Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.
About Panorama Discussions
Post discussions about Panorama, a centralized network security management solution for all your Palo Alto Networks firewalls irrespective of their form factors or locations, in this forum.

Discussions

Welcome to the Panorama Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by • Community Team Member
  • 5087 Views
  • 0 replies
  • 0 Likes

Forwarding system logs to log collector

Hello, Currently we have firewall sending Threat and TRAFFIC log types with CEF format to Sentinel workspace through Linux log collector with omsagent. We need to send the System log types as well from the firewall to the log collector and then in Sentinel. In order to do that we followed the steps in highlighted guide: Azure-Sentinel/Solution...

Prodan by • L0 Member
  • 3640 Views
  • 2 replies
  • 0 Likes

Panorama and PANOS RADIUS Authentication Failing after upgrade to 10.2

Hello, Thought I would pass on this solution I found. After upgrading our Panorama from 10.1 to 10.2, our RADIUS authentication no longer worked. The root cause was our Microsoft RADIUS server was using TLS 1.0 for the PEAP-MSCHAP TLS handshake and 10.2 REQUIRES TLS 1.1. The solution is to add the following registry setting to your Microsof...

BKRogers by • L1 Bithead
  • 3203 Views
  • 1 replies
  • 0 Likes

How can I provde M-200 System drive is normal

Dear Community, The customer has an SSD LED that is blue and flashing. And the document only provides HHD status was bule and have not any information about SSD. Cause I cannot find any documents to provide M-200 System device (SSD) is in normal status. M-200 Appliance Front Panel Description (paloaltonetworks.com) Replacement only prov...

SAML for external admin, local admin for internal admin

Hi, been racking my brain trying to figure this one out. Essentially, to comply with regional guidelines for our client, we are enforcing MFA for all administrative accounts on the Palo Altos, which are internet facing. I have implemented SAML authenticating with Azure AD with Microsoft Authenticator for 2FA, which is all fine and well, and I a...

Cannot create auth keys

Trying to generate an auth key to setup some dedicated log collectors. Tried in the GUI and CLI. In both instances I get the error, "Failed to add authkey. Failed to update DB." Runing 11.0.2-h2. Any suggestions?

Panorama Logs - Storage and LPS rate

Der All, I have couple of queries regarding Log storage and Lps. I have M300 Panorama appliance with Active/Passive. I have installed the Panorama HDD with full capacity which is 16TB HDD. I am managing 400+ firewall from this Panorama. For Initial period I will forward the fw logs to Panorama later will forward fw logs to SIEM solution. So ...

Ramakrishnan_2-1720506560807.png

Panorama Firewall logs

Dear All, I currently manage two M-300 Panorama devices in Active/Standby mode, each with a full disk capacity of 4x4 TB (16 TB each). My firewall logs are forwarded to the Active Panorama. Estimated log lps we need at least 93 TB of storage to store 14-15 days of logs, as we do not have that capacity at current Panorama deployment. Due to this...

Allow google translate URL

My PAN-OS Version is 10.2.7-h8 and use PA-820 I try to allow google translate,and block other URL(include google search、google drive...) When I follow the link as below,but not successfully. https://docs.paloaltonetworks.com/advanced-url-filtering/administration/configuring-url-filtering/url-category-exceptions/guidelines-for-url-category-exce...

TRANSLATE.png
yasheng by • L1 Bithead
  • 2371 Views
  • 1 replies
  • 0 Likes

Resolved! Using API to update Permitted IP Addresses list

We use the Permitted IP Addresses list (Panorama>Setup>Interfaces) to restrict access to Panorama to our public IPs. The problem we run into is that some of our devices use cellular as backup (new public IP every two days) or worse--Starlink (who change your public IP several times per day). Since this list only uses IP, not DNS, I can't...

JDBailey by • L1 Bithead
  • 5838 Views
  • 4 replies
  • 0 Likes

Panorama messages.

hi. Any idea why panorama suddenly started sending this messages a lot opaque: gRPC connection to iot.services-edge.paloaltonetworks.com:443 is broken, error: fail to parseTlsCert, err fail to load client cert[/root/client.pem], err open /root/client.pem: no such file or directory time: 2020-08-10 10:53:30 and how to fix this ? Thanks !!

policy based Ikev2 site to site VPN between Cisco router and Palo Alto

we have a policy-based site-to-site VPN between cisco router and palo alto. But the tunnel goes down and doesn't come up after the IPsec lifetime is expired. And tunnel only comes up after sending traffic from cisco to palo alto and not the other way. When The devices under the Cisco LAN subnet(192.168.2.0/24) try to communicate with the server ...

msdphi by • L2 Linker
  • 2055 Views
  • 1 replies
  • 0 Likes

VMware ESXi Panorama ha1 down

Hello - I have a VMware ESXi Panorama (10.1.10-h1) active/passive pair and the ha1 port goes down several times a day every day. This produces the following in system logs "Staying in Active state after split-brain recovery (split-brain duration: xx's". I've rebooted, ensured that the root was less than 90% and increased the Heartbeat Interva...

Built-in External Dynamic Lists - Not showing so they can be added to shared Policy

I am currently attempting to make all of my firewals look the same from a policy perspective as possible and I would like to know if there is a way to add the Built-in External Dynamic Lists To the shared policy. I understand that each firewall is updating the list based on the dynamic updates received but, I would thing that these items should...

  • 730 Posts
  • 47 Subscriptions
Top Solution Authors
Top Liked Authors
Labels