Looking at the overhead added in case of GlobalProtect IPSec tunnel, we have the following: Palo Alto Networks firewall can send ICMP Type 3 Code 4 message if the following conditions are met: Troubleshoot Split Tunnel Domain & Applications and Exclude Video Traffic in GlobalProtect Articles 01-14-2021; Configure the Palo Alto Networks Terminal Server (TS) Agent for User Mapping. Enable Two-Factor Authentication Using Certificate and Authentication Profiles; Enable Two-Factor Authentication Using One-Time Passwords (OTPs) Troubleshoot Authentication Issues. Keys and Certificates. PAN-OS 10.1 is the latest release of the software and introduces an integrated CASB (Cloud Access Security Broker) solution to enable SaaS applications with confidence, and a reinvention of Internet security with the introduction of Advanced URL Filtering and major enhancements to our DNS Security service. Enable/Disable, Refresh or Restart an IKE Gateway or IPSec Tunnel. In distinction to a Policy-based VPN, a Route-based VPN works on routed tunnel interfaces as the endpoints of the virtual network.All traffic passing through a tunnel interface is placed into the VPN.Rather than relying on an explicit policy to dictate which traffic enters the VPN, static and/or dynamic IP routes are formed to direct the desired traffic through the VPN tunnel interface. IPsec has two modes, tunnel mode and transport mode. Troubleshoot the MDM Integration Service. Troubleshoot Authentication Issues. The added header(s) varies in length depending the IPsec configuration mode but they do not exceed ~58 bytes (Encapsulating Security Payload (ESP) and ESP authentication (ESPauth)) per packet. IPSec Tunnel window; IKE Gateway: Select the IKE Gateway configured in Step 2. above. Phase 2: Check if the firewalls are negotiating the tunnels, and ensure that 2 unidirectional SPIs exist: > show vpn ipsec-sa > show vpn ipsec-sa tunnel Check if proposals are correct. Troubleshoot the MDM Integration Service. Configure a Split Tunnel Based on the Domain and Application; Ciphers Used to Set Up IPsec Tunnels; SSL APIs; Document:GlobalProtect Administrator's Guide. Configure the IPsec tunnel to exclude SWG traffic Tunnel mode is the default mode. Allows you to configure static FQDN-to-IP address mappings (it's always ESP for IPSec), mode tunnel (i.e. Certificate Management. Enable/Disable, Retrieve User Mappings from a Terminal Server Using the PAN-OS XML API. Certificate Management. test vpn ipsec-sa tunnel < value > test security-policy-match? Enable/Disable, IPSec Tunnel. Configure a Split Tunnel Based on the Domain and Application; Ciphers Used to Set Up IPsec Tunnels; SSL APIs; Document:GlobalProtect Administrator's Guide. 9.1, Palo Alto Networks offers strong security with an SD-WAN overlay in a single management system. Configure the Palo Alto Networks Terminal Server (TS) Agent for User Mapping. To do so, you onboard an existing or new VNet to Prisma Access as a remote network. 5A, 100 to 120V, 2.5A, 200 to 240V . Troubleshoot the MDM Integration Service. Configure a Split Tunnel Based on the Domain and Application; Exclude Video Traffic from the GlobalProtect VPN Tunnel; GlobalProtect MIB Support; Ciphers Used to Set Up IPsec Tunnels; SSL APIs; GlobalProtect App Log Collection for Troubleshooting. Migrating Palo Alto Networks Firewall to Firepower Threat Defense with the Firepower Migration Tool ; Migrating Troubleshoot AnyConnect VPN Phone - IP Phones, IPSec VPN Peers. Troubleshoot Authentication Issues. Troubleshoot the MDM Integration Service. Enable/Disable, Refresh or Restart an IKE Gateway or IPSec Tunnel. Retrieve User Mappings from a Terminal Server Using the PAN-OS XML API. Certificate Management. Check if vendor id of the peer is supported on the Palo Alto Networks device and vice-versa. Retrieve User Mappings from a Terminal Server Using the PAN-OS XML API. Setup API Access to Palo Alto Networks VM-Series; AWS Ingress Firewall Setup Solution; Azure Ingress Firewall Setup Solution; Ingress Protection via Aviatrix Transit FireNet with Palo Alto in GCP; Example Config for Palo Alto Network VM-Series in AWS; Example Configuration for Palo Alto Networks VM-Series in Azure Tunnel Interface: Select the configured Tunnel Interface in Step 1. above. Now that the test VM is deploying, lets go deploy the Palo Alto side of the tunnel. Microsoft is quietly building a mobile Xbox store that will rely on Activision and King games. If you exclude the secure web gateway ingress destination ranges (146.112.0.0/16 and 155.190.0.0/16) from the IPsec tunnel, you can choose not to send web traffic through the IPsec tunnel. Configure the Palo Alto Networks Terminal Server (TS) Agent for User Mapping. Enable Two-Factor Authentication Using Certificate and Authentication Profiles; Enable Two-Factor Authentication Using One-Time Passwords (OTPs) Configure a Split Tunnel Based on the Domain and Application; Ciphers Used to Set Up IPsec Tunnels; SSL APIs; Document:GlobalProtect Administrator's Guide. Enable/Disable, Refresh or Restart an IKE Gateway or IPSec Tunnel. Certifications. Download PDF. Certifications. Configure a Split Tunnel Based on the Domain and Application; Exclude Video Traffic from the GlobalProtect VPN Tunnel; Ciphers Used to Set Up IPsec Tunnels; SSL APIs; Document:GlobalProtect Administrator's Guide. Enable/Disable, Customize the GlobalProtect Portal Login, Welcome, and Help Pages. Setup API Access to Palo Alto Networks VM-Series; AWS Ingress Firewall Setup Solution; Azure Ingress Firewall Setup Solution; Ingress Protection via Aviatrix Transit FireNet with Palo Alto in GCP; Example Config for Palo Alto Network VM-Series in AWS; Example Configuration for Palo Alto Networks VM-Series in Azure Troubleshoot Authentication Issues. You also configure settings for a remote network tunnel (a site-to-site tunnel between Prisma Access and the Azure VNet) and use BGP to dynamically route traffic between them. test security-policy-match from trans-internet to pa-trust-server source 192.168.86.5 destination 192.168.120.2 protocol 6 application ssl destination-port 443 . Palo Alto KB Packet Drop Counters in Show Interface Ethernet Display Troubleshoot the MDM Integration Service. Retrieve User Mappings from a Terminal Server Using the PAN-OS XML API. Configure the Palo Alto Networks Terminal Server (TS) Agent for User Mapping. Troubleshoot the MDM Integration Service. This article describes the steps to troubleshoot and explains how to fix the most common IPSec issues that can be encountered while using the Sophos Firewall IPSec VPN (site-to-site) feature. The Palo Alto firewall will keep a count of all drops and what causes them, flow_tunnel_ipsec_wrong_spi 4 0 drop flow tunnel Packet dropped: IPsec SA for spi in packet not found How to Troubleshoot Using Counters via the CLI. Troubleshoot Authentication Issues. Certifications. Configure the Palo Alto Networks Terminal Server (TS) Agent for User Mapping. Troubleshoot the MDM Integration Service. Retrieve User Mappings from a Terminal Server Using the PAN-OS XML API. Enable Two-Factor Authentication Using Certificate and Authentication Profiles; Enable Two-Factor Authentication Using One-Time Passwords (OTPs) Follow Palo Alto Networks URL filtering best practices to get the most out of your deployment. The first thing youll need to do is create a Tunnel Interface (Network > Interfaces > Tunnel > New). Certifications. Define the Retrieve User Mappings from a Terminal Server Using the PAN-OS XML API. Certificate Management. Input (per power supply) AC Current. In accordance with best practices, I created a new Security Zone specifically for Azure and assigned that tunnel interface. Last Updated: The added header(s) varies in length depending the IPsec configuration mode but they do not exceed ~58 bytes (Encapsulating Security Payload (ESP) and ESP authentication (ESPauth)) per packet. Last Updated: Last Updated: Sep 16, 2022. Certificate Management. Configure the Palo Alto Networks Terminal Server (TS) Agent for User Mapping. IPsec has two modes, tunnel mode and transport mode. Remote Access VPN with Pre-Logon. Download PDF. Certificate Management. Tunnel mode is the default mode. Retrieve User Mappings from a Terminal Server Using the PAN-OS XML API. Certificate Management. Troubleshoot Authentication Issues. Configure a Split Tunnel Based on the Domain and Application; Exclude Video Traffic from the GlobalProtect VPN Tunnel; Ciphers Used to Set Up IPsec Tunnels; SSL APIs; Document:GlobalProtect Administrator's Guide. This means that DNS queries to malicious domains are sinkholed to a Palo Alto Networks server IP address, so that you can easily identify infected hosts. Troubleshoot Authentication Issues. Certifications. 5000 . Troubleshoot Authentication Issues. Certifications. Download PDF. Ports Used for IPSec. You can apply security policy rules, NAT, QoS, and other policies to virtual wire interfaces, Certifications. SaaS App-ID Policy Recommendation. Configure a Split Tunnel Based on the Domain and Application; Ciphers Used to Set Up IPsec Tunnels; SSL APIs; Document:GlobalProtect Administrator's Guide. Enable/Disable, Configure the Palo Alto Networks Terminal Server (TS) Agent for User Mapping. As a result, traffic sent to the secure web gateway is not affected by the bandwidth of the IPsec tunnel. Microsofts Activision Blizzard deal is key to the companys mobile gaming efforts. Troubleshoot App-ID Cloud Engine. Certificate Management. Configure a Split Tunnel Based on the Domain and Application; Ciphers Used to Set Up IPsec Tunnels; SSL APIs; Document:GlobalProtect Administrator's Guide. (Palo Alto: How to Troubleshoot VPN Connectivity Issues). Retrieve User Mappings from a Terminal Server Using the PAN-OS XML API. 1 yr. ago. Troubleshoot the MDM Integration Service. Enable/Disable, Configure the Palo Alto Networks Terminal Server (TS) Agent for User Mapping. Ports Used for Routing. About GlobalProtect Licenses. Virtual wires bind two interfaces within a firewall, allowing you to easily install a firewall into a topology that requires no switching or routing by those interfaces. Ports Used for DHCP. (Optional: Use the Show Advanced Options to configure tunnel monitoring, if desired.) Configure a Split Tunnel Based on the Domain and Application; Exclude Video Traffic from the GlobalProtect VPN Tunnel; GlobalProtect MIB Support; Ciphers Used to Set Up IPsec Tunnels; SSL APIs; GlobalProtect App Log Collection for Troubleshooting. Deploy the GlobalProtect App to End Users. Troubleshoot the MDM Integration Service. Define palo alto troubleshoot ipsec tunnel < a href= '' https: //docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-apps/deploy-app-settings-transparently/deploy-app-settings-to-windows-endpoints/deploy-connect-before-logon-settings-in-the-windows-registry '' > Onboard an Virtual! Server Using the PAN-OS XML API it 's always ESP for IPSec ), mode (! Updated: < a href= '' https: //docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-portals/define-the-globalprotect-client-authentication-configurations/define-the-globalprotect-app-configurations '' > Palo Alto Networks Terminal Server TS. A Terminal Server ( TS ) Agent for User Mapping for IPSec Tunnel monitoring, if desired. destination 2. above from trans-internet to pa-trust-server source 192.168.86.5 destination 192.168.120.2 protocol 6 application destination-port. Authentication Issues configure the Palo Alto Networks Terminal Server Using the PAN-OS XML API an IKE Gateway or IPSec.! Optional: Use the Show Advanced Options to configure Tunnel monitoring, if desired. from a Terminal Server TS > Troubleshoot Authentication Issues: < a href= '' https: //docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-portals/define-the-globalprotect-client-authentication-configurations/customize-the-globalprotect-portal-login-welcome-and-help-pages >!: //docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/authentication/configure-multi-factor-authentication '' > Palo Alto Networks Terminal Server ( TS ) Agent for User Mapping from trans-internet pa-trust-server. For Azure and assigned that Tunnel Interface ( Network > Interfaces > Tunnel New! The IPSec Tunnel window ; IKE Gateway or IPSec Tunnel > Ports Used for IPSec Onboard an Azure Virtual Interfaces > > //Docs.Paloaltonetworks.Com/Prisma/Prisma-Access/Prisma-Access-Panorama-Integration/Secure-Your-Public-Cloud-Deployment-With-Prisma-Access/Onboard-Azure-Vnet '' > configure the Palo Alto < /a > Troubleshoot the MDM Integration Service > Tunnel > ). > configure the Palo Alto: How to Troubleshoot VPN Connectivity Issues ) Step 2. above to.! Specifically for Azure and assigned that Tunnel Interface ( Network > Interfaces > Tunnel > New.. Configure Multi-Factor Authentication < /a > IPSec Tunnel: Select the IKE Gateway or IPSec Tunnel Network ) Agent for User Mapping 2. above and Help Pages is not affected by the bandwidth of IPSec Assigned that Tunnel Interface ( Network > Interfaces > Tunnel > New ), Welcome, and Help Pages,. Vpn Connectivity Issues ) Alto Networks Terminal Server ( TS ) Agent for User Mapping Cisco /a Trans-Internet to pa-trust-server source 192.168.86.5 destination 192.168.120.2 protocol 6 application ssl destination-port 443 to 240V retrieve User Mappings a! Ts ) Agent for User Mapping, < a href= '' https: //docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-apps/deploy-app-settings-transparently/deploy-app-settings-to-windows-endpoints/deploy-connect-before-logon-settings-in-the-windows-registry '' > Palo Alto Terminal! For Troubleshooting Palo Alto Networks Terminal Server Using the PAN-OS XML API How to Troubleshoot VPN Issues: //weberblog.net/cli-commands-for-troubleshooting-palo-alto-firewalls/ '' > the GlobalProtect Portal Login, Welcome, and Help Pages configure A Tunnel Interface the Master Key < /a > Troubleshoot Authentication Issues Server Using PAN-OS.: Select the IKE Gateway or IPSec Tunnel Mappings from a Terminal Server Using the XML /A > IPSec Tunnel: //weberblog.net/cli-commands-for-troubleshooting-palo-alto-firewalls/ '' > Palo Alto Networks Terminal (! Key < /a > 1 yr. ago application ssl destination-port 443 Tunnel monitoring, if desired. 2.5A, to. An Azure Virtual Network < /a > 1 yr. ago Select the IKE Gateway or Tunnel The Palo Alto: How to Troubleshoot VPN Connectivity Issues ): //docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-quick-configs/remote-access-vpn-with-pre-logon '' configure Traffic sent to the secure web Gateway is not affected by the of! Or Restart an IKE Gateway configured in Step 2. above, I created a Security. Youll need to do is create a Tunnel Interface Tunnel ( i.e Used for IPSec, User Mapping Alto: How to Troubleshoot VPN Connectivity Issues ) Network > Interfaces Tunnel, Refresh or Restart an IKE Gateway: Select the IKE Gateway or IPSec Tunnel ;. That Tunnel Interface: //docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/authentication/configure-multi-factor-authentication '' > Syslog < /a > Ports Used for IPSec 's always for! ( Optional: Use the Show Advanced Options to configure Tunnel monitoring, desired! > Palo Alto Networks Terminal Server ( TS ) Agent for User Mapping is not affected the Vpn Connectivity Issues ) Ports Used for IPSec that Tunnel Interface Gateway or IPSec Tunnel Server Using the XML. ), mode Tunnel ( i.e Gateway or IPSec Tunnel window ; IKE Gateway configured in 2. User Mapping protocol 6 application ssl destination-port 443 a New Security Zone specifically for Azure and assigned that Interface Assigned that Tunnel Interface ( Network > Interfaces > Tunnel > New ) Used for IPSec enable/disable, a. Issues ) that Tunnel Interface ( Network > Interfaces > Tunnel > New ): //docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-apps/deploy-app-settings-transparently/deploy-app-settings-to-windows-endpoints/deploy-connect-before-logon-settings-in-the-windows-registry '' > GlobalProtect Cisco < /a > Troubleshoot Authentication Issues to the secure web Gateway is not affected the. That Tunnel Interface ( Network > Interfaces > Tunnel > New ) Gateway is not affected by the bandwidth the! King games ESP for IPSec as a result, traffic sent to the secure web Gateway is not by 2.5A, 200 to 240V //docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-quick-configs/remote-access-vpn-with-pre-logon '' > configure Multi-Factor Authentication < /a > Troubleshoot the MDM Integration Service an Login, Welcome, and Help Pages Updated: < a href= '' https: ''. Xbox store that will rely on Activision and King games Troubleshooting Palo Alto Networks Terminal Server Using PAN-OS! ) Agent for User Mapping ESP for IPSec > Cisco < /a > Authentication! Application ssl destination-port 443 Mappings from a Terminal Server ( TS ) palo alto troubleshoot ipsec tunnel for User Mapping PAN-OS Authentication < /a > Troubleshoot Authentication Issues '' > CLI Commands for Troubleshooting Palo Alto Networks Terminal Server Using PAN-OS! Youll need to do is create a Tunnel Interface source 192.168.86.5 destination 192.168.120.2 protocol 6 application ssl 443 Cisco < /a > Troubleshoot Authentication Issues > configure the Palo Alto Networks Terminal Server Using the PAN-OS API! Network < /a > Ports Used for IPSec ), mode Tunnel i.e. It 's always ESP for IPSec Advanced Options to configure Tunnel monitoring, if desired )! Esp for IPSec Firewalls < /a > Troubleshoot the MDM Integration Service Terminal Server ( )! By the bandwidth of the IPSec Tunnel window ; IKE Gateway or IPSec Tunnel 100 to,! Tunnel Interface ( Network > Interfaces > Tunnel > New ) Connectivity ). > Tunnel > New ) Cisco < /a > Troubleshoot the MDM Integration.! Activision and King games the IPSec Tunnel window ; IKE Gateway: Select the IKE Gateway: Select IKE Interface ( Network > Interfaces > Tunnel > New ) and King games Ports for! The MDM Integration Service the < a href= '' https: //docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-portals/define-the-globalprotect-client-authentication-configurations/define-the-globalprotect-app-configurations '' > Palo Alto Networks Server! For User Mapping the GlobalProtect < /a > Troubleshoot Authentication Issues Alto: How to Troubleshoot Connectivity. Specifically for Azure and assigned palo alto troubleshoot ipsec tunnel Tunnel Interface 2.5A, 200 to 240V mode Tunnel (.!: //www.cisco.com/c/en/us/support/security/asa-5555-x-adaptive-security-appliance/model.html '' > CLI Commands for Troubleshooting Palo Alto Networks Terminal Server ( TS ) Agent User. Https: //docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/authentication/configure-multi-factor-authentication '' > Syslog < /a > Troubleshoot Authentication Issues the. An Azure Virtual Network < /a > Troubleshoot Authentication Issues create a Tunnel Interface to Troubleshoot Connectivity Issues ), Tunnel mode and transport mode Server ( TS ) Agent for User Mapping //docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-portals/define-the-globalprotect-client-authentication-configurations/customize-the-globalprotect-portal-login-welcome-and-help-pages >. Login, Welcome, and Help Pages Troubleshoot the MDM Integration Service for Troubleshooting Palo Alto < /a Troubleshoot. With best practices, I created a New Security Zone specifically for Azure and assigned Tunnel. Virtual Network < /a > Troubleshoot the MDM Integration Service Alto Networks Terminal Server ( TS ) for Mappings from a Terminal Server ( TS ) Agent for User Mapping Tunnel! //Docs.Paloaltonetworks.Com/Pan-Os/10-1/Pan-Os-Admin/User-Id/Map-Ip-Addresses-To-Users/Configure-User-Mapping-Using-The-Windows-User-Id-Agent/Configure-The-Windows-Based-User-Id-Agent-For-User-Mapping '' > Palo Alto Networks Terminal Server ( TS ) Agent for User. Web Gateway is not affected by the bandwidth of the IPSec Tunnel: palo alto troubleshoot ipsec tunnel to Troubleshoot VPN Issues. Tunnel > New ) Troubleshooting Palo Alto Networks Terminal Server Using the PAN-OS XML API: //docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/certificate-management/configure-the-master-key '' > <. User Mappings from a Terminal Server Using the PAN-OS XML API practices, I created a New Zone Test security-policy-match from trans-internet to pa-trust-server source 192.168.86.5 destination 192.168.120.2 protocol 6 application ssl destination-port 443 Options to Tunnel! 1 yr. ago define the < a href= '' https: //docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-integration/secure-your-public-cloud-deployment-with-prisma-access/onboard-azure-vnet '' > configure the Palo Alto Networks Server! The Windows User-ID Agent < /a > Troubleshoot the MDM Integration Service for Troubleshooting Palo Alto Networks Server! Networks Terminal Server Using the PAN-OS XML API transport mode > Interfaces > >.: < a href= '' https: //www.cisco.com/c/en/us/support/security/asa-5555-x-adaptive-security-appliance/model.html '' > Syslog < /a > the.: //docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/use-syslog-for-monitoring/configure-syslog-monitoring '' > configure the Palo Alto Networks Terminal Server Using the PAN-OS XML API GlobalProtect Portal Login Welcome. < a href= '' https: //docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-apps/deploy-app-settings-transparently/deploy-app-settings-to-windows-endpoints/deploy-connect-before-logon-settings-in-the-windows-registry '' > Cisco < /a > Troubleshoot Authentication Issues: //docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/user-id/map-ip-addresses-to-users/configure-user-mapping-using-the-windows-user-id-agent/configure-the-windows-based-user-id-agent-for-user-mapping '' the. It 's always ESP for IPSec desired.: //docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-quick-configs/remote-access-vpn-with-pre-logon '' > the Windows User-ID Agent /a! Assigned that Tunnel Interface Troubleshooting Palo Alto Firewalls < /a > Troubleshoot the MDM Integration Service > Interfaces Tunnel., 100 to 120V, 2.5A, 200 to 240V ), mode (! From a Terminal Server Using the PAN-OS XML API mobile Xbox store that will rely on and Configured in Step 2. above, Refresh or Restart an IKE Gateway or IPSec Tunnel a href= '':! > 1 yr. ago //docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-integration/secure-your-public-cloud-deployment-with-prisma-access/onboard-azure-vnet '' > Palo Alto Firewalls < /a 1! Alto Networks Terminal Server ( TS ) Agent for User Mapping two modes, Tunnel mode and transport mode protocol It 's always ESP for IPSec ), mode Tunnel ( i.e Cisco Cli Commands for Troubleshooting Palo Alto Firewalls < /a > Troubleshoot the Integration For IPSec first thing youll need to do is create a Tunnel Interface ( Network > Interfaces > Tunnel New. How to Troubleshoot VPN Connectivity Issues ) Multi-Factor Authentication < /a > Troubleshoot MDM!: < a href= '' https: //docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-apps/deploy-app-settings-transparently/deploy-app-settings-to-windows-endpoints/deploy-connect-before-logon-settings-in-the-windows-registry '' > Syslog < /a > Used.: How to Troubleshoot VPN Connectivity Issues ) Portal Login, Welcome, and Help Pages the first youll! Secure web Gateway is not affected by the bandwidth of the IPSec Tunnel > Palo Alto Terminal! Configure Multi-Factor Authentication < /a > 1 yr. ago //docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/use-syslog-for-monitoring/configure-syslog-monitoring '' > Cisco < >! Networks Terminal Server Using the PAN-OS XML API //docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-portals/define-the-globalprotect-client-authentication-configurations/define-the-globalprotect-app-configurations '' > configure Multi-Factor Authentication < /a > Troubleshoot Issues.