General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4174 Views
  • 0 replies
  • 0 Likes

Best Practice Assessment /SCM

I used to run BPA in Strata Cloud Manager, but now when I log in I can’t find the On-Demand BPA option. How can I run a Best Practice Assessment on a Palo Alto firewall?

Multi-VSYS 11.2.8 - How to assign a dedicated Forward Trust Certificate per VSYS for SSL Decryption

Hi everyone,I’m running PAN-OS 11.2.8 with Multi-VSYS enabled (3 VSYS). I need a different Forward Trust Certificate per VSYS for SSL decryption, but since my certificates are imported in the Shared store, I can only select one Forward Trust Certificate globally.Should I import the certificates directly at the VSYS level instead of Shared to fix...

Route & Path Selection

I have a Cisco backround & I am currently studying Virtual Routers & Static Routes in the PA 8.0 admin guide. I am trying to understand how Metrics are used in the firewall because it sounds like Administrative Distance does the same thing. Can someone tell me if my theory is right when it comes to Palo Alto forwarding packets to an in...

Palo Alto Networks Training and Student Engagement Opportunities

Howdy Palo Alto Community!In addition to my employee role in the IT department, I volunteer as a staff advisor for the Islander Cyber Society (our campus cybersecurity club) at Texas A&M University–Corpus Christi.Previously, we participated in the Palo Alto Networks Cybersecurity Academy and explored offerings such as Cybersecurity Fundament...

jdean77 by L0 Member
  • 86 Views
  • 0 replies
  • 0 Likes

PA-445 lost management access

Hey All, thank you for those who helped me out yesterday!I'm back with what i think is a doozy,I tried to change the firewall's login IP from 192.168.1.1 to 192.168.69.1. The problem was that the firewall already used 192.168.69.1 as its office network gateway, so we were trying to use the same IP for two different purposes. The firewall detecte...

Ownership Dispute Involving Palo Alto Hardware

Hello, PaloAlto community I understand that this place may not be the most appropriate for this kind of request/post. I hope I am not violating any forum rules and if I am - I apologize. At the moment, however, I have no other effective means of reaching PaloAlto directly. I have tried to contact PaloAlto through both email and phone, but w...

HA Configuration Sync from PA-A to PA-B?

Hello everyone, Here is the scenario: PA-A has the full configuration and a Device Priority of 50. PA-B has no configuration and a Device Priority of 100. Both firewalls are configured in Active-Passive mode and belong to the same Group ID. Under High Availability → General → Setup, for the option “Enable Config Sync”, which firewall should ha...

XFF IP Address Logging clarification and impact

I would like to view XFF IP Address in the Logs. I went through a few articles and have a few clarifications: https://docs.paloaltonetworks.com/network-security/security-policy/administration/identify-users-connected-through-a-proxy-server/use-xff-values-for-ip-based-security-policy-and-logging https://docs.paloaltonetworks.com/network-securit...

ET_0-1778692034141.png
ET by L3 Networker
  • 218 Views
  • 2 replies
  • 0 Likes

Ruckus vsz Syslog and User-ID Agent

Hello community, this topic has been on my mind as well. I already searched the forums, but unfortunately I couldn’t quite make sense of it. Which setting do I need to configure on a VSZ 7.1.1.0.872 for the syslog server? Take a look at the image, please! Or rather: will I then see these entries in the syslog that ends up on the Palo Use...

2026-05-11_08-41-10.jpg

Design active passive connected with vrrp switches

Design active passive connected with vrrp switches for physical connection and AE i want to connect full mesh topology but want to confirm it's working like stack switches. PA1 > (2 links sw1,sw2) PA2 > (2 links sw1,sw2) so for aggregation to i can assign port to the AE. thanks.

Configuring XFF logging without a URL Filtering License

1. Create a Custom URL Category with * under ‘sites’ (Objects >> Custom Objects >> URL Category >> Add) 2. Create a URL Filtering Profile & set your Custom Category action to “alert” (Objects >> Security Profiles >> URL Filtering >> Add) Tick the box to log XFF on the ‘URL Filtering Settings’ tab… ...

1.png
2.png
3.png
4.png

Resolved! X-Forwarded-For (XFF) operation query

Hello, We are evaluating the implementation of X-Forwarded-For (XFF) functionality for logs. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/identify-users-connected-through-a-proxy-server/use-xff-values-for-ip-based-security-policy-and-logging However, this functionality was activated and affected the traffic, denying traffic...

Alpalo by L4 Transporter
  • 1950 Views
  • 2 replies
  • 1 Likes

Regarding HA ports and PoE ports

Thank you for your continued support. Please allow me to confirm the following. ① The PA-400 and PA-500 series do not have HA ports. However, we are assuming that the regular ports will be used as HA ports. In that case, are two HA ports required? Currently, we are using 8 ports (1 port for HA), so we understand that a device with 9 or more ...

  • 24348 Posts
  • 124 Subscriptions
Top Liked Authors
Labels