General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 3434 Views
  • 0 replies
  • 0 Likes

Reason Why Logs Are Received by SLS but Not Stored

In Strata Logging Service, ACTUAL RETENTION DAYS was shown as 0 for certain log types (such as firewall_traffic).

Meanwhile, we observed that system and dns_security logs have increasing ACTUAL RETENTION DAYS.
I understanding is that when ACTUAL RETEN

...

PALO ALTO BACKDATE SUBSCRIPTION POLICY

Could you please advise where we may obtain an official document or website link from Palo Alto Networks that formally states the backdating policy as described below?

 

Backdating on subscriptions:

  • Lapsed Orders placed after the expiration date wit

...

Resolved! Cdb process not running on PA firewall

Hi Folks,

 

Auto-commit on our passive firewall is failing. When checking the logs we could the see the commit failure reason as below:

 

PA-3220 not started, auto commit failed:

 

Details:
Management server failed to send phase 1 to client cord
Commit faile

...

Activate vsys in FW HA and impact from Panorama

Hi,

 

I have a cluster A/P 5220 model managed from panorama. I would like to activate multivsys capacity and started to configure little by little in a Cluster currently in service. All config is done from panorama.

 

What would it be the steps and i

...

BigPalo by L4 Transporter
  • 126 Views
  • 2 replies
  • 0 Likes

S2S IPsec VPN with Multiple Domain Encryption

We have experiencing difficulties having more than one domain encryption in IPsec tunnel, specifically when both are in the same subnet. Only one domain encryption remains active in the IPsec phase2. There are few times you can bounce IPsec gateway a

...

R.Thakar by L0 Member
  • 1142 Views
  • 3 replies
  • 0 Likes

unwanted installation of crtex xdr

Hi,

Since yesterday, one of my customers have the software cortex xdr on their computer. But thy don't have cortex licence, and i don't work with cortex xdr. What can i do ?

info by L0 Member
  • 46 Views
  • 0 replies
  • 0 Likes

Question on PA-440 Failover

Question regarding PA-440 and failover. 

 

How can I setup a failover in a PA-440 between two physical ports on that PA-440 firewall. For example: If Eth1/7 was connected to a cradlepoint and port 8 was a ipsec tunnel. 

 

What is the proper way to co

...

Create Custom Report for Unused Rules

Hi

I am struggling a bit here. 

I've been tasked to set up various reports on palo firewall. 

One of them is to create a custom report displaying all unused rules. 

I've tried many things. I followed this link: https://knowledgebase.paloaltonetworks.com/

...

Resolved! License Forms

Hello Team,

I'm working with a customer for whom we purchased a Support Only license, and now we would like to start working on their environment. However, we want to activate the license under their CSP account.

I am aware that this is not possible,

...

Sectigo Root CA Trusted Store Request

Greetings,
 
Sectigo has (recently) updated their Public Root Certificates (mid-2025), introducing new roots including: 
- RSA: Sectigo Public Server Authentication Root R46(https://crt.sh/?d=4256644734) 

KB Articles for reference: https://www.sectig
...

L.Yalezo by L1 Bithead
  • 1835 Views
  • 4 replies
  • 0 Likes

Support with PA-440 Software

Dear all,

 

I have a pair of HA PA-440 with the software version of 11.2.7-h4, now I want to install the version 11.2.10-h2 to remediate CVE-(High Severity Vulnerability in PAN-OS) and (Customer Advisory on Device Certificate Renewal for NGFW Devices

...

PAN OS version 11.1.13-h1 is remediate or not?

Dear all,

 

I have this questions where I want to make sure first before doing an upgrade on my PA-820?

 

Recently I have gone through the customer advisory of the following: (Customer Advisory on Device Certificate Renewal for NGFW Devices in Active

...

  • 24299 Posts
  • 122 Subscriptions
Top Liked Authors
Labels