General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Parent Application Subtypes automatically allowed?

Hi All,

 

In a security policy, if I allow Application "ipsec" with service as "application-default" then will the firewall also allow

- ipsec-esp

- ipsec-esp-udp

- ipsec-ah

- ike ?

 

If you see applipedia, and if you search "ipsec" then you see the above me

...

Globalprotect never connects after a restart

I have moved to another location and here I am connected via  a cable to a modem running O2 internet. Sadly, my VPN never seem to be able to reconnect and after each restart I battle with it greatly.

I have to reinstall certificates, sometimes I try r

...

Globalprotect never connects after a restart

I have moved to another location and here I am connected via  a cable to a modem running O2 internet. Sadly, my VPN never seem to be able to reconnect and after each restart I battle with it greatly.

I have to reinstall certificates, sometimes I try r

...

Issue after Internet Upgrade

We recently installed a new 300/300 circuit and MIS router at my workplace.  No IPs have been changed, but since the upgrade we cannot ping internet addresses, and our latency and speed results from speedtest.net are horrific (like 1000+ and less tha

...

Lmg412 by L0 Member
  • 2116 Views
  • 3 replies
  • 0 Likes

Service settings in a NAT

I ran across this setting this morning- when setting up a NAT rule, you can specify a service or service group. Cool, but is there a reason to do that when a policy is necessary to open a service port?

cloughr by L2 Linker
  • 2766 Views
  • 3 replies
  • 0 Likes

Error Checking credentials - Gateway Timed out

Hi There,

  I have installed Minemeld on my Ubuntu Server 14.04.. And the service is up and running.. Wheneve I use the default Username and Password to logon to the console, it gives me an error "Error Checking credentials - gateway timed out".. I ha

...

maltwist by L2 Linker
  • 18760 Views
  • 15 replies
  • 0 Likes

Resolved! Cannot find pan_packet_diag.log on PA VM

Hello,

 

I am new to this forum so please bear with me. I would like to use debug log feature on my PA VM. I am able to turn the logging on with the following commands:

debug dataplane packet-diag set log

debug dataplane packet-diag set log feature flow

...

HAL9000 by L1 Bithead
  • 4177 Views
  • 4 replies
  • 0 Likes

Discussion on most stable PAN-OS image as of July 2016

I am going through some cleanup of our PAN firewalls. We have 8 sites with active/standby pairs of PAN's. The sites are connected with IPSEC VPN's. The code varies from 6.0.3 to 7.0.4 versions.

 

What's your feeling on the most stable 7.X code as of no

...

rpugh1 by L0 Member
  • 3735 Views
  • 7 replies
  • 0 Likes

VPN question

Hey there,

 

I was curious if anyone successfully used another VPN client on their IOS or Andriod device that works.  I was told that with X-Auth/IP-Sec the Cisco Anyconnect client worked but it appears that the new 4.0 client does not (am I wrong?).  

...

mjillson by L0 Member
  • 1513 Views
  • 1 replies
  • 0 Likes

Resolved! Blocking .docm files

Hi,

 

we see a lot of files with extension docm attacking the mailserver via smtp and identified as malicious by wildfire. is there a way to simply block those files via File Blocking profile like we are doing for pe and other file types. The point is

...

Skype Enterprise

Hi,

I need to create a rule to make run Skype enterprise. I don't find an app for skype enterprise so i tried to create a rule with only skype and ms-lync-online but it's deny with the destination port 5061...I don't understand.

 

does someone has an id

...

ALC_Palo by L0 Member
  • 2073 Views
  • 1 replies
  • 0 Likes

TRAPS and Reverse Proxy

Hello Folks,

 

I have recently installed a ESM core and console server. I have added a URL re-write rule to allow my traffic to be proxied through this server. The issus is that the web based traffic is rewriting no problem. Its the communication on po

...

  • 24297 Posts
  • 99 Subscriptions
Top Solution Authors
Top Liked Authors
Labels