General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4116 Views
  • 0 replies
  • 0 Likes

postscript-pdl application classification - buggy

We are setting up a new printing zone on the PA and have created a rule that allow the following applications , postscript-pdl, hp-jetdirect, lpd, snmp. It allows one page to print to the printer and then it stops. After much testing we added a second rule below the first fule bu the applications are set to any. It allows everything to print no...

jdprovine by L4 Transporter
  • 3432 Views
  • 4 replies
  • 0 Likes

Allow streaming-media for training sites that use youtube links

One of out departments recently purchased access to an online training site that uses youtube to play some of the videos within the courses. We block all streaming-media on our network as a general rule on our PA 3020. I would like to allow access to the vidoes within the training courses without oppening up the rest of youtube to these users. I...

drischar by L0 Member
  • 2703 Views
  • 2 replies
  • 0 Likes

Source users no longer showing up in Monitor and ACC

A few weeks ago I noticed that in our firewall suddenly all the Source User fields are showing blank. This is very strange since it happened without any changes being made to the firewall or the Domain Controller. We populate user IDs using LDAP. All the settings are correct and the LDAP servers (our primary and backup domain controllers) are bo...

TDag11 by L0 Member
  • 4565 Views
  • 3 replies
  • 0 Likes

vwire using a single physical interface possible?

Right now we use a standard vwire with 2 physical interfaces. We're about to make some hardware changes that means that the vwire input and output will be from/to the same physical switch. If I have to use 2 interfaces then on that switch I'll just be using two untagged ports from/to the appropriate VLANs on the switch. But do I have to use 2 ph...

GP user access using internal DNS

Hi all,when GP user need to access internal resource, i want them to use vpn assigned internal dns server, but currently userstill go to ask local dns on their PC. and if user access via ip, it is OK. How to break it out ?

Yue.Ma by L1 Bithead
  • 2268 Views
  • 2 replies
  • 0 Likes

HA issues

I have 5060 pair (pan1 and pan2) with 7.1.2 in HA. Whenever pan2 interfaces are up, not shutdown, sooner or later we experience issues. It doesn’t matter if pan2 is active or passive. Could it be h/w ? Config is in sync

niuk by L3 Networker
  • 3447 Views
  • 5 replies
  • 0 Likes

Site to Site VPN between PA200 and any third party device.

Hi all Please help me to sort out the situation below. We have one PA 200 is working fine in the main office. The main office have the static WAN IP and it is acting as the SSL VPN gateway. Now, we need to connect a small brach office to main office through site to site VPN. The banch office doesn not have the static WAN IP. what are the chea...

Resolved! GlobalProtect timeout only for one user

Hi, We have a customer pc using GProtect to our office, we use this VPN to access using RDP to his computer. The problem is that GProtect timeout is 24hours, so we need customer help in order to log again in GProtect VPN. If there any way to delete this 24hours time out only for this VPN connection? without changin for all the vpns customers?? T...

Resolved! Can the PAN device block HTTP Dos Attacks?

Hello Guys,I'm going to do some service availability test in the near future. We can't get any information of the attack pattern. The only information we know is that the tester will conduct these attack.HTTP CC(cache-control) attackSlowloris attackHttp post attackHttp Hash dos attackI'm afraid that those attack patterns seem to be normal for th...

JTR by Not applicable
  • 17459 Views
  • 14 replies
  • 1 Likes

Resolved! user for web-gui

Hello, at first, thank you for that great tool, especially for the gui. I will change the password for admin. How can I do this? With htpasswd? And, is it possible to add users with different privilegs? Thank you for your efforts.

Help on CSV Output Feed

I'm looking to output feeds to a format that I can ingest in some log analysis tools, and need to output fields that I have defined in miners. Is there any information on how to access that data and output it?

kx1499 by L0 Member
  • 4154 Views
  • 3 replies
  • 0 Likes

SSL certificate cache

Hi,there are various settings in the decryption profile and also under Device -> Sessions -> Decryption Certificate Revocation Settings to controll how the firewall should deal with expired or self-signed certificates etc. I am currently testing these things in a Lab and I am having difficulties to see any differences in the firewall's beh...

Resolved! Multiple Zones with one VLAN

I am trying to segregate my client computers and I don't have the ability to work with VLANs. All of our clients are in a single VLAN and I want to set them up in different subnets and zones. All of the clients connect to the Palo Alto through a single interface (also can't be changed). I tried to do this with untagged sub-interfaces but I don't...

rdlenk by L1 Bithead
  • 5771 Views
  • 1 replies
  • 0 Likes

staticupdates URL and missing software version

Hello, On a Panorama 7.0.2, using the update from "staticupdates.paloaltonetworks.com". Some versions are strangely not showing .For PA200 image, we can't see the updates for 7.0.1 and 7.0.2.I can't test with the URL updates.paloaltonetworks.com for technical reasons. If I do a request system software download version, i can see the version re...

Panorama-forum.png
  • 24334 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels