General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Switch from Static to Dynamic Address Object Groups

Hello all, we are running into an issue where we are unable to change static address object groups to dynamic address object groupsWe have an M500 and several PA7050 and the objects are managed under the "shared" device group for all the PA7050's. We have added tags etc. to the address objects and on the panorama they show up with their dynamic...

GlobalProtect VPN usage reports?

I'd like to generate a scheduled report of all the GlobalProtect VPN users connected in the last 24 hours. Is this possible to create in Pan OS 7.1?

Maxstr by L3 Networker
  • 5104 Views
  • 4 replies
  • 0 Likes

Resolved! Office 365 - Polling issue

Hello, I have noticed an IP address which is published by Microsoft and not “mined” by minemeld: 40.112.64.16/28 in Office Identity. I don’t this this IP range in published IPv4 feed (I have imported default configuration published in Live). How do we collect the informations? How can we follow which information has been mined and sent to th...

Windows Updates across a Site to Site VPN

I have a WSUS server. I have a Site to Site VPN from a PA-3020 at a hosting facility to a Cisco ASA on my corporate network. The PA-3020 is running 7.1.4. When I try to run updates from the servers in the hosting facility, it shows as ms-update in the Traffic Log. The Session End Reason is “tcp-rst-from-server”. I am allowing all traffic on...

Resolved! Static Route via CLI

I have a firewall with multiple Vsys/VRs. Need to add a static route from one VR to another and I know I can do it via GUI, however I like to use the CLI if possible. So would this command add the static route from one VR pointing to another? set network virtual-router VR-Inside routing-table ip static-route 10.10.10.10/32 nexthop next-vr VR-I...

Captive Web Portal isn't working as expected

We're a school and have just started implimenting BYOD for our Students. Along with this is the requirement to Authenticate the users their BYOD devices so we can monitor and filter their web usage. This is easily done with our PA-3050, or so we thought! Our current setup is that our Student BYOD devices are in their own VLAN (known to the PA vi...

Arcolite by L0 Member
  • 6272 Views
  • 3 replies
  • 0 Likes

Global Protect certificate error

Hi, We are testing GProtect 2.3.2 version and its not working fine.Debug GP client shows "WINHTTP CALLBACK_STATUS_FLAG_CERT_CN_INVALID". The certificate is issued with the Common Name clientvpn.xxx.xxx, and this is the address of the portal. If instead of the DNS name of the portal, we put the IP address, the client warns that the CN of the cert...

block specific user social media, google ads, youtube channel,apps store?

Dear all, my customer have some of this requirments, can palo alto do this stuff:1.can palo alto block specific user in social media like facebook. example: block user name contains john? or block twitter user?2. Block google ads?3. Block specific youtube channel, example: block youtube channel based on parameter Age-restricted content? or block...

What is the difference between Firewall throughput and Threat Prevention throughput?

My company has a 100mbps symetric ISP connection and will be purchasing a PAN firewall, PAN-200 or PAN-500. Is "Firewall throughput" the capacity to sort only on TCP/IP data while "Threat Prevention throughput" is the capacity to sort on the entire packet? If so, and we purchase the subscription for anti-malware protection then it seems that th...

Resolved! Alert on IP Activity

I have a manager that would like to setup an alert wheneever a certain IP address hits our network. Does anybody know of an easy way to do this without creating a security policy and just monitoring that policy?

BPry by Cyber Elite
  • 2379 Views
  • 2 replies
  • 0 Likes
  • 24381 Posts
  • 123 Subscriptions
Top Solution Authors
Top Liked Authors
Labels