General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Public wifi clients unable to access our public web servers

Our public wifi traffic is unable to reach our external web servers that have public IPs (like webmail). The public wifi network is in the same zone, but it is assigned 172.30.0.0 IP, and we have ACLs to prevent the 172.30.0.0 network from talking to 192.168.0.0. It is also being outbound NAT so it gets assigned a different public IP address th...

Maxstr by L3 Networker
  • 2460 Views
  • 3 replies
  • 0 Likes

Resolved! how to make ssh work on different port number

Hi, my colleague requested for some server to communicate to outside server (internet) using sftp. but they want to use port 9122.on the firewall rule i cannot find the way how to do it. i know sftp i using ssh port 22. i tried defining port 9122 and ssh as application but it doesnt work. anybody have any idea? tia chris

Clearing files to create space.

My PA200 is complaining about 10% space. pa200> show system files/var/cores/:total 4.9M-rw-rw-rw- 1 root root 652K Apr 24 20:21 core.20803-rw-rw-rw- 1 root root 652K May 17 13:44 core.17902drwxrwxrwx 2 root root 4.0K Jun 1 03:16 crashinfo-rw-r--r-- 1 root root 3.2M Jun 1 03:30 l3svc_7.0.6_0.tar.gz-rw-rw-rw- 1 root root 652K Aug 13 07:51 core....

Migration tool refuses HTPPS connection

Hello! I downloaded MT 3.1 for vmware player, imported it and turn it on. MT has ip adres 192.168.208.129 and I can ping it, but when I try to access it using HTTPS, it refuses connection. Does anybody had similar problem and how it can be solved? Best regards,Maja

mkopcic by L2 Linker
  • 2568 Views
  • 2 replies
  • 0 Likes

Resolved! User-ID and internet access

Hello, If a user uses the PC at home (not behind the Palos) to access the Internet then hibernates their PC, then comes to work and connects to the network (behind the Palos) and un-hibernates, they can no longer access the Internet until the PC re-authenticates to AD and when the user-ID agent can identify the user again. There is a period when...

Farzana by L4 Transporter
  • 3055 Views
  • 2 replies
  • 0 Likes

Resolved! New to Palo Alto device

I am a new technology coordinator in a school that has a Palo Alto device. I am new to these devices. The support contract (right term?) was up in 2014, and I would like to figure out how to get firmware (Pan-OS?) updates on the device. It is a PA-200. Can anyone point me in the right direction? I have searched Google and found lots of dead ends...

LSVPN Troubleshooting

I have all the guides for configuring LSVPN at the gateway, portal and satelite. I have done that and now verifying the LSVPN connection. This is the first LSVPN satelite to try and connect. Is there a good troubleshooting guide with steps for determing why the satelite is not connecting. As all are aware the issue could be either the gateway, p...

Check Dynamic Update Version On All Palo's From Panorama

Panorama has been great so far, but can I not check all my devices Dynamic Update Version from within Panorama? For instance there was the 613 update yesterday and some of our devices did not get the scheduled update due to the timezone they were in. So I have to log in to each Palo and check the Threat and Content version individually. We only...

Resolved! Recycling old Palo gear

Does anyone know of a recycling program for Palo Alto networks, we have an old 5050 in the office we want to get rid of (no support or licenses) and would rather not throw it in the trash

nrobison by L1 Bithead
  • 4535 Views
  • 1 replies
  • 0 Likes

OS 7.1 blocking telnet over SSL

We have in-house software that uses secure-telnet port 992 and that has been blocked after the 7.1.4-h2 upgrade. I've created a rule to pass the traffic to the destenation address with any application any service but never help, the logs said reset both by internzone rule, only changing interzone rule to allow will let the application communicat...

Top 5 user behavior report

In the predefined report it has a section called Top 5 user behavior report. What exactly is this telling me about the user/pcs/devices that are listed?

jdprovine by L4 Transporter
  • 2548 Views
  • 3 replies
  • 0 Likes

globalprotec vpn for phones

Is anyone using the globalprotect vpn client for their phones and mobile devices? How do you like it? Can it use the same portal and gateway and the pc's? Was was the cost and how much was it

jdprovine by L4 Transporter
  • 3108 Views
  • 4 replies
  • 0 Likes

Lync Client and GlobalProtect Split tunneling issue

Hi, Mircosoft recommands to enable splitunnling for lync. https://blogs.technet.microsoft.com/nexthop/2011/11/14/enabling-lync-media-to-bypass-a-vpn-tunnel/ To still continue to have the internet over the VPN, how can Globalprotect client only allow specific public ip address to bypass the tunnel? Thank you Kind regards, Pierrick

  • 24413 Posts
  • 125 Subscriptions
Top Solution Authors
Labels