General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Anyone using save/load filter optins under Monitor tab?

Out of curiosity is anyone using Save Filter and Load Filter options under Monitor tab and find them user friendly?I have mentioned to Palo representatives few times that filter field should have droppdown history like browser address bars have but they always suggest to go with save/load option that i really dislike 🙂

Resolved! Restricting VPN access to internal services on per-user basis

Folks. I have a normal Global protect portal for internal staff which works fine. I now have been asked to provide access for a support organisation which is not staff - not employed by our company - but which needs access to certain devices inside our network. Does anyone know if there is any way I can restrict what they access via Global Prote...

darren_g by L4 Transporter
  • 10065 Views
  • 7 replies
  • 1 Likes

DHCP Discard session

Scenario is we have ISP connected to Outside zone.DHCP server on Inside Zone.On Each satellite we have DHCP relay configured to readh DHCP server.Whenever there is any issue with Power at location where interface connected to inside zone goes down.Traffic gets routed to Outside zone and inturn gets discarded session as we dont have security poli...

URL Filtering by IP

Hello, We would like to report on web browsing based on the IP off the user's computer, not username (or Identity). Can someone offer a guide, or point me in the right direction? Thank you.

New Pan OS 8.0 Release date

Hi, Palo Alto Engineer said clientless VPN will release with new PAN OS 8.0 in near future. I just wanted to know what is the exact release date for new PAN OS? Thanks,Lakshitha.

Resolved! How do I create my list of blocked IPs for firewall to feed from ?

I need to create my list 'MineMeld-source-List' of blocked IPs which I want to use in the rule. I tried to use prototype stdlib.listIPv4Generic as input where I can add indicators. Then used stdlib.aggregatorIPv4Inbound based aggregator and subsribed firewall to stdlib.feedHCGreen based output (MineMeld-source-List). But on firewall I am getting...

niuk by L3 Networker
  • 15883 Views
  • 9 replies
  • 0 Likes

Sequence number Randomization.

Hi Guys, ASA has a feature where it randomize TCP Sequence numbers to prevent hijack session. Does palo alto has any similar feature. Sorry to compare the products here. My intention is to configure similare setting in firewall. Regards,

yadsingh by L2 Linker
  • 5781 Views
  • 3 replies
  • 0 Likes

Current SSL Certificate best practices?

Greetings all, We're getting close (hopefully) to rolling out our PAN boxes and I'm working on getting together information to pass up the chain on features like SSL Decryption and SSL certificate security. I've got a few questions concerning best practices on certification generation on the PAN boxes and how the certs are used: Are PAN admins l...

jsalmans by L4 Transporter
  • 4511 Views
  • 2 replies
  • 0 Likes

IPSEC VPN support for both side as Dynamic, Supported on Juniper but not on PA

Hi There, I was migrating configuration from Juniper to PA, everything worked as expected except IPSEC VPN. Customer has two sites and both sites have ADSL connection with Dynamic IP address, however on one end Dyn DNS is used. In the below example Site-A has Dyn DNS and www.vpn.com gets updated as soon as IP gets changed on Site-A. But on PA th...

IPSEC VPN.PNG
IPSEC VPN2.PNG
fozail by L3 Networker
  • 13623 Views
  • 17 replies
  • 0 Likes

Resolved! Setting up GlobalProtect with Authentication Sequence

Hello, Trying to configure GlobalProtect to work with local accounts and LDAP accounts with an authentication sequence. The PAN is almost seemingly treating the local account as a LDAP account according to the system logs.The account Idea11Support is the local PAN account we are trying to use but it keeps trying to authenticate it against the TA...

1.png
Farzana by L4 Transporter
  • 5120 Views
  • 1 replies
  • 0 Likes

User to group maping for xml-api user who provided no domain string

Hello,i need to map user to ldap group. For desktops there is no problem, mappings goes well. But if some user connects via smartphone and didn't provide DOMAIN\ then problem occur. Is there any way to achieve this goal ?Typing DOMAIN\ on mobile keyboard is difficoult.Users are authenticated through 802.1x on extrenal NAC and user-id is passed ...

  • 24416 Posts
  • 125 Subscriptions
Top Solution Authors
Labels