General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

Discover LIVEcommunity Through Our New Animated Explainer Video!

We’re thrilled to unveil a brand-new animated video that highlights everything LIVEcommunity has to offer! This short and engaging video gives you a quick tour of the many resources available in our vibrant community — from interactive discussions and customer journey guides to the Cyber Elite program and Member Spotlight features. Whether ...

kiwi_0-1745308399217.png
kiwi by Community Team Member
  • 4230 Views
  • 0 replies
  • 0 Likes

Resolved! Handling Unknown TCP iSCSI traffic

I have a Dell Equalogic SAN that is replication to an offsite location. The traffic is sent over via a VPN tunnel (Certificate based). This traffic is being reported as unknown tcp. I can verify that the traffic in question is in fact the SAN traffic as the source and destination matches. I also read that the PA normally flags certificate based...

jharlow by L3 Networker
  • 4336 Views
  • 3 replies
  • 0 Likes

SSL Decryption

We do SSL Decryption on our PA. Recently we have been seeing a lot of sites that do not decrypt Chrome comes up with ERR_SSL_FALLBACK_BEYOND_MINIMUM_VERSION Firefox does not have any meaning full error message A quick google shows that it is to do with disabling of SSL v3. When the site is added to no decryption policy it works, so obviously...

RC-BHF by L2 Linker
  • 4544 Views
  • 5 replies
  • 1 Likes

Resolved! User-ID Agent questions?

Hello I have few questions regarding user-ID agent that is installed on DC (domain controller) 1- When the user login to machine, agent on DC send the username/IP details to PAN immediately? 2- Say after 10 minutes, user log off then agent on DC send the username/IP details to PAN immediately? 3- Multiple users login to one machine using s...

Kashif by L2 Linker
  • 10606 Views
  • 8 replies
  • 0 Likes

Frequent re-keying of ipsec tunnels

When I look under Monitor -> Logs -> System, I see the following: 1. ipsec-key-delete: IPSec key deleted. Deleted SA <SA info> SPI:<hex dump> 2. ike-nego-p2-succ: IKE phase-2 negotiation is succeeded as responder, quick mode. Established SA <SA info> SPI: <hex dump> 3. ipsec-key-install: IPSec key installed. In...

HA VSYS

Hi, Have anyone tried to configure different HA setup for different VSYS? Let's say VSYS1 is active/active and VSYS2 is active/passive. Thanks, MBS

Resolved! VPN with built in VPN Client of OS X

Hi there, for a special reason I need to setup a dedicated VPN Gateway for the built in iOS/OS X VPN client. Before I start to setup a Linux System for that I would like to find out if it's possible with PaloAlto or not. In the past there was a X-Auth possibility and I also found documents for PAN-OS 4.x but it looks like these possiblities ar...

Panorama Error commit

Hi, We have a cluster PA (Madrid) in version 5.0.14, and two PA in stand-alone (Singapur, Miami) in version 7.0.6. We just commited the panorama config but we got a error in cluster PA Madrid. Panorama in 7.0.6 can handle firewalls in version 5.0.14, right?? How can I get more info about this commited failed??

Captura.JPG

dnsproxy failures

System log fills with messages like "Failed to resolve domain name:defrxpwgklm.capco.com after trying all attempts to name server(s): 8.8.4.4 194.25.0.68". DNS without dnsproxy is working. Can i restart the dnsproxy to fix this issue?The messages are appearing after some threats of type "Suspicious DNS Query".

azwicker by L1 Bithead
  • 3774 Views
  • 3 replies
  • 0 Likes

Resolved! DMZ Web Server Access Setup PT2

Hello Community, Can someone please let me know if Palo Alto have any documentation examples of setting up access to a webserver from the Internet that resides in a DMZ? Thank you Carlton

User-ID Agent Upgrade

Hi, We are planning to upgrade the User-ID Agent from version 6.0.6-4 to 7.0.3-13. Three PAN-OS are running with version 7.1.1, 7.0.5-h2 and 7.0.2 use the same agent server. Is version 7.0.3-13 will work with PAN-OS version above?

qafcopa by L1 Bithead
  • 4131 Views
  • 3 replies
  • 0 Likes

Global Protect 3.0.0 Gateway Certificate Error "Server Certificate verification failed" *FIX*

Hi All, Recently had a client upgrade their Global Protect Agent to 3.0.0 from 2.2.2. When connecting to the Gateway they would encounter the following message - "Server Certificate verification failed". From 2.1.0 you had to ensure the External Gateway address in the Agent/Client configuration of the Portal is the CN of the Certificate you...

Resolved! Group Mapping for Domains with Non-contiguous namespace

Hi I'm attempting to implement userID on PAN-OS 7.0.6 within a multi-domain forest. All of our workstations exist on one domain and users logging into those workstations exist on another domain within the same forest. I have the UserID agent setup on a member server on the workstation domain and it can correctly map the IP address to usernames...

  • 24355 Posts
  • 124 Subscriptions
Top Solution Authors
Top Liked Authors
Labels