top of page

Category ✅
Search


Prisma Access GlobalProtect Portal Reachable, Apps Dead: Service Connection Check
Prisma Access needs a healthy service connection / service connection to the DC. User tunnel up is not DC reachability. Techclick CLI lab: symptoms, commands, traps, and proof.
-
Aug 152 min read


Palo Alto Interface Down After Reboot: show interface Hardware vs Protocol
Split hardware down from protocol down. Speed/duplex, aggregate membership, and vsys assignment are the usual post-reboot surprises. Techclick CLI lab: symptoms, commands, traps, and proof.
-
Aug 152 min read


Palo Alto PBF Ignored: test pbf-policy-match When Default Route Wins Anyway
Policy Based Forwarding is a first lookup. If test pbf-policy-match misses, the virtual router default route wins. Check source zone, enforce symmetric return, and next-hop liveliness. Techclick CLI lab: symptoms, commands, traps, and proof.
-
Aug 152 min read


Palo Alto WildFire Stuck Pending: CLI to See If Samples Are Leaving the Box
Check WildFire status, forwarding, and file-size limits. Pending forever usually means no cloud reachability or the file type is not forwarded. Techclick CLI lab: symptoms, commands, traps, and proof.
-
Aug 152 min read


Palo Alto Zone Protection Silent Drops: show counter global When Ping Lies
Zone protection and flood protection drop before policy. Read show counter global filter severity drop and the zone-protection profile counters. Techclick CLI lab: symptoms, commands, traps, and proof.
-
Aug 152 min read


Panorama Commit Failed: show jobs processed When the Push Never Reaches the Firewall
A Panorama commit is not a firewall commit. Use show jobs processed on Panorama and on the firewall, then push again only to the devices that failed. Techclick CLI lab: symptoms, commands, traps, and proof.
-
Aug 152 min read


Palo Alto App-ID Unknown-TCP: When to Use Application Override vs More Time
unknown-tcp means App-ID did not finish. Give it time and a decoder first. Application-override is a scalpel for a known private protocol, not a shortcut for every deny. Techclick CLI lab: symptoms, commands, traps, and proof.
-
Aug 152 min read


Palo Alto Dataplane High CPU: show running resource-monitor Before You Reboot
Use show running resource-monitor and packet-diag before reboot. High CPU is usually one flow, one app-id, or one flood — reboot only hides the next cycle. Techclick CLI lab: symptoms, commands, traps, and proof.
-
Aug 152 min read


Palo Alto User-ID Empty: show user ip-user-mapping When User Rules Never Hit
If show user ip-user-mapping ip <host> is empty, the user rule cannot match. Fix the agent, WMI, or syslog mapping before you change policy. Techclick CLI lab: symptoms, commands, traps, and proof.
-
Aug 152 min read


Palo Alto NAT Miss: test nat-policy-match When Return Traffic Dies
Run test nat-policy-match for both directions. If destination NAT is missing or source NAT is hiding the server, the return packet never finds the original session. Techclick CLI lab: symptoms, commands, traps, and proof.
-
Aug 152 min read


Palo Alto GlobalProtect Portal Up, Gateway Down: CLI Split That Saves an Hour
Portal and gateway are different listeners. Prove portal auth, then test the gateway IP, SSL profile, and client IP pool separately. Techclick CLI lab: symptoms, commands, traps, and proof.
-
Aug 152 min read


Palo Alto SSL Decrypt Breaks One SaaS App: CLI to Find the Decrypt Policy
Identify the session, confirm it is decrypted, then exclude that app or that certificate pin from ssl-inbound/forward-proxy. Do not turn off decryption globally. Techclick CLI lab: symptoms, commands, traps, and proof.
-
Aug 152 min read


Palo Alto Security Policy Miss: test security-policy-match When Traffic Hits Interzone-Default
Use test security-policy-match with the real 5-tuple and application. If the result is interzone-default, the session never reached your intended rule — fix zone, user, or app-id before you add another any-any. Techclick CLI lab: symptoms, commands, traps, and proof.
-
Aug 152 min read


Palo Alto IKE Phase-1 Up, Phase-2 Down: Proxy-ID CLI That Most Teams Skip
Phase-1 only proves IKE identity. Phase-2 dies when proxy-IDs / encryption domains do not match. Align local/remote networks, not the IKE gateway. Techclick CLI lab: symptoms, commands, traps, and proof.
-
Aug 152 min read


Palo Alto HA Suspended: CLI Checks When Active-Passive Stops Failing Over
Run show high-availability state on both peers. If one side is suspended, clear the suspend, confirm HA1/HA2 are up, then fail over only after running-config is synced. Techclick CLI lab: symptoms, commands, traps, and proof.
-
Aug 152 min read
Palo Alto Security Policy Not Matching: Proving Which Rule Traffic Actually Hit
The rule looks correct, the traffic still gets denied. Here is the exact order to prove which rule matched, why App-ID changed the answer mid-session, and the shadowing check most engineers skip.
-
Aug 153 min read


-
Jul 14, 20250 min read


-
Jul 8, 20250 min read


-
Jun 22, 20250 min read


-
Jun 20, 20250 min read
bottom of page