General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Starlink DHCP Route Injection dropping if DHCP expires briefly

This is a remote location with a Starlink connected directly into a Palo Alto 510. We have another backup satellite connection provider which should be used for emergency / comms only when Starlink goes offline. Starlink renews its DHCP lease every 5 minutes. Normally, this works fine, and gets renewed successfully without interruption. Once...

Cortex XSOAR community edition

Hi all, I signed up via this link (https://start.paloaltonetworks.com/sign-up-for-community-edition.html) for Cortex XSOAR community edition about 1-2 hours. But still did not receive any mail or link to download. How long should I wait for mail or link?Thanks in advance!

Palo Alto Networks NGFW Best Practice Assessment (BPA) via the Posture API

Palo Alto Networks NGFW Best Practice Assessment (BPA) via the Posture API Client & Partner Implementation Guide — Windows PowerShell Workflow Purpose This guide provides a practical end-to-end procedure for generating an on-demand Best Practice Assessment (BPA) from a Palo Alto Networks firewall configuration using the Strata Cloud Manager ...

JeanPaul222_1-1786098312985.png
JeanPaul222_2-1786098327651.png
JeanPaul222_3-1786098347950.png
JeanPaul222_5-1786098493750.png

GlobalProtect Mobile Initial SAML Authentication with ID Fails After Upgrading to PAN-OS 10.2.18-h6

Hi , Observed Behavior- Before upgrading to PAN-OS 10.2.18-h1, GlobalProtect SAML authentication using ID worked normally on all platforms.- After upgrading to PAN-OS 10.2.18-h6, only Android, iPhone, and iPad are affected.- Initial SAML authentication fails only on mobile clients.- Windows clients continue to authenticate successfully using t...

connection failed unsupported URL.jpg
connection failed ERR_UNKNOWN_URL_SCHEME.jpg

Resolved! Panorama Major PAN-OS Upgrade - Full Commit and Push Requirement

Greetings All, Seeking clarification on the full commit and push of Panorama configuration required after upgrading to a major version (ex: 10.2.x to 11.1.x) outlined in step 13 of Upgrade Panorama with an Internet Connection. Is this actually required? This requirement is not outlined in the following LIVECommunity articles / KB articles ...

nohash4u by L3 Networker
  • 187 Views
  • 2 replies
  • 0 Likes

Certain logs not sending to Splunk

Hi All, PA 1410PAN-OS 11.1.13-h9license valid Advanced URL Filtering Advanced WildFire License Just recently i have configure Log forwarding to our Splunk. We follow this document https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGwCAK the splunk is successfully receive Traffic, Threat, System, GlobalProtect, and ...

New Internet connection - break up HA pair to provision?

We have a pair of PA440s as our main firewall, with a fairly complex but not totally weird configuration - all physical interfaces in use, some with sub-interfaces, NAT to some inbound servers, VPN, URL filtering, etc etc. We have a new Internet connection - same provider, but with upgraded service that precluded just turning up the speed. ...

ACME and SSL decryption

So i recently got wind of this: https://www.thesslstore.com/blog/47-day-ssl-certificate-validity-by-2029/ acme.sh and/or certbot takes care of the servers, but won't this break existing SSL decryption rules? Any strategies/workarounds for this? tia

Resolved! Trial VM-Series OVA-deployed VM stuck at PA-HDF login prompt for over 24 hours; multiple hosts and multiple attempts

Hello! I reached out to receive a trial for the VM-Series NGFW so I could practice/lab out some configs during my certification path. I have followed all of the instructions provided, confirmed ESXi version was fine, increased vCPU and RAM allocated following the sizing guide, and tried being patient, but multiple attempts at getting the VM-se...

VRT-JH by L1 Bithead
  • 21555 Views
  • 9 replies
  • 0 Likes

ARP table By SNMP

Hi, Any idea How I get ARP table from Palo Alto Firewalls (PA-200, PA-500 and PA-3020) by SNMP? Did try BRIDGE-MIB::dot1dTpFdbTable but gave me NULL resualts Mike Alani

SAML SSO Admins Cannot Install Software Updates - "You don't have superuser access"

Hello Everyone, We are troubleshooting an issue where administrators authenticated through Microsoft Entra ID (Azure AD) SAML SSO are unable to install PAN-OS software updates. Environment: Palo Alto Firewall Microsoft Entra ID SAML SSO Authentication Profile configured with: Admin Role Attribute: adminrole Entra ID SAML Claim: adminrole ...

Resolved! VM100 SCM support

Hi, looking for some clarification on VM100 SCM support. I have a customer who has onboarded two VM100s (HA pair) and is currently managing their configuration via SCM. No issues there, however when we look at the Dashboard there is no evidence of these devices at all. Other firewalls are showing, but the VM100s are missing. Telemetry appears ...

Resolved! [SOLVED] Prisma Access Panorama-Managed The Serviceability Commands Are Not Working!!

Hello LiveCommunity Team! I created this post to share my experience with an issue regarding the *Serviceability Commands* function in version 6.1.0-h7 of the Panorama Cloud Service plugin. My client reports that this function is not operating as expected; the EDL and routing information sections appear empty, do not allow the selection of speci...

DanielSRomero_0-1785964009584.png
DanielSRomero_2-1785964529454.png

Resolved! EOS devices and License Relationship. (PA-220)

Hi, I am worried about PA-220 EOS. I have PA-220 and bought 5 licenses. (Threat Prevention, GlobalProtect Gateway, PAN-DB URL Filtering, WildFire License, Premium Partner Support) As described in the link below, our device is EOS. But not EOL. https://www.paloaltonetworks.com/services/support/end-of-life-announcements/hardware-end-of-life-...

tsenturk by L0 Member
  • 3969 Views
  • 4 replies
  • 0 Likes

Resolved! Server Monitoring Not Connected

Hello, Microsoft AD under Server Monitoring is showing as 'not connected.'We would like to use the PAN-OS Integrated User-ID AgentOutput from debug commands show UserID Debug Log is enabled but nothing is logging. Anyone encountered similar issue?

  • 24424 Posts
  • 125 Subscriptions
Top Solution Authors
Labels