General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Wildfire Alert reporting source and destination NATs that aren't configured on associated firewalls

Greetings, We've had several Wildfire Alerts that show both the source and destination addresses translated yet NAT is not configured. For the subject data flow, the source is an external network for which we have no control. The destination is our client. The Alert shows that that the Source address is being translated to another address tha...

Resolved! Panorama M-100 - Led Red Alert

Hi, I have a Panorama M100, the device lost connection, neither couldn't be access by console, so we don't make any changes. Then we reboot and connect keyboard direct to appliance and we choose option F1, whit that, the device Started working and recover the access, but now the device show up a led red alert. that it means -- System Health Indi...

ERROR INICIAL AL CARGAR PANORAMA M-100.png
sdsadasdsa.jpg

Where to put Office 365 dependencies?

I created a security policy for Office 365 using the application IDs. When I commmited, it said that SSL required, but I already have SSL/web-browsing in another policy below. During testing, I found that the 365 policy was not catching any 365 traffic... my SSL policy was catching it instead, and logging it all as "ssl" instead of Office. So I ...

Maxstr by L3 Networker
  • 2188 Views
  • 1 replies
  • 0 Likes

No SSL decrypt collaboration

When we try to setup an Skype for Business call we always get blocked by the SSL decrypt of the Palo Alto system.I would like to configure no ssl decrypt for collaboration. Is this possible and how?

ZEBIT by L3 Networker
  • 3353 Views
  • 5 replies
  • 0 Likes

Resolved! Know UserID version agents from Palo Alto

How can i know the version installed in UserID agents server from Palo Alto???? i tried show user user-id-agent statistics but Version shows the protocol version, not the real version client UserID https://live.paloaltonetworks.com/t5/Learning-Articles/What-Does-the-Version-for-quot-Show-User-User-ID-Agent/ta-p/53699

Template and Devcie Group Design

Hello Experts I have two firewalls cluster, managed by panorama. One cluster is for perimeter firewall and other is core/DC firewalls. I have three customers and I created three vsys (CUST1, CUST2 and CUST3) on both clusters. Now what is the recommendations for creating how many templates and device groups on panorama. Should I create three devi...

Resolved! HA sync-passwords both devices

Hello I have itha pair, both password changed. the primary device's ticket closed automatically, but the secondary's was still open. password match thoughbut... request high-availability sync-to-remote running-config <<-- would that be valid to sync the configs to include passwords? Best regardsAndres

Apadilla by L3 Networker
  • 4585 Views
  • 2 replies
  • 0 Likes

Resolved! PBF for Office 365

Hi all, One of our startegic customer is requesting the possibility to route just the O365 traffic to a specific link and after researching about this I think that the best is using MineMeld to automatically feed a list of application IP adrress but I did't find any documentation describing how to perform this. Any of you have used the MineM...

rrunge1 by L1 Bithead
  • 22218 Views
  • 15 replies
  • 0 Likes

VPN DNS not resolving

I have users on 3 different local AD domains. We are consolidating, but in the mean time, users have been able to connect to the GlobalProtect VPN and browser network resources. A few weeks ago one user emailed me and said he is connected to VPN, but cannot connect to a terminal server. I check into it and realize that he can ping the IP of the ...

Telnet session time out when idle time 1 minute

Hello Everyone ! I am Aung Naing, Nice to meet you all !! In our network we use POS device connect to POS server with telnet program. But when we start the telnet program from POS client device, the time is have to wait about 1minute and if nothing movment in POS client pc about 1minute the telnet connection is di...

Resolved! show log command filtering by interface

I need to filter a log by interface.I have an interface down and I want to know how long was down. It´s palo alto 5020. with pan os 7.what log should I check? and how can i filter by interface 1/16?

Resolved! Agentless User ID - Server Log Monitor Frequency

After configuring Agentless User ID, the default value for Server Log Monitor Frequency of 2 seconds caused CPU usage on the Domain Controller to be higher than desired. Changing this value to 10 seconds brought CPU usage on the Domain Controller to an acceptable level. What are the ramifications of having this longer Server Log Monitor Freque...

herrmoss by L2 Linker
  • 5838 Views
  • 3 replies
  • 0 Likes
  • 24432 Posts
  • 125 Subscriptions
Top Solution Authors
Labels