General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

New Internet connection - break up HA pair to provision?

We have a pair of PA440s as our main firewall, with a fairly complex but not totally weird configuration - all physical interfaces in use, some with sub-interfaces, NAT to some inbound servers, VPN, URL filtering, etc etc. We have a new Internet connection - same provider, but with upgraded service that precluded just turning up the speed. ...

Certain logs not sending to Splunk

Hi All, PA 1410PAN-OS 11.1.13-h9license valid Advanced URL Filtering Advanced WildFire License Just recently i have configure Log forwarding to our Splunk. We follow this document https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGwCAK the splunk is successfully receive Traffic, Threat, System, GlobalProtect, and ...

ACME and SSL decryption

So i recently got wind of this: https://www.thesslstore.com/blog/47-day-ssl-certificate-validity-by-2029/ acme.sh and/or certbot takes care of the servers, but won't this break existing SSL decryption rules? Any strategies/workarounds for this? tia

Palo Alto Networks NGFW Best Practice Assessment (BPA) via the Posture API

Palo Alto Networks NGFW Best Practice Assessment (BPA) via the Posture API Client & Partner Implementation Guide — Windows PowerShell Workflow Purpose This guide provides a practical end-to-end procedure for generating an on-demand Best Practice Assessment (BPA) from a Palo Alto Networks firewall configuration using the Strata Cloud Manager ...

JeanPaul222_1-1786098312985.png
JeanPaul222_2-1786098327651.png
JeanPaul222_3-1786098347950.png
JeanPaul222_5-1786098493750.png

Panorama Major PAN-OS Upgrade - Full Commit and Push Requirement

Greetings All, Seeking clarification on the full commit and push of Panorama configuration required after upgrading to a major version (ex: 10.2.x to 11.1.x) outlined in step 13 of Upgrade Panorama with an Internet Connection. Is this actually required? This requirement is not outlined in the following LIVECommunity articles / KB articles ...

nohash4u by L3 Networker
  • 60 Views
  • 1 replies
  • 0 Likes

Resolved! Trial VM-Series OVA-deployed VM stuck at PA-HDF login prompt for over 24 hours; multiple hosts and multiple attempts

Hello! I reached out to receive a trial for the VM-Series NGFW so I could practice/lab out some configs during my certification path. I have followed all of the instructions provided, confirmed ESXi version was fine, increased vCPU and RAM allocated following the sizing guide, and tried being patient, but multiple attempts at getting the VM-se...

VRT-JH by L1 Bithead
  • 21492 Views
  • 9 replies
  • 0 Likes

ARP table By SNMP

Hi, Any idea How I get ARP table from Palo Alto Firewalls (PA-200, PA-500 and PA-3020) by SNMP? Did try BRIDGE-MIB::dot1dTpFdbTable but gave me NULL resualts Mike Alani

SAML SSO Admins Cannot Install Software Updates - "You don't have superuser access"

Hello Everyone, We are troubleshooting an issue where administrators authenticated through Microsoft Entra ID (Azure AD) SAML SSO are unable to install PAN-OS software updates. Environment: Palo Alto Firewall Microsoft Entra ID SAML SSO Authentication Profile configured with: Admin Role Attribute: adminrole Entra ID SAML Claim: adminrole ...

Resolved! VM100 SCM support

Hi, looking for some clarification on VM100 SCM support. I have a customer who has onboarded two VM100s (HA pair) and is currently managing their configuration via SCM. No issues there, however when we look at the Dashboard there is no evidence of these devices at all. Other firewalls are showing, but the VM100s are missing. Telemetry appears ...

Resolved! [SOLVED] Prisma Access Panorama-Managed The Serviceability Commands Are Not Working!!

Hello LiveCommunity Team! I created this post to share my experience with an issue regarding the *Serviceability Commands* function in version 6.1.0-h7 of the Panorama Cloud Service plugin. My client reports that this function is not operating as expected; the EDL and routing information sections appear empty, do not allow the selection of speci...

DanielSRomero_0-1785964009584.png
DanielSRomero_2-1785964529454.png

Resolved! EOS devices and License Relationship. (PA-220)

Hi, I am worried about PA-220 EOS. I have PA-220 and bought 5 licenses. (Threat Prevention, GlobalProtect Gateway, PAN-DB URL Filtering, WildFire License, Premium Partner Support) As described in the link below, our device is EOS. But not EOL. https://www.paloaltonetworks.com/services/support/end-of-life-announcements/hardware-end-of-life-...

tsenturk by L0 Member
  • 3916 Views
  • 4 replies
  • 0 Likes

Resolved! Server Monitoring Not Connected

Hello, Microsoft AD under Server Monitoring is showing as 'not connected.'We would like to use the PAN-OS Integrated User-ID AgentOutput from debug commands show UserID Debug Log is enabled but nothing is logging. Anyone encountered similar issue?

Resolved! PA Active/Passive and Cisco stacking LACP

hello, we have setup Active/ Passive connected with cisco stacking 9500 with four links full-mesh as shown below: Paloalto active: PA(active) AE1 ========= cisco-1 switch (Etherchanel 10) PA(active) AE1 ========= cisco-2 switch (Etherchanel 20) Paloalto Passive: PA(passive) AE1 ========= cisco-1 switch (Etherchanel 10) PA(passive) AE1 ...

Prisma Access HIP object Windows patch management

We have created a HIP profile and configured windows patch management. However, the options under this is not very clear. I have to get some clarifications on thisMissing Patches - Severity When the operator is set to Greater Than or Equal To, what values are valid in the field? We currently use 3, assuming this represents Critical Windows sec...

K.Herath by L0 Member
  • 122 Views
  • 1 replies
  • 0 Likes
  • 24422 Posts
  • 125 Subscriptions
Top Solution Authors
Labels