General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4118 Views
  • 0 replies
  • 0 Likes

Captive portal Redirect not working for some android devices.

Hi, I have captive portal setup in guest zone .The setup is working fine for some mobile devices (android) and laptops where the users are presented with captive portal login page once they try to browse inernet. Some mobile android devices are facing the problem that captive portal is not presented when they try to browse.They can not use inter...

Clientless VPN - pass creds to applications

Hello, one of our customers want to use PA as SSO for their applications.Have you any idea if it is possible ?We can use Kerberos or LDAP for clients authentication to PA but what about pass it to the application ?

Palo Alto Networks Firewall detected a url that i havent visited

Myself sai, working as cyber threat analyst. When I am working on one issue, I have checked the risk report of the url - www.weddingsonthefrenchriviera.com in Virustotal, IBM X-force website, URL Query. However in palo alto web interface it is showing that i have accessed the url. I havent accessed the url, i have just checked its risk report. P...

Global Protect - Minimize Panel

I'm working on a pre-logon configuration for GP. After it connects, the panel maximizes. Is there a way to keep the panel from maximizing without removing the app from the system tray? I don't want users having to close the window after it connects.This is GP 3.1.6.

Global Protect Commit Warning

Hi, I'm getting a slightly perplexing commit warning from Global Protect. I am using almost entirely defeault settings for the Portal Agent, so I'm not entirely sure what this warning is pertaining. My only guess is its referring to the setting I have pictured below? But i dont see how it can be flagged for "misses information" when a setting is...

Screen Shot 2017-03-15 at 1.03.48 pm.png

Resolved! ACC Network Activity logging

I'm wondering if the data that shows up in ACC is dependent upon session end (since that's when we're logging) to be reflected in the ACC data graphs. For example: If I have a host doing a large data transfer, will that information not show up in ACC until the session is finished or is the firewall tracking other things besides traffic monitor l...

epeeler by L2 Linker
  • 3354 Views
  • 2 replies
  • 0 Likes

PA 7.0, GP and RSA-ID double authentication

Hi, There is a deployment with RSA-ID as OTP and GP as VPN client (3.1 or 3.0). PAN-OS version 7.0.14.After the recent upgrade from 6.x to 7.x an issue showed up - when authenticating from GP - login information is asked twice.This seems like a known issue:https://community.rsa.com/docs/DOC-46969I've adjusted the PA settings according to this: h...

nikoo by L3 Networker
  • 3875 Views
  • 3 replies
  • 0 Likes

Best way to prevent brute force attacks (LDAP) on public facing Microsoft RDWeb login page

We are using Server 2012r2 RDS gateway and have the PA configured to with a security policy to allow the untrusted traffic (ssl, rds, http) that is NATed to the internal rds gateway. We are seeing a lot of failed audits in the logs on the terminal server. What is the best way to prevent brute force attacks for logins to Active Directory?

Resolved! SSL decryption & not working VPN

Hi guys, We wittnessed a very strange phenomenon this morning.First we received a call that our VPN gateway was not accepting any VPN connections.At the same time we received calls that certain websites were not accessible. These websites had in common that they were SSL encrypted. We have 2 PA-500 firewalls with a HA configuration.SSL decryptio...

How to ignore routes learned by OSPF

I would like to ignore some of the routes learned by OSFP so they don't install in the forwarding table. Important, I'm not talking about suppress/filter routes that my PA announce through OSPF. For explaining me better, I'm looking for "OSPF Inbound Filtering" in the language of Cisco:http://www.cisco.com/c/en/us/td/docs/ios/12_0s/feature/guide...

COM-UCO by L1 Bithead
  • 10059 Views
  • 7 replies
  • 0 Likes
  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels