General Topics

Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

 

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! 

 

This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussi

...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 367 Views
  • 0 replies
  • 0 Likes

UIA user normalized issue

Hi,

We have 2 cluster firewalls with the same config for UIA and Group mapping.

 

If i look for an IP. show user ip-user-mapping all | match IP

I cant see a different behavior.

One cluster shows user as use@domain and groups where this user belongs -

...

BigPalo by L4 Transporter
  • 116 Views
  • 1 replies
  • 0 Likes

Palo alto interface DHCP

I have configured DHCP on 4 interfaces, each DHCP on a different subnet. I connected each Palo alto port to a unique switch with the understanding that all devices connected to particular PA port will get ip addresses only from the corresponding DHCP

...

PA440 HA failover not working

I'm having an issue with a HA failover with 2 PA440s. When I finished setting up the HA for both firewalls the first time, I was not able to sync them, it threw me a strange error and after some research, I found documentation where it stated that I

...

Resolved! Recommended PAN-OS version

Hi community

 

Today I was informed by @pshanubhog that there now is an article available in the live community about the recommended/preferred software versions by PaloAlto Networks support. The article contains the preferred versions by support for P

...

Remo by L7 Applicator
  • 573749 Views
  • 17 replies
  • 18 Likes

Active-Active NAT Rule Binding

I can't find anything which goes into enough detail on Active-Active design around NAT and more importantly ARP.

The easiest way to explain the current deployment is as follows:

  • Site 1 / Firewall A
  • Site 2 / Firewall B

Each firewall is connected to uni

...

CHammock by L2 Linker
  • 5097 Views
  • 4 replies
  • 1 Likes

Zero-Trust Strategy for Prisma

Hi all

I have been tasked with providing a Zero-Trust strategy document to management, related to how to implemenet this on our Prisma Access solution. 

I am looking for some examples that I can pull from that anyone has done this already for.

I have

...

D.Maas by L1 Bithead
  • 274 Views
  • 2 replies
  • 0 Likes

Python: panos opstate

I'm having tremendous success automating security policy updates with the panos Python library, but I'm currently stuck on obtaining the hit counts of rules programmatically. 

 

I'm able to access all attributes of the SecurityRule objects, but the o

...

dawonk by L0 Member
  • 185 Views
  • 1 replies
  • 0 Likes

Redistribution UIA not working...... INTERNAL ERROR

Hi,

I configured a PA in order to redistribute UIA mappings to another FWs. All the config is OK but its not working.

 

I can see this in the FW redistributing:

 

(active)> show redistribution service status

Redistribution info:
Redistribution service

...

BigPalo by L4 Transporter
  • 256 Views
  • 2 replies
  • 0 Likes

Configure SAML for GloblaProtect and use groups to filter

Hi,

I would like to configure SAML for my GP authentication and  I would also like to be able to assign IPs by user groups and configure rules for these remote users by user groups. 

Does anyone know if this is possible? how can match users received

...

BigPalo by L4 Transporter
  • 469 Views
  • 3 replies
  • 0 Likes

Global Protect application blank screen

Hello Members,

 

Can anyone help me to solve the global protect blank screen issue on my PC, as for others it normally works fine.

 

I am using Windows 11 and I have already removed and re-installed the GP App but still it shows a blank screen and I

...

SamiPTfA by L1 Bithead
  • 26505 Views
  • 23 replies
  • 0 Likes

ACC not displaying

PANOS version: 11.0.3-h3

We are experiencing a recurring issue with the Application Command Center (ACC) on our Palo Alto firewall. Every 2–3 days, the ACC becomes unresponsive or stops updating properly. The only way to restore functionality is by m

...

Action of allow  but of Type policy deny

Hi

panos 11.2:

 

I am using SSL Inspection for all inbound traffic on my web sites.

Certain TLS connections with TLS inspection enabled did not work. Looking at the traffic log the connections shows an Action of “allow” but of Type “deny” with Sessio

...

chens by L3 Networker
  • 844 Views
  • 13 replies
  • 0 Likes
  • 24057 Posts
  • 115 Subscriptions
Top Solution Authors
Top Liked Authors
Labels