General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.


Resolved! Applications On Non-Standard Ports

It's perfectly possible I'm being unusually dumb here, but I can't see an elegant way of allowing application usage on non-standard ports - for example ssh on tcp/32777. The obvious way of doing it is to allow a rule that allows appid:ssh on service:


visualize custom regions on traffic/threat map

Is it possilbe to show custom regions with gps coordinations on the threat/traffic map with the correct gps coordinates?


We have set custom regions for departments with private subnets and gps coordinations.

In the traffic or threat map we can only se



NAT question when migrating config.

Converting config from Nortel Connectivty switch to PA200.

3 interfaces

untrust - public ip -

trust:private ip -



There is one to one mapping of few untrust ip to trust ips( to access trust ips from ou


Moving a VSYS from one PA device to another


Question here , how can we move a VSYS from one device to another ? please note that in this scenario we cannot backup everything a restore on target since target is running other things that need to be running .

Any ideas ? what are important th


Resolved! Get information on Security Profiles our of PANOS?

Hi all,


My team is currently undergoing an audit and one of the requests is for the configuration of the security profiles, including URL filtering, from our firewalls.  As we are fairly new to PANOS this has not been requested before.  I don't see


RSKadish by L2 Linker
  • 4 replies

Resolved! Security flaw with GlobalProtect?


While setting up a computer with fingerprint authentication+windows password, I discovered that after installing GlobalProtect I could circumvent the whole two-factor authentication by choosing to login with GlobalProtect(clicking the GP icon in t


SSL decryption issues with latest Firefox

I'm having SSL decryption issues with the latest versions of Firefox.

In Firefox i get following error when visiting a https site:

Secure Connection Failed

An error occurred during a connection to security library: improperly


dieter_b by L4 Transporter
  • 17 replies

qos report



How can i generate a throuput report on my untrust interface .
And how can i genearate qos report like class 1 and class 2 usage for a period of time )

Thank you 

sib2017 by L4 Transporter
  • 4 replies

Minemeld AWS user data error

hi all,

I spun up a linux server in AES and followed the instruction to import user data from here

according to the instruction, the user data was encoded in base 64, but it


bartoq by L3 Networker
  • 7 replies

TS agent on XenApp 7.7?



As i can see the newest TS agent(7.0.2) is only supporting XenApp 5.0/6.0/6.5. 


I have a customer that wants to get UserIDs from Citrix and then use AD groups to limit access to resources. BUT the customer is running on XenApp 7.7. Anyone who


Global Protect Slowness

We recently installed a PA-3020 on a 1G circuit and are experiencing very low speeds when clients are conecting in using GlobalProtect. When connecting in from home on a 20M connection we are seeing speed drops down to a max of 5M (mostly lower). We 


drischar by L1 Bithead
  • 10 replies

Problems with XFF cleaning

Dear all,

we are getting more and more problems with the way PA handles the X-forwarded-for header.

It is very useful in getting the internal client IP in a proxy environment. OTOH, you need to clean it before it goes out so that you don't leak interna


AndreasB by L2 Linker
  • 14 replies

GlobalProtect: Pre-Login and user cert based auth?

Hi All,


I've successfully configured pre-login and can enter my creds in to the GP client the first time I log in and it works great. Is there a way to use a user certificate for the user auth and avoid any action on the users part for auth?




  • 23591 Posts
  • 103 Subscriptions
Top Solution Authors
Top Liked Authors