General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Resolved! test custom-url command with Panorama deployed rules.

I'm trying to test a few urls in a custom url category I have deployed on my FW, but am unable to get to work. All my rules/objects are pushed out via Panorama and it seems as though the command only allows you to test locally defined rules (i get an error when specifying the rule name unless i use a local one). I don't see this test custom-ur...

chrisp by L3 Networker
  • 5316 Views
  • 5 replies
  • 0 Likes

SSL Inbound Inspection

Hi,I have setup a decryption policy to decrypt inbound SSL traffic for the Exchange web mail server. However, when I check the logs I see only some traffic as decrypted and some arnn't. Refer below screenshots,Why isn't the policy not decrypting all the traffic?I'm trying to decommission the Microsoft ISA server used as reverse proxy for Exchnag...

Shayan by L1 Bithead
  • 7550 Views
  • 6 replies
  • 0 Likes

GlobalProtect with X-Auth split tunnelling

Hi guys,I'm working on a GP portal and gateway configuration, in order to provide to the customer full compatibility with the old vpn clients (ex: cisco) I enabled X-Auth support on it. The client with a third party software authenticates but it always gets a default route 0.0.0.0 and not the single networks specified in the GP Gateway-->Clie...

Resolved! Problem with access to WF-500 Appliance

Hello, I try to access to the WF-500 via the Mgmt interface but I found the error message in the attachement. What is the reason of this issue ? what should i do to resolve this problem? I will appreciate all your helps.

wildfire.JPG
RCHAIBI by L2 Linker
  • 4558 Views
  • 5 replies
  • 0 Likes

Please tell me why send a email with BMP image will judged to be a threat?

Please tell me why send a email with BMP image will judged to be a threat?The firewall will show up a threaten sentence, during the sending job..Please help me here. Thank you. Threat Details: Name: IBM Lotus Domino BMP Parsing Integer Overflow VulnerabilityID: 38197DescriptionIBM Lotus Domino is prone to an integer overflow vulnerability while ...

Resolved! RFC 3021

Does the firewall support RFC 3021 IP Space aka 255.255.255.254 mask on routed point to point interfaces?Thanks,Ray.

rholman by Not applicable
  • 8175 Views
  • 5 replies
  • 1 Likes

IPSec VPN issue between Palo and MS Azure

Hi Guys, Having problems with a site2site VPN connection on a palo alto firewall. It seems to randomly drop and stop working. Sometimes it will stay up for days then drop and other times it stays up for about an hour and then drop. I have followed various guides from palo and Microsoft (this is a VPN to MS Azure) on how to configure it and as I ...

VPN logs.png

Default Ping Size

Is there a way to change the default ping size from 56 bytes? I know there is a switch to change the size but I'm interested in knowing if the default can be changed.

RFalconer by L3 Networker
  • 3052 Views
  • 2 replies
  • 0 Likes

FreeIPA [LDAP] group integration

Hello, anybody has experience with user group integration with FreeIPA ldap server?I have tried many different settings with no success. With some settings i can see groups but they seems to be empty.show user group list - shows proper groups, butshow user group name some_group_name - shows nothing but source type: servicesource: LDAP_pr...

Configuring PA-500 - separate access to to different IP addresses

Hello All, I hope that you can help me with one, I would say, common task but I'm unable to find right answer to this.We are using PA-500 and behind it, there is 5 servers. We also using Global Protect for accessing to servers.I need to setup on PA-500 that one specific user need to access only to one specific server, while all other users can a...

How to License PA VM without Internet Access

Hello Community, I have followed the guide on how to Licence PM VM without internet access here https://live.paloaltonetworks.com/t5/Management-Articles/How-to-license-a-Palo-Alto-Networks-VM-Series-firewall-without/ta-p/66178 Everything seems to be going fine, however when try to manually upload license key I get the following error message, se...

license.png

Estimate PANOS 8 Release?

do anyone here have estimate when PANOS 8 release? because my client have existing problem that not resolve and will be resolve on PANOS 8. I forgot to ask TAC about estimate date PANOS 8 release.

User Authentication Profile update for VPN User-ID mapping PANOS 7.0.x

Dear All, i have problem in my VPN user Identification (they cannot login to portal) after there's update/change in my AD server group. I already doing this https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Force-User-Group-Mapping-Refresh/ta-p/62597 to force user group mapping refresh. It's work to update my User-ID in my polic...

  • 24414 Posts
  • 125 Subscriptions
Top Solution Authors
Labels