General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.
About General Topics
Post a discussion here if you have general questions regarding configuration and troubleshooting for Palo Alto Networks products. Use this forum to collaborate with like-minded security professionals to improve your security posture.

Discussions

How to Allow an App But Block a "Depends On?"

From what I understand, you need to explicitly allow "depends on" apps for a given app to work,

 

https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Check-if-an-Application-Needs-Explicitly-Allowed/ta-p/61893

 

However, what if I want to

...

cosx by L2 Linker
  • 3241 Views
  • 2 replies
  • 0 Likes

Resolved! Eicar no longer in AV signatures?

Is Eicar testfile no longer blocked by PA? I've tried through 2 PA devices and on both occasions it arrived to endpoint station (where was blocked by endpoint AV).

On 8th September 2015 same configuration was still blocking it.

 

Yes, I am trying htt

...

santonic by L6 Presenter
  • 4139 Views
  • 4 replies
  • 1 Likes

Aggregate Ethernet Trunked Traffic in a VWire

Hi Team, 

 

I was wondering if the below is acheivable. I plan to deploy vwires for this setup. Upstream switch's are Cisco switch's and same with downstream. (downstream switch's are stacked switch's - so logically one switch) The red is indicating

...

Screen Shot 2015-10-17 at 15.45.02.png

Issues with SSL Inspection

Hi,

 

I am having this weird issue where an application breaks because of SSL inspection. I have made an exclusion  based on the certificate:

ssl-exclude-cert [ login.salesforce.com *.salesforce.com ];

 

However, the firewall still decrypts the traffic, a

...

salesforce.JPG
MMCiobanu by L3 Networker
  • 3831 Views
  • 6 replies
  • 0 Likes

PBF e-mail notification

Hello,

Does anyone know if there's a way to have a notification e-mail sent when PBF kicks in?  We had a hiccup on our Internet circuit and PBF worked flawlessy... so well though that I wasn't really aware of the circuit issue until the next day when

...

dwoolley by L1 Bithead
  • 3278 Views
  • 4 replies
  • 0 Likes

Resolved! PA-500 6.1.4 Policy and URL filtering

Hi,

I have very big problem with my firewall. I have a few URL filtering rules which I block some of sites. 

Example:

1. Allow social network(linkedin) block youtube -> name AllowSN

2. Allow youtube block social network(linkedin) -> name AllowYT

3 an

...

ITBT by L1 Bithead
  • 3726 Views
  • 8 replies
  • 0 Likes

PA 500 stop sending reports automatically by email

Hello,

 

After upgrading two cluster of PA500 to 7.0.1, customized reports cannot be sent automatically using email.

Using the 'Test send email' is working so it's not an issue with the config. The device stop sending the reports after 18 days...

 

Regard

...

licenselu by L4 Transporter
  • 2728 Views
  • 4 replies
  • 0 Likes

VLAN with Palo Alto Networks PA-500

Hello,

 

We need to set up a VLANS in the office with the PA-500 but we don't like to change our address. It's possible to configure a VLANs with MAC address or protocole with PA-500?

Thanks 

RCHAIBI by L2 Linker
  • 4982 Views
  • 12 replies
  • 0 Likes

IPSec VPN issue

Hi All,

 

We have configured IPSec VPN between PAN and AWS. 

 

When i iniate the tunnel, IPSec and IKE SA installed successfully as a initiator.

then, IKE protocol IPSec SA delete message sent to peer. SPI:0x...

After a second, IPSec key deleted. Del

...

Javith by L3 Networker
  • 3039 Views
  • 6 replies
  • 0 Likes

HA Upgrade

I found this link on the knowledge base

https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Upgrade-a-High-Availability-HA-Pair/ta-p/57081

Has anyone used this method or any other method that they would like to share. I am currently at 6.

...

jdprovine by L4 Transporter
  • 3299 Views
  • 3 replies
  • 0 Likes

Resolved! LDAP Server Update DHCP from GlobalProtect

Hi all,

 

As you may know:  When a client is connected on GlobalProtect, they are assigned a dynamic IPv4 Address, not static.  

 

In my situation, I have about 100 GlobalProtect clients.  When the client connects for the first time, they are require

...

mmclimans by L3 Networker
  • 1788 Views
  • 1 replies
  • 0 Likes
  • 23712 Posts
  • 104 Subscriptions
Top Solution Authors
Top Liked Authors
Labels