General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Threat Vector, a Unit 42 Podcast, is Now on LIVEcommunity!

We have some exciting community news to share: Threat Vector, a Unit 42 podcast, is now on LIVEcommunity!

 

Threat Vector is your compass in the world of cyberthreats. Listen to this biweekly podcast to learn about unique threat intelligence, cutting

...

jforsythe by Community Team Member
  • 272 Views
  • 0 replies
  • 0 Likes

How and Why to Accept a Solution to Your Post

Did you know that you can help your fellow community members by accepting solutions when a reply answers your question. Accepted solutions are a super-helpful resource in the community, and we want to make sure our members understand how this feature

...

JayGolf_0-1691518400714.jpeg
JayGolf by Community Team Member
  • 3597 Views
  • 2 replies
  • 14 Likes

Resolved! Failure to install Apps and Threats

Model PA-3050
Software Version 9.1.16
GlobalProtect Agent 6.1.0
Application Version 8692-7955 (03/30/23)
Threat Version 8692-7955 (03/30/23)
Antivirus Version 4401-4918 (03/26/23)
WildFire Version 757322-760771 (04/06/23)
URL Filtering Version 20230406.2015

...

Kali by L2 Linker
  • 2269 Views
  • 4 replies
  • 1 Likes

NAT mapping public to private IP

Hello all,

 

I have been updating our NAT policies within our PA-3220 to specify traffic translation mapping from our public addresses to private addresses. After committing the changes the traffic has only been routing to the catch all NAT rule at t

...

IKEv2 IPv6 tunnel with dynamic endpoint from one IP

With IPv4 it is possible to build multiple IPSec tunnels from one interface IP with dynamic/unknown destinations and separate them based on the IKE peer IDs. That configuration is accepted by the firewall.

As for IPv6, as soon as one source interface

...

nikoo by L3 Networker
  • 1573 Views
  • 2 replies
  • 0 Likes

Log forwarding - Filtering and Auto- tag not working

Hi there,

 

I had setup Log forwarding profile, where I am sending All logs to syslog server. Thats working great.

 

Then I added one more line where I am filtering threat logs for (severity eq critical) and (zone.src eq internet_zone)

 

Checking f

...

LogForwarding.png
MatchingList.png
filter.png
Action.png

Release dates for PAN-OS

Hello all,

 

Can anyone provide me the release dates for the following in regards to PAN-OS:

10.0.4
10.0.5
10.0.6
10.0.7
10.0.8
10.0.9
10.0.10
10.0.11
10.0.12

Thank you

jsmoove by L0 Member
  • 158 Views
  • 2 replies
  • 0 Likes

Reverse proxy for Exchange ActiveSync

We have a Palto Alto cluster and I want to use them as reverse proxy for our Exchange inbound trafic. We activated decryption for this trafic and we want to allow only ActiveSync trafic / application.

 

It did not work with only allow ActiveSync appl

...

karsayor by L0 Member
  • 198 Views
  • 2 replies
  • 0 Likes

Resolved! Monitor Logs - filtering with wildcard?

Are wildcards supported now when trying to filter logs in Monitor? I saw a post from 2015 asking about it and at the time the answer was "Wildcards are not supported in the traffic log filters."

 

Was hoping that 9 years is enough time to implement t

...

dlcrewse by L1 Bithead
  • 144 Views
  • 2 replies
  • 0 Likes

Allow traffic mikrotik site to site.

Hi everyone. I just installed a firewall at an office. Office A is connected to office B via two site-to-site mikrotiks.
Inside office A there is a server that records the presence of office B employees.
After introducing the PA440 it stopped working..

...

AlessioS by L0 Member
  • 132 Views
  • 1 replies
  • 0 Likes

403 forbidden error while importing IDP fiile

Hii,

 

I have been trying to import G suit IDP file in SAML Identity provider on palo alto VM firewall but for infinite time its just showing message "uploading" without showing any error message. when I checked in network tab of inspect element I ca

...

Resolved! change default static route

Hi.

 

ethernet 1/1 > DHCP

ethernet 1/2 > Static

 

i want to dst. 172.16.1.x next hop ethernet 1/1 ///// dst. 172.16..2.x next top ethernet 1/2 for change.

not use pbf rule.

qmso475_0-1712801906455.png
qmso475 by L3 Networker
  • 196 Views
  • 2 replies
  • 0 Likes

Query related to import export config

Hi Team,

We are doing a migration of the firewall from the local VM firewall to another new firewall which managed by Panaroma. We have the below question for the import and export configuration. 

1) Can we export a few configurations together, like

...

Resolved! Upgrade PAN OS from 10.1 to 11.1

Hi Community,

 

My customer plan to upgrade their PAN OS from 10.1 to 11.1

From documentation said, You can now use the Skip Software Version Upgrade feature to skip software versions when upgrading your device from PAN-OS 10.1 or later releases.

Wh

...

HSutanto_0-1709107246673.png

Can't import a certificate via XML API using C#

Hello,

 

I'm trying to import a certificate to a Palo Alto VM-50 via XML API with an App written in C# but I always get this error:

 

<response status = 'error' code = '400'><result><msg>No file uploaded</msg></result></response>

 

 

My C# code is be

...

kittcat by L0 Member
  • 77 Views
  • 0 replies
  • 0 Likes

Issues with pushing out 10.2.9-h1

There is not a community discussion for issues implementing 10.2.9-h1

We have a maintenance window to push out 10.2.9-h1 Thursday evening and with recent issues with 1.2.7.h3 and other roll outs i am starting this thread for the community.

  • 24174 Posts
  • 100 Subscriptions
Top Liked Authors
Labels