General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience.

General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Ensuring a Safe and Secure Community: How You Can Help

 

Dear LIVEcommunity Members,

 

Ensuring a top-tier experience on LIVEcommunity and protecting our members’ safety and security is our top priority! To this end, we have implemented additional security measures to safeguard our vibrant global commun

...

safe-community_oct24.jpg
report-content.jpg
jforsythe by Community Team Member
  • 487 Views
  • 0 replies
  • 2 Likes

Resolved! Regarding Security Advisory CVE-2024-3393

Hello Team,

   I have recently upgraded my pa-1410 firewall to panos ver. 11.1.4-h7, because its preferred version so far.

Today I have received this advisory link ...

https://securityadvisories.paloaltonetworks.com/CVE-2024-3393

I have DNS Security

...

Resolved! OS Upgrade path to 10.2.10-h9

Hello.
I am currently using PAN-820.


The OS is 10.1.9-h3. What is the correct way to upgrade? (I will upgrade to 10.2.10-h9.)

1. Upgrade to 10.1.14-h6, then upload 10.2.0, then upgrade to 10.2.10-h9
2. Upload 10.1.14-h6 and 10.2.0, then upgrade to 10.2

...

danudan by L0 Member
  • 80 Views
  • 1 replies
  • 0 Likes

When will PAN-OS start supporting modern SSH ciphers?

I'm running PAN-OS 11.1 and an Ubuntu 24.04.1 server which runs OpenSSH 9.6p1.

I had to tune my sshd_config to support really ancient stuff like aesXXX-ctr and hmac-sha1 just to allow for SSH decrytion...

 

Please Palo Alto update the supported ciphe

...

GlobalProtect Portal require :443

Hi All,

 

I have an issue where we need to input <firewall IP Address>:443 in order to connect. But some of my users does not require the :443 to connect to the VPN.

 

Screenshot as shown below,

 

Any way that i dont even require :443 to be connecte

...

KevinNg_0-1726118355889.png
Kevin-Ng by L1 Bithead
  • 955 Views
  • 7 replies
  • 0 Likes

Resolved! My PA-1410 logs for single day, why? how to solve?

Hello Team,

                 My new PA-1410 logging is not more than a single day when checking the traffic logs.

Previously I had PA-3220 I could checked months of logs.

whats wrong here in the PA-1410 loggin settings?

 

manager@PA-1410-Main(active)

...

Websites stopped working after update

Hello,

We have updated 10.2.6-h3 to 10.2.8-h3 earlier and recently to 10.2.10-h9 but in both times we had to do rollback to 10.2.6-h3 because our websites stopped working.

 

Everything else seemed to work except inbound traffic to these applications.

...

ToniE by L2 Linker
  • 218 Views
  • 2 replies
  • 0 Likes

Inbound TLS/SMTP inspection (to FortiMail)

Hi,

I'm wondering if anyone happens to be doing successful inbound inspection of SMTP/TLS to a FortiMail appliance? Or any other mail server for that matter.  I've run in to a brick wall when it comes to renegotiation. The Palo is serving the correct

...

Screenshot 2021-02-04 at 14.43.04.png
pkaren by L1 Bithead
  • 2834 Views
  • 2 replies
  • 0 Likes

Mulit-Vsys setup with Wildfire

Hi Friends,

 

We are planning for a multi-vsys PA setup, where one vsys will have only L3/L4 policies and second vsys will be in L2 bridge mode with Threat prevention features only.

Vsys1 will only scan L3/L3 policies while vsys2 will scan traffic fo

...

PaloAlto Passive Firewall Monitoring in HA Setup

Hi everyone,
Greetings!

I’m currently using OpManager to monitor a Palo Alto firewall in an HA Active/Passive setup, and the Link State of the interfaces on the passive device is set to auto.
While OpManager is able to correctly pull interface details

...

USER111 by L0 Member
  • 108 Views
  • 0 replies
  • 0 Likes

PA-VM sysd_construct_sync_importer

We got a customer that runs into this issue recently, it's a known issue (not public) for versions 11.0.0, 10.2.3, 10.2.2-h1 (and also to us 10.2.3-h2, 10.2.2-2).

When you run into this, means that there's a hardware issue, please go to TAC in order

...

Palo FAIL TO LOGIN.png
Gabeeh by L0 Member
  • 8068 Views
  • 8 replies
  • 3 Likes
  • 23712 Posts
  • 110 Subscriptions
Top Solution Authors
Top Liked Authors
Labels