General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Group Mapping

I have created my LDAP server profile and my group mapping under user identification. However when I try and force the group update I get an error.

 

Server error : op command for client useridd timed out as client is not available

 

Any ideas?

JeffTQT by L2 Linker
  • 2414 Views
  • 1 replies
  • 0 Likes

Resolved! URL FILTERING

 

 

dear engineers.
could you help me!!

I have the following problem with the URL filter:

I commented that I have blocked the streaming media category in which enters youtube

when I open firefox without any problem with the rule applies both http and htt

...

chromeyou.JPG
firefoxyou.JPG
Edluna by L1 Bithead
  • 3676 Views
  • 5 replies
  • 0 Likes

Resolved! Support for static local IP and Domain Lists

I'd like to start by saying, that this is an amazing tool! Thanks for sharing this, it has great potential and my customer is excited. One question: is there currently any support for creating and maintaining local IP and domain blocklists on the Min

...

nbilal by L3 Networker
  • 5283 Views
  • 4 replies
  • 0 Likes

Google Drive Sync client with Decryption

There seemed to be a work around in the past where you could launch googledrivesync.exe with a --unsafe_network switch that would allow it to deal with the decryption because they seem to have their own preloaded set of CA's the client trusts and doe

...

bbilut by L3 Networker
  • 2581 Views
  • 1 replies
  • 1 Likes

Web GUI Font Readability Issues After Upgrading to 7.1

Since upgrading to 7.1 I've noticed that the new font used in the Web GUI is very hard to read.  In many places it appears squished and just looks wrong.

 

In the list of what's new in 7.1 this is actually touted as a "font update" but it sure seems li

...

Fonts.jpg
SamKear by L1 Bithead
  • 1922 Views
  • 1 replies
  • 0 Likes

PA-500 Throughput

The PA-500 datasheet indicates that the maximum throughput for traffic being filtered by App-ID is 250Mbps

 

 

https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/datasheets/pa-500/pa-500-ds.pdf

 

What it doesn't say, is what if I just have

...

RustyPA by L1 Bithead
  • 2389 Views
  • 3 replies
  • 0 Likes

Decryption causing more sites to fail

Just floating this out to the community. We have had decryption enabled for the past 2 years. In the last 6 months we are adding a new site to the no decrypt category about once a week. We are up to 94 sites that it can't decrypt. Yesterday it was Of

...

craymond by L4 Transporter
  • 4262 Views
  • 6 replies
  • 0 Likes

ACC Behaviour

Hello everyone!

 

I've got a question about the behaviour of the new ACC in 7.0 and above.

 

I can apply a global filter for the action of deny.

 

When I do this, the graphs show no data, even if I click refresh.

 

If I click 'jump to logs' with the

...

bmorris1 by L4 Transporter
  • 1942 Views
  • 4 replies
  • 0 Likes

show counter global filter category flow aspect dos

 

Hi,

 

 

Below is  output of  'show counter global filter category flow aspect dos' 

 

What does it mean by value and rate . Does it mean '143291' packets dropped ?     

 

namevaluerateseveritycategoryaspect      flow_dos_red_tcp11432910dropflowdosf...

sib2017 by L4 Transporter
  • 4578 Views
  • 11 replies
  • 0 Likes

PA blocks outbound port 10443, doesn't show up in logs

I have and external website that I need to access on port 10443: https://<public IP>:10443. The connection never completes and times out. 

 

If I pull the PA FW out and throw in an ASA, works just fine. The logs on PA don't even show port 10443 being

...

dclark1 by L1 Bithead
  • 3370 Views
  • 8 replies
  • 0 Likes

SMTP weird characters

Hi everyone!

My client's SMTP traffic goes through ASA and Palo Alto and some other network application devices such as proxies and stuff.

At some point, the SMTP message gets some SMTP characters added.

 

I removed ASA ESMTP inspection just in case, and

...

incomplete and ddos drops

Hi

The following report shows incomplete

Database: Traffic Log
Columns: Source Zone, Source Address, Source Port, Destination Zone, Destination Address, Destination Port,
Application, Bytes
Query Builder: (app eq incomplete) and (port.dst leq 1023)

but

...

sib2017 by L4 Transporter
  • 1645 Views
  • 1 replies
  • 0 Likes

Importing device into Panorama with shared objects

Hello

 

I would like to import device into Panorama with all objects as shared into Panorama. I read the below line from PA documentation 

Import devices' shared objects into Panorama's shared context is enabled by default, which means Panorama imports ...

  • 23662 Posts
  • 104 Subscriptions
Top Solution Authors
Top Liked Authors
Labels