General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! Static Route via CLI

I have a firewall with multiple Vsys/VRs. Need to add a static route from one VR to another and I know I can do it via GUI, however I like to use the CLI if possible. So would this command add the static route from one VR pointing to another? set network virtual-router VR-Inside routing-table ip static-route 10.10.10.10/32 nexthop next-vr VR-I...

Captive Web Portal isn't working as expected

We're a school and have just started implimenting BYOD for our Students. Along with this is the requirement to Authenticate the users their BYOD devices so we can monitor and filter their web usage. This is easily done with our PA-3050, or so we thought! Our current setup is that our Student BYOD devices are in their own VLAN (known to the PA vi...

Arcolite by L0 Member
  • 6583 Views
  • 3 replies
  • 0 Likes

Global Protect certificate error

Hi, We are testing GProtect 2.3.2 version and its not working fine.Debug GP client shows "WINHTTP CALLBACK_STATUS_FLAG_CERT_CN_INVALID". The certificate is issued with the Common Name clientvpn.xxx.xxx, and this is the address of the portal. If instead of the DNS name of the portal, we put the IP address, the client warns that the CN of the cert...

block specific user social media, google ads, youtube channel,apps store?

Dear all, my customer have some of this requirments, can palo alto do this stuff:1.can palo alto block specific user in social media like facebook. example: block user name contains john? or block twitter user?2. Block google ads?3. Block specific youtube channel, example: block youtube channel based on parameter Age-restricted content? or block...

What is the difference between Firewall throughput and Threat Prevention throughput?

My company has a 100mbps symetric ISP connection and will be purchasing a PAN firewall, PAN-200 or PAN-500. Is "Firewall throughput" the capacity to sort only on TCP/IP data while "Threat Prevention throughput" is the capacity to sort on the entire packet? If so, and we purchase the subscription for anti-malware protection then it seems that th...

Resolved! Alert on IP Activity

I have a manager that would like to setup an alert wheneever a certain IP address hits our network. Does anybody know of an easy way to do this without creating a security policy and just monitoring that policy?

BPry by Cyber Elite
  • 2436 Views
  • 2 replies
  • 0 Likes

QoS limiting download bandwidth for multiple subnets behind LAN interface.

Hi, I need to limit download bandwidth for multiple (more than 😎 subnets which are behind LAN interface. They need to have different limit values. I can't believe there is only 8 classes and I am limited to them. So is this a hardware limitation? What is the purpose of it? And most important, is there anything to workaround it? Thanks, Rahman

Can Not Registered My PA-200

Hello, I have registered the PA-200 on support web site, and the license is showed correct on the web GUI and on command "request license info", but it still show "device registered: no" on "show wildfire status".Do anyone know why ? And how can I make it to the "yes" so I can use the wildfire function? Please help me ! Thanks.

WS000003.JPG
mjkssg by L1 Bithead
  • 7158 Views
  • 9 replies
  • 1 Likes

Resolved! MineMeld outbound calls impacted by SSL interception

I could see the node was having problems pulling the external resource due it being decrypted and our CA being used. I added our CA to the Ubuntu store with the processes used here, but still no juice. http://askubuntu.com/questions/645818/how-to-install-certificates-for-command-line Thoughts?

Change to HTTP decoder

Did I miss a notice that the http decoder was being changed so that most of my rules based on the web-browsing app would break? Nearly all of my web-browsing traffic is suddenly being identified as unknown-tcp. I notice in the release notes for 646 app update that the http decoder was modified.

epeeler by L2 Linker
  • 2302 Views
  • 1 replies
  • 0 Likes

Palo Alto deny All policy reason non-syn-tcp

Hi, We realised our PA in version 7.0.6 is having any issue with the traffic. We see many traffic being dropped by DENY all rule (the last rule in the rule set). Looking in application we see "non-syn-tcp" in all the connections. These denies connections always ocurrs each 30 minutes. For example: 4.01pm, 4.31pm, 5.01pm, 5.31pm. we have disab...

logs.JPG

Resolved! Multiple VLANs through Network Interface

Hopefully this is a very simple question, but I wanted to make sure I was actually researching the correct thing. I am planning on connecting a hypervisor (Hyper-V 2012), directly to one of my Network Interfaces on my PA. The hypervisor has multiple VLANs, and I need them all to go through the PA. I incorrectly thought if I just set the VLAN/...

  • 24432 Posts
  • 125 Subscriptions
Top Solution Authors
Labels