General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

CPE for the Conferences or Summits

Hello,

Can anyone help me how to check how many ISC2 CPEs are provided from Palo for the Summit and Conferences (like one we have recently in London Threat Management MicroSummit on 5th Dec-2023?

 

Thank you

Regards

Hina

Failed to Fetch the Device Certificate

Hi Team,

 

I facing the issue to install the device certificate. I have generated the OTP in CSP. and installed it in the panorama-managed firewall. but we are getting the below error ' Failed to fetch the device certificate.TPM public key match fail

...

Packet buffer protection - PA5220 vs PA5410

I've recently upgraded my firewall from a PA-5220 pair to a PA-5410 pair. The firewalls were on the same PanOS version (10.2.4-h2) and with the same configuration. This was the original configuration for PBP at the upgrade time:
The 5220 wasn't loggin

...

Screenshot 2023-06-21 alle 13.32.49.png
Screenshot 2023-06-21 alle 13.14.05.jpg
Screenshot 2023-06-21 alle 13.14.44.jpg
Screenshot 2023-06-21 alle 13.47.53.png

Dual ISP failover - stuck UDP sessions

Hi, I've configured Dual ISP failover using a PBF and everything seems to failover from ISP1 to ISP2  just fine. My issue is after we have failed over to ISP2 and ISP1 comes back online, not all traffic flips back to ISP1. 

 

UDP sessions for devices t

...

GobalProtect setup accross multiple standalone FWs in Azure

Hi All,

 

current setup more or less..

 

                                      |---PAN FW1---|

internet -->--- Ext LB----                         ---Int LB--------Azure Env

                                      |---PAN FW2---|

 

PAN FW1 and PAN FW2 a

...

PA_nts by L3 Networker
  • 1036 Views
  • 7 replies
  • 0 Likes

Export/import tool using set commands

"Hello to the Palo Alto Networks community,

After conducting research on the tasks of exporting and importing configuration file in PA-VM version 10, I've learned that using file transfer protocols like TFTP and SCP allows for the export and import o

...

RChan39 by L0 Member
  • 268 Views
  • 0 replies
  • 0 Likes

PA-3220 after upgrade into 10.2.6

Experience applications flow issue, most of the sessions incomplete (i deleted all active sessions with no resolution), reboot, fail-over several times, no luck. I opened a ticket with Tech support for advance packet flow process analysis no resoluti

...

elmgbar by L1 Bithead
  • 848 Views
  • 5 replies
  • 0 Likes

DH group 15 not supported in phase 1 with IKE v1?

I need to migrate an old firewall to a PA-440 and came across an ancient IPsec where they have used DH group 15 for both phase 1 and 2. According to the docs for PanOS 10.2 DH 15 is now supported but the 440 whines about DH15 in phase 1 as I use IKE

...

Resolved! License renewal

Please confirm if the expired PaloAlto licenses can be renewed?

If “YES”, Please confirm which of the expired PaloAlto licenses can be renewed?

not able to open support case

Hi,

 

When I try to open support case error message coming up saying "Problem Category is missing".

 

Although I select the product as PAN-OS while creating the case.

 

BR,

Alaa

aasaggaf by L0 Member
  • 288 Views
  • 1 replies
  • 0 Likes

Best upgrade practice with HA Pair ?

We are preparing to update this weekend to 10.2.7 to resolve the expiring root certificate issue. We have an HA pair that we want to failover while upgrading as to not disrupt service. While I have the upgrade path from the Palo documentation what I

...

Walt by L1 Bithead
  • 591 Views
  • 1 replies
  • 0 Likes

Setting Up Double NAT over a site-to-site VPN

Hi,

 

I've been trying to read up on if it is possible to set up what Cisco would call "Twice NAT" on Palo Alto, and while there seems to be a lot out there for really odd fringe cases, I'm struggling to find anything on what I think would be a reall

...

Jamin79 by L0 Member
  • 715 Views
  • 3 replies
  • 0 Likes
  • 24215 Posts
  • 99 Subscriptions
Top Liked Authors
Labels