General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4117 Views
  • 0 replies
  • 0 Likes

IPSEC VPN support for both side as Dynamic, Supported on Juniper but not on PA

Hi There, I was migrating configuration from Juniper to PA, everything worked as expected except IPSEC VPN. Customer has two sites and both sites have ADSL connection with Dynamic IP address, however on one end Dyn DNS is used. In the below example Site-A has Dyn DNS and www.vpn.com gets updated as soon as IP gets changed on Site-A. But on PA th...

IPSEC VPN.PNG
IPSEC VPN2.PNG
fozail by L3 Networker
  • 12755 Views
  • 17 replies
  • 0 Likes

Resolved! Setting up GlobalProtect with Authentication Sequence

Hello, Trying to configure GlobalProtect to work with local accounts and LDAP accounts with an authentication sequence. The PAN is almost seemingly treating the local account as a LDAP account according to the system logs.The account Idea11Support is the local PAN account we are trying to use but it keeps trying to authenticate it against the TA...

1.png
Farzana by L4 Transporter
  • 5002 Views
  • 1 replies
  • 0 Likes

User to group maping for xml-api user who provided no domain string

Hello,i need to map user to ldap group. For desktops there is no problem, mappings goes well. But if some user connects via smartphone and didn't provide DOMAIN\ then problem occur. Is there any way to achieve this goal ?Typing DOMAIN\ on mobile keyboard is difficoult.Users are authenticated through 802.1x on extrenal NAC and user-id is passed ...

Data pattern to check 2 conditions on Credit Cards

Hi, Let's say I want to create a Data Pattern to check 2 conditions on DLP: 1) Check Luhn number. This can easily be done by setting a weight in the "CC" field on a DLP Data Pattern.2) Once the Luhn number checked, check if the first 7 numbers of the credit card matches some BIN codes of an specific Bank. is that possible? I mean, the "2 condit...

MarcelST by L3 Networker
  • 3066 Views
  • 2 replies
  • 0 Likes

Resolved! Bandwidth limit AD group

We have a need to limit download and upload to 50 Mb/50 Mb for a specific AD group in our company. I have followed the steps in this article https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/quality-of-service/use-case-qos-for-a-single-user#36469 When I apply the qos profile to interfaces it then applies to 50 Mb limit to everyone ...

Resolved! More than one Radius Connection Profile for GlobalProtect on PAN-OS 7.1.0 and Windows 2012 R2 NPS

We are hosting 4 clients with each having their own server. I have setup 4 separate GlobalProtect Gateways and Portals for each client with access only to their server. I have configured Radius and tested it. I want to be able have one different Active Directory group for each client and have the users that are in the respective groups only ha...

Resolved! ACC report on Sunday

Hi Guys, ACC issue. Don't know what could be the reason for the URL block report to show some activities when nobody was using a network on Sunday. NTP? And also question to why all users got 2 digits in the end of their username, Is it normal? Thx,Myky

Latimer issue.PNG

Any known issues with PAN OS 5.0 for user-ID and IP mapping not working?

I have a lab setup with two palo alto firewalls (PA-200). I am running it with the code it came with the device (PAN OS 5.0.6).I configured User-ID as per the guidelines on this link (https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Agentless-User-ID/ta-p/62122). However, i was unable to get it work. So i followed thi...

BlackNurse Testing Causes issues on Egress Firewall

FYI It doesn't appear to require an attack to be an IP address bound to the PA. It also appears that testing a remote firewall while egressing through a PA firewall causes your local firewall to experience DOS effects. It is not just inbound to an IP address of a PA's interface or NAT to that interface. I did an hping3 of type 3 to a remote PA-3...

bspilde by L4 Transporter
  • 3480 Views
  • 3 replies
  • 0 Likes

Resolved! TLS secured SMTP inbound inspection?

Hi,I've recently had a client who's PAN appliance failed to pick up a Zero-Day piece of malware that found it's way into their network via email.We have wildfire configured correctly and it transpires they are using opportunistic TLS on their mail relay, the spammer had send the infected attachement using TLS so the Palo Alto had no hope of actu...

Dpeters1 by L2 Linker
  • 18117 Views
  • 11 replies
  • 0 Likes

Resolved! show routing resource

When using show routing resource command. Why is there a overlimit value when we are under the 2500 limit count LOBAL ROUTING RESOURCE USAGE:==========All Routes (total): 1088 (limit 2500)All IPv4 Routes (total): 1088 (limit 2500) (overlimit counts 393372562)All IPv6 Routes (total):

  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels