • 0 Likes

Welcome to the General Topics Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating:

 

Rules and Best Practices

 

  1. Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussion
...

JayGolf by Community Team Member
  • 934 Views
  • 0 replies
  • 0 Likes

I cannot delete a virtual wire interface

Hello,

 

I've already looked at similar topics here, but it did not help me.

 

I'm supposed to set up a DHCP server on ethernet1/2 and to do it, I need to set up ethernet1/2 as a layer3 interface on the CLI first.

 

Initially, I tried these commands:

...

Resolved! proxy-id information through CLI -IPSEC Tunnels

To all,

 

I have multiple tunnels on PA 850. It was difficult to see through which tunnel specific traffic was sent. I tried "show vpn ipsec-sa" it gave me only Peer IP addresses but not proxy-IDs ( interesting traffic permitted through tunnel).

 

is the

...

DNARNI by L0 Member
  • 12699 Views
  • 6 replies
  • 0 Likes

Problem with dynamic update Failed to download file

Hi,

 

I have a problem with dynamic updates. I see new content version or antivirus, but I cannot download it with message Failed to download file.

Ping to updates.paloaltonetworks.com and downloads.paloaltonetworks.com is working.Service route is Us

...

upload and download speed issue

Hi,

We are using PA820
i have a isp connection of 700mps up/down.and i have an internal server that can access from public and the domain is pointed to the public ip.the internal server is in my dmz zone and isp is in untust only untrust interface is

...

Resolved! Traffic hitting policy rule it shouldn't

Hi,

 

PanOS 9.1.0

I need to block traffic to certain websites and domains.

I created a URL Category object and put just one site inside (example.com).

I then created a firewall rule like this:

 

Source zone: LAN

Source address: any

Dest Zone: WAN

Dest address:

...

TACACS authentication with Cisco ISE not working

Hello, I would like to ask currently I have two firewall that needs to be configure TACACS. One of the firewall is working fine and I'm able to login using my credentials from ISE. However, another firewall is not working for the TACACS authenticatio

...

fhassan by L0 Member
  • 106 Views
  • 1 replies
  • 0 Likes

URL access issue

we have one legal category url where it’s not working checked on palo and found no return traffic .So palo support told need to check with upstream as we didn’t find issue on our azure too as we use azure public IP.As we don’t manage any CDN we don’t

...

Failed to send CHAP authentication request:

admin@PA-(active)> test authentication authentication-profile ISE-TACACS username XXXX password
Enter password :

Target vsys is not specified, user "XXXX" is assumed to be configured with a shared auth profile.

Do allow list check before sending out a

...

pacavi by L1 Bithead
  • 18074 Views
  • 4 replies
  • 0 Likes

Stop Connect "On-Demand" after "Pre-Logon"

Hi !

 

we use the pre-login feature with client cert logon - this work quite good. after logon we would like to connect on demand with saml login. we made two configs, one for prelogon and one for the user, both with prelogon:


At the moment if you l

...

2025-05-13 15_00_16-Panorama und 7 weitere Seiten - Geschäftlich – Microsoft_ Edge.png
2025-05-13 15_03_51-Panorama und 7 weitere Seiten - Geschäftlich – Microsoft_ Edge.png

Alerts in AIOPS Still Exists

Hi community,

 

I have a critical alert on CVE Vulnerability on our firewall. However, after performing the PANOS upgrade to the version that patched the CVE, the alert is still showing in AIOPS.

 

So, my questions are, shouldn't the alert disappear

...

Palo Alto Networks Approved
Palo Alto Networks Approved

Resolved! [API] - User-ID

Hello Guys,

 

Sorry if the location is incorrect. I was looking for a location regarding API.

 

I'm trying to set up an user with his IP through API. This is for a lab.

I did follow this page:

 

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-pa

...

Issue with GP Access for JIO Users on PA-820

Dear Friends,

 

One of our customer is facing an issue with users on PA-820. According to the customer, many users are connecting to the internet via mobile hotspot using JIO SIM cards. While they can successfully connect to GlobalProtect, but they a

...

  • 24030 Posts
  • 115 Subscriptions
Top Liked Authors
Labels