General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 907 Views
  • 0 replies
  • 0 Likes

Resolved! Proto in packet capture filter

What is proto in packet capture filter ? The manual only says:

Proto—Specify the protocol to filter

The field only seems to accept numbers...

dieter_b by L4 Transporter
  • 7401 Views
  • 5 replies
  • 0 Likes

XSIAM Engineer Certification

Has anyone completed the Cortex XSIAM Engineer certification? If so, could you share your experience? Also share your guidance on how to prepare for it.

Palo Alto Networks Approved
Palo Alto Networks Approved

PAN-OS 11.2.8 ETA

Hi All,

 

i would like to know the ETA of the PAN-OS 11.2.8 as per last PA TAC mention that the 11.2.8 tentative release date of june 25 

 

but so far no info of the release yet 

 

this is to fix for GUI display issue with SAML SLO url.

 

thank you

Mgmt Traffic over VPN

Hi All,

 

  I am looking to deploy a few (4) PA-440's into the field. What is the best way to configure my remote firewalls to send MGMT traffic 3.3.3.3/24 (using loopback) over a vpn to central firewall to pass along to panorama MGMT (10.10.10.10/24

...

Advice on dual isp, getting dns to work

Hello all,

I currently have a PA440 and I have 2 isp's, ATT and comcast which will be our backup and it's my 1st time setting this up, we are a small business of about 80 users, I already followed how to configure dual isp redundancy on the links pro

...

cdcirexx by L3 Networker
  • 749 Views
  • 8 replies
  • 0 Likes

spanning tree portfast for cisco to palo links

I am moving some palo interfaces to a new cisco switch. 

What is the recommended spanning tree configuration on both palo and cisco sides when connecting these devices?

 

PA(config-if)# spanning-tree port type ?
edge Consider the interface as edge por

...

M.Allen by L1 Bithead
  • 152 Views
  • 0 replies
  • 0 Likes

PA-820 Support renewal

 

Hi All,

Our current PA-820 support is due to expire in October, so I requested a renewal quote, and our vendor is stating that paloalto is declining to extend support. Has anyone had similar feedback from resellers and or paloalto regarding their n

...

Resolved! How to add switchport trunk allowed to AE interfaces?

I have a cisco switch which has a trunk to a PA device. On the switch it is configured switchport trunk allowed vlan 120,766,767. How do I add the corresponding configuration on the PA end?

The AE2 int already has the .120, .766 and .767 sub interfac

...

M.Allen by L1 Bithead
  • 361 Views
  • 2 replies
  • 0 Likes

Palo Alto Kerberos for sso

Anyone hit the same issue before?

2025-08-16 20:35:38.768 +0800 debug: pan_auth_cache_get_authprof_info(pan_auth_cache_authprof_n_authseqprof.c:218): prof "KRB-SSO", vsys "vsys1" (method: Kerberos pre-auth) has sso hash table id: 1 (0 means no or inv

...

jQuery vulnerability on management interface of PA-3220

Hello all,

 

Our customer is currently using PA-3220 running PAN-OS 11.1.
During their recent vulnerability scan, the following CVEs were reported that jQuery used on the Web management interface;

 

CVE-2018-8046
CVE-2007-6758

 

Questions:
1. Do these v

...

kawai818 by L0 Member
  • 162 Views
  • 1 replies
  • 0 Likes

prevent-brute-force-attacks

Hello Everyone

 

I am looking for suggestions on how we could protect our GlobalProtect VPN. We have been seeing people trying to perform brute-force attacks on random user accounts daily. We do have MFA set up, but is there any automation we could i

...

dshastri by L0 Member
  • 1958 Views
  • 6 replies
  • 0 Likes

Resolved! Advanced-routing ignores BGP local-pref

Troubleshooting a routing issue I've just discovered that the local preference isn't used for forwarding decisions when ECMP is enabled. Has anyone seen this before? I'm about to log a support case, but I thought I'd ask here in tandem.

What I see is

...

dmgeurts by L2 Linker
  • 1213 Views
  • 3 replies
  • 0 Likes
  • 24162 Posts
  • 117 Subscriptions
Top Solution Authors
Top Liked Authors
Labels